HelgeLeFelge | 26.11.2021 13:10 | Windows Defender Offline Log Code:
--------------------------------------------------------------------------------
Microsoft Antimalware (F7F4CD20-7371-4319-B1DB-6FCFC68573EC) Service Log
Started On 11-26-2021 11:58:03
************************************************************
OS install time not retrieved: hr = 0x8007000d
Current time: 11/26/2021 10:58:03.264572700 UTC (9125 ms since boot)
2021-11-26T10:58:03.251Z ProductId: 4, ProductFeature: 0, LaunchedProtected: 0, IsWcos: 0, IsContainerOs: 0
2021-11-26T10:58:03.251Z [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: WdoWppTracing-20211126-115803-00000003-ffffffff.bin ...
2021-11-26T10:58:03.251Z [WPP] Trace session started - WdoWppTracing-20211126-115803-00000003-ffffffff.bin
2021-11-26T10:58:03.251Z OS Build/Branch info: 19041.1.amd64fre.vb_release.191206-1406
2021-11-26T10:58:03.251Z [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Offline Scanner
2021-11-26T10:58:03.251Z Service is asked to be reenabled.
2021-11-26T10:58:03.267Z Task(-EnableService) launched
2021-11-26T10:58:03.282Z Loaded module#0 MpComServer.
2021-11-26T10:58:03.282Z Loading engine...
2021-11-26T10:58:03.407Z UpdateEngine start: Source: 3, szUpdateDirectory: C:\Windows\Microsoft Antimalware\Definition Updates\{0D82DE60-E2C1-4951-88F8-0C9E1D5F5468}
2021-11-26T10:58:03.485Z Verifying engine and signature files (source: 0) ...
2021-11-26T10:58:03.517Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates\{62F9E917-604D-470E-89D7-C13B9AE0F7A9}\mpengine.dll]
2021-11-26T10:58:03.563Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates\{62F9E917-604D-470E-89D7-C13B9AE0F7A9}\mpasbase.vdm]
2021-11-26T10:58:03.563Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates\{62F9E917-604D-470E-89D7-C13B9AE0F7A9}\mpasdlta.vdm]
2021-11-26T10:58:03.626Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates\{62F9E917-604D-470E-89D7-C13B9AE0F7A9}\mpavbase.vdm]
2021-11-26T10:58:03.657Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates\{62F9E917-604D-470E-89D7-C13B9AE0F7A9}\mpavdlta.vdm]
Database:
2021-11-26T10:58:03.673Z Can't find offline cache cache (C:\Windows\Microsoft Antimalware\Scans\mpcache-E272FF203F86865D0CA5D6363E45BD083FF5685E.bin): 0x00000002IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007bIDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000dIDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d
2021-11-26T10:58:06.501Z [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.
2021-11-26T10:58:06.517Z CSignatureStatus: back to good
2021-11-26T10:58:06.517Z [Engine] Loaded C:\Windows\Microsoft Antimalware\Definition Updates\{62F9E917-604D-470E-89D7-C13B9AE0F7A9}
2021-11-26T10:58:06.517Z [Engine] Removing C:\Windows\Microsoft Antimalware\Definition Updates\{0D82DE60-E2C1-4951-88F8-0C9E1D5F5468} ...
2021-11-26T10:58:06.517Z MpPlatformKillbitsFromEngine (0x40a0800) written, hr = 0x0
Signature updated via XCopy on 11-26-2021 11:58:06
Product Version: 4.18.1907.16384
Service Version: 4.18.1909.6
Engine Version: 1.1.18700.4
AS Signature Version: 1.353.1621.0
AV Signature Version: 1.353.1621.0
************************************************************
2021-11-26T10:58:06.517Z UpdateEngine finished with 0x0: Source: 3, szUpdateDirectory: C:\Windows\Microsoft Antimalware\Definition Updates\{0D82DE60-E2C1-4951-88F8-0C9E1D5F5468}
2021-11-26T10:58:06.532Z Engine loaded!
2021-11-26T10:58:06.532Z Verifying license file...
2021-11-26T10:58:06.532Z Verified [C:\ProgramData\Microsoft\Windows Defender\Offline Scanner\msmplics.dll]
2021-11-26T10:58:06.532Z MpPlatformKillbitsFromEngine (0x40a0800) written, hr = 0x0
Product Version: 4.18.1907.16384
Service Version: 4.18.1909.6
Engine Version: 1.1.18700.4
AS Signature Version: 1.353.1621.0
AV Signature Version: 1.353.1621.0
************************************************************
2021-11-26T10:58:07.314Z MpManagerEnable: setting DisableAS to 0 ...
2021-11-26T10:58:07.314Z MpManagerEnable: setting DisableAV to 0 ...
2021-11-26T10:58:07.314Z Scheduled scan configured CPU priority: normal (LowCpuPriority: 0)
Engine:
2021-11-26T10:58:30.200Z Setting original file name "pcalua.exe" for "\\?\c:\windows\syswow64\pcacli.dll", hr=0x0
Engine:
2021-11-26T10:58:31.622Z Setting original file name "reg.exe" for "\\?\c:\windows\syswow64\reg.exe", hr=0x0
Engine:
2021-11-26T10:58:32.237Z Setting original file name "schtasks.exe" for "\\?\c:\windows\syswow64\schtasks.exe", hr=0x0
Internal signature match:subtype=Lowfi, sigseq=0x00003B9663B694BC, sigsha=453d7010a1da1384f3668f77d4026c6d12766501, cached=false, source=0, resourceid=0xf810c38e
Internal signature match:subtype=Lowfi, sigseq=0x0000108073673E9D, sigsha=b01216c252daed6d861229c115568d31d571f929, cached=false, source=0, resourceid=0x59d47228
Internal signature match:subtype=Lowfi, sigseq=0x00001080510AD9E7, sigsha=7212b14cc25f6fce1af343f96846136b50dc298d, cached=false, source=0, resourceid=0x59d47228
Internal signature match:subtype=Lowfi, sigseq=0x0000E378B114A455, sigsha=c229c52077dcd9988b0306432f53f808af51fb96, cached=false, source=0, resourceid=0x3d963a92
Internal signature match:subtype=Lowfi, sigseq=0x0003AC78F2DE668A, sigsha=9333642bd5e3339d607acf8845411fff60f6cece, cached=false, source=0, resourceid=0x24b04d03
Engine:
2021-11-26T10:58:57.145Z Setting original file name "pcalua.exe" for "\\?\c:\windows\system32\pcacli.dll", hr=0x0
Engine:
2021-11-26T10:58:57.147Z Setting original file name "pcalua.exe" for "\\?\c:\windows\system32\pcadm.dll", hr=0x0
Engine:
2021-11-26T10:58:58.999Z Setting original file name "reg.exe" for "\\?\c:\windows\system32\reg.exe", hr=0x0
Engine:
2021-11-26T10:58:59.747Z Setting original file name "schtasks.exe" for "\\?\c:\windows\system32\schtasks.exe", hr=0x0
Internal signature match:subtype=Lowfi, sigseq=0x00003B9663B694BC, sigsha=453d7010a1da1384f3668f77d4026c6d12766501, cached=false, source=0, resourceid=0x2440a323
2021-11-26T10:59:03.279Z Process scan (postsignatureupdatescan) started.
2021-11-26T10:59:03.357Z Process scan (postsignatureupdatescan) completed.
Engine:
2021-11-26T10:59:04.230Z Setting original file name "vssadmin.exe" for "\\?\c:\windows\system32\vssadmin.exe", hr=0x0
Engine:
2021-11-26T10:59:10.294Z Triggered AR EMS scan
Engine:
2021-11-26T10:59:10.294Z EMS scan for process: lsass pid: 808, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T10:59:10.356Z EMS scan for process: svchost pid: 916, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T10:59:10.403Z EMS scan for process: svchost pid: 308, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T10:59:10.419Z EMS scan for process: svchost pid: 828, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T10:59:10.466Z EMS scan for process: svchost pid: 116, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T10:59:10.497Z EMS scan for process: svchost pid: 1072, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T10:59:10.528Z EMS scan for process: svchost pid: 1200, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T10:59:10.560Z EMS scan for process: svchost pid: 1560, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T10:59:10.606Z EMS scan for process: svchost pid: 1656, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T10:59:10.622Z EMS scan for process: svchost pid: 1804, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T10:59:10.638Z EMS scan for process: svchost pid: 1868, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
2021-11-26T10:59:38.492Z [Cloud] Engine is requesting config to do cloud query [regular network].
2021-11-26T10:59:38.492Z Service stop requested (ServiceError: 0x0). Calling CleanupMpService ...
2021-11-26T10:59:38.570Z Unloaded module#0 MpComServer.
Microsoft Antimalware (F7F4CD20-7371-4319-B1DB-6FCFC68573EC) Log
Stopped On 11-26-2021 11:59:38 (Exit Code = 0x0)
************************************************************
--------------------------------------------------------------------------------
Microsoft Antimalware (F7F4CD20-7371-4319-B1DB-6FCFC68573EC) Service Log
Started On 11-26-2021 12:05:19
************************************************************
OS install time not retrieved: hr = 0x8007000d
Current time: 11/26/2021 11:05:19.212300500 UTC (9078 ms since boot)
2021-11-26T11:05:19.201Z ProductId: 4, ProductFeature: 0, LaunchedProtected: 0, IsWcos: 0, IsContainerOs: 0
2021-11-26T11:05:19.201Z [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: WdoWppTracing-20211126-120519-00000003-ffffffff.bin ...
2021-11-26T11:05:19.201Z [WPP] Trace session started - WdoWppTracing-20211126-120519-00000003-ffffffff.bin
2021-11-26T11:05:19.201Z OS Build/Branch info: 19041.1.amd64fre.vb_release.191206-1406
2021-11-26T11:05:19.201Z [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Offline Scanner
2021-11-26T11:05:19.201Z Service is asked to be reenabled.
2021-11-26T11:05:19.201Z Task(-EnableService) launched
2021-11-26T11:05:19.217Z Loaded module#0 MpComServer.
2021-11-26T11:05:19.217Z Loading engine...
2021-11-26T11:05:19.358Z UpdateEngine start: Source: 3, szUpdateDirectory: C:\Windows\Microsoft Antimalware\Definition Updates\{D5DBA55F-4AA8-4AAC-B460-A228E187FB1D}
2021-11-26T11:05:19.436Z Verifying engine and signature files (source: 0) ...
2021-11-26T11:05:19.467Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates\{07D1D0F0-840F-47AD-BE3E-8E69E4F5B24D}\mpengine.dll]
2021-11-26T11:05:19.498Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates\{07D1D0F0-840F-47AD-BE3E-8E69E4F5B24D}\mpasbase.vdm]
2021-11-26T11:05:19.514Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates\{07D1D0F0-840F-47AD-BE3E-8E69E4F5B24D}\mpasdlta.vdm]
2021-11-26T11:05:19.561Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates\{07D1D0F0-840F-47AD-BE3E-8E69E4F5B24D}\mpavbase.vdm]
2021-11-26T11:05:19.592Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates\{07D1D0F0-840F-47AD-BE3E-8E69E4F5B24D}\mpavdlta.vdm]
Database:
2021-11-26T11:05:19.624Z Can't find offline cache cache (C:\Windows\Microsoft Antimalware\Scans\mpcache-04538E568BC49FBEAD94ACF6D60BB2403B288398.bin): 0x00000002IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007bIDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000dIDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d
2021-11-26T11:05:22.405Z [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.
2021-11-26T11:05:22.421Z CSignatureStatus: back to good
2021-11-26T11:05:22.421Z [Engine] Loaded C:\Windows\Microsoft Antimalware\Definition Updates\{07D1D0F0-840F-47AD-BE3E-8E69E4F5B24D}
2021-11-26T11:05:22.421Z [Engine] Removing C:\Windows\Microsoft Antimalware\Definition Updates\{62F9E917-604D-470E-89D7-C13B9AE0F7A9} ...
2021-11-26T11:05:22.421Z [Engine] Removing C:\Windows\Microsoft Antimalware\Definition Updates\{D5DBA55F-4AA8-4AAC-B460-A228E187FB1D} ...
2021-11-26T11:05:22.421Z MpPlatformKillbitsFromEngine (0x43f0800) written, hr = 0x0
Signature updated via XCopy on 11-26-2021 12:05:22
Product Version: 4.18.1907.16384
Service Version: 4.18.1909.6
Engine Version: 1.1.18700.4
AS Signature Version: 1.353.1621.0
AV Signature Version: 1.353.1621.0
************************************************************
2021-11-26T11:05:22.421Z UpdateEngine finished with 0x0: Source: 3, szUpdateDirectory: C:\Windows\Microsoft Antimalware\Definition Updates\{D5DBA55F-4AA8-4AAC-B460-A228E187FB1D}
2021-11-26T11:05:22.421Z Engine loaded!
2021-11-26T11:05:22.437Z Verifying license file...
2021-11-26T11:05:22.437Z Verified [C:\ProgramData\Microsoft\Windows Defender\Offline Scanner\msmplics.dll]
2021-11-26T11:05:22.437Z MpPlatformKillbitsFromEngine (0x43f0800) written, hr = 0x0
Product Version: 4.18.1907.16384
Service Version: 4.18.1909.6
Engine Version: 1.1.18700.4
AS Signature Version: 1.353.1621.0
AV Signature Version: 1.353.1621.0
************************************************************
2021-11-26T11:05:23.250Z MpManagerEnable: setting DisableAS to 0 ...
2021-11-26T11:05:23.250Z MpManagerEnable: setting DisableAV to 0 ...
2021-11-26T11:05:23.250Z Scheduled scan configured CPU priority: normal (LowCpuPriority: 0)
Internal signature match:subtype=Lowfi, sigseq=0x00003B9663B694BC, sigsha=453d7010a1da1384f3668f77d4026c6d12766501, cached=false, source=0, resourceid=0xf810c38e
Internal signature match:subtype=Lowfi, sigseq=0x0000108073673E9D, sigsha=b01216c252daed6d861229c115568d31d571f929, cached=false, source=0, resourceid=0x59d47228
Internal signature match:subtype=Lowfi, sigseq=0x00001080510AD9E7, sigsha=7212b14cc25f6fce1af343f96846136b50dc298d, cached=false, source=0, resourceid=0x59d47228
Internal signature match:subtype=Lowfi, sigseq=0x0000E378B114A455, sigsha=c229c52077dcd9988b0306432f53f808af51fb96, cached=false, source=0, resourceid=0x3d963a92
Internal signature match:subtype=Lowfi, sigseq=0x0003AC78F2DE668A, sigsha=9333642bd5e3339d607acf8845411fff60f6cece, cached=false, source=0, resourceid=0x24b04d03
2021-11-26T11:06:19.227Z Process scan (postsignatureupdatescan) started.
2021-11-26T11:06:19.318Z Process scan (postsignatureupdatescan) completed.
Internal signature match:subtype=Lowfi, sigseq=0x00003B9663B694BC, sigsha=453d7010a1da1384f3668f77d4026c6d12766501, cached=false, source=0, resourceid=0x2440a323
Engine:
2021-11-26T11:06:28.593Z Triggered AR EMS scan
Engine:
2021-11-26T11:06:28.593Z EMS scan for process: lsass pid: 800, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T11:06:28.656Z EMS scan for process: svchost pid: 908, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T11:06:28.703Z EMS scan for process: svchost pid: 1012, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T11:06:28.718Z EMS scan for process: svchost pid: 824, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T11:06:28.765Z EMS scan for process: svchost pid: 732, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T11:06:28.797Z EMS scan for process: svchost pid: 1064, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T11:06:28.828Z EMS scan for process: svchost pid: 1196, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T11:06:28.875Z EMS scan for process: svchost pid: 1524, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T11:06:28.906Z EMS scan for process: svchost pid: 1620, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T11:06:28.922Z EMS scan for process: svchost pid: 1768, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2021-11-26T11:06:28.953Z EMS scan for process: svchost pid: 1836, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
2021-11-26T11:06:56.854Z [Cloud] Engine is requesting config to do cloud query [regular network].
2021-11-26T11:06:56.854Z Service stop requested (ServiceError: 0x0). Calling CleanupMpService ...
2021-11-26T11:06:56.933Z Unloaded module#0 MpComServer.
Microsoft Antimalware (F7F4CD20-7371-4319-B1DB-6FCFC68573EC) Log
Stopped On 11-26-2021 12:06:56 (Exit Code = 0x0)
************************************************************ |