Schmuizin | 24.07.2021 13:30 | MBAMSERVICE log (Teil4/4): Code:
07/24/21 " 14:13:22.254" 322373937 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:61915 Action=Filter"
07/24/21 " 14:13:22.279" 322373953 0ad8 1e0c DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:56416 Action=Filter"
07/24/21 " 14:13:36.809" 322388484 0ad8 2a04 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:56944 Action=Filter"
07/24/21 " 14:13:36.837" 322388515 0ad8 1e0c DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:60079 Action=Filter"
07/24/21 " 14:13:41.044" 322392718 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\SearchFilterHost.exe), cmdline (""C:\Windows\system32\SearchFilterHost.exe"" 0 800 804 812 8192 808 784 )"
07/24/21 " 14:13:41.604" 322393281 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:13:41.044" 322392723 2748 2870 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\SearchFilterHost.exe"
07/24/21 " 14:13:41.044" 322392723 2748 2870 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:13:44.609" 322396281 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:13:46.657" 322398328 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:13:51.844" 322403515 4114 4298 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000004114 (\Device\HarddiskVolume5\Windows\System32\svchost.exe) is exiting"
07/24/21 " 14:14:10.215" 322421890 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:61324 Action=Filter"
07/24/21 " 14:14:10.246" 322421921 0ad8 2a04 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:56287 Action=Filter"
07/24/21 " 14:14:10.793" 322422464 3c98 46f4 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000003C98 (\Device\HarddiskVolume5\Windows\System32\svchost.exe) is exiting"
07/24/21 " 14:14:20.896" 322432578 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 15604."
07/24/21 " 14:14:20.896" 322432578 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 15604."
07/24/21 " 14:14:20.901" 322432578 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 15604."
07/24/21 " 14:14:20.902" 322432578 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 15604."
07/24/21 " 14:14:20.907" 322432578 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 15604."
07/24/21 " 14:14:20.907" 322432578 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 15604."
07/24/21 " 14:14:20.908" 322432578 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 15604."
07/24/21 " 14:14:20.913" 322432593 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 15604."
07/24/21 " 14:14:20.920" 322432593 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 15604."
07/24/21 " 14:14:20.921" 322432593 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 15604."
07/24/21 " 14:14:20.925" 322432593 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 15604."
07/24/21 " 14:14:20.954" 322432625 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\svchost.exe), cmdline (C:\Windows\system32\svchost.exe -k appmodel -p -s camsvc)"
07/24/21 " 14:14:21.346" 322433015 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:14:20.955" 322432634 03a8 3e70 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\svchost.exe"
07/24/21 " 14:14:20.955" 322432634 03a8 3e70 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:14:23.015" 322434687 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:14:24.152" 322435828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:14:51.370" 322463046 0ad8 30ac DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:58744 Action=Filter"
07/24/21 " 14:14:51.394" 322463062 0ad8 3f50 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:53880 Action=Filter"
07/24/21 " 14:14:59.446" 322471125 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:14:59.447" 322471125 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:15:08.572" 322480243 3394 234c DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000003394 (\Device\HarddiskVolume5\Windows\System32\SearchProtocolHost.exe) is exiting"
07/24/21 " 14:15:08.586" 322480257 2950 23b8 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000002950 (\Device\HarddiskVolume5\Windows\System32\SearchFilterHost.exe) is exiting"
07/24/21 " 14:15:14.898" 322486578 0ad8 1c88 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:52595 Action=Filter"
07/24/21 " 14:15:14.926" 322486609 0ad8 3b48 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:55877 Action=Filter"
07/24/21 " 14:15:15.281" 322486953 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:54162 Action=Filter"
07/24/21 " 14:15:15.310" 322486984 0ad8 2a04 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:57853 Action=Filter"
07/24/21 " 14:15:15.314" 322486984 0ad8 3f50 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:64831 Action=Filter"
07/24/21 " 14:15:20.969" 322492640 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 15604."
07/24/21 " 14:15:37.236" 322508906 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:15:45.334" 322517015 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:63682 Action=Filter"
07/24/21 " 14:15:45.366" 322517046 0ad8 2a04 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:52585 Action=Filter"
07/24/21 " 14:15:46.651" 322518328 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\NOTEPAD.EXE), cmdline (""C:\Windows\system32\NOTEPAD.EXE"" C:\ProgramData\Spybot - Search & Destroy\Logs\210720-204516.xml.cleaning.log)"
07/24/21 " 14:15:46.669" 322518343 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 3784."
07/24/21 " 14:15:46.669" 322518343 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 3784."
07/24/21 " 14:15:46.748" 322518421 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\SearchProtocolHost.exe), cmdline (""C:\Windows\system32\SearchProtocolHost.exe"" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-3267400732-2583111342-1326098953-100115_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-3267400732-2583111342-1326098953-100115 1 -2147483646 ""Software\Microsoft\Windows Search"" ""Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)"" ""C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc"" ""DownLevelDaemon"" ""1"")"
07/24/21 " 14:15:46.764" 322518437 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\SearchFilterHost.exe), cmdline (""C:\Windows\system32\SearchFilterHost.exe"" 0 800 804 812 8192 808 784 )"
07/24/21 " 14:15:47.254" 322518937 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:15:46.652" 322518331 16c8 43bc DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\NOTEPAD.EXE"
07/24/21 " 14:15:46.652" 322518331 16c8 43bc DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:15:46.749" 322518428 2748 2870 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\SearchProtocolHost.exe"
07/24/21 " 14:15:46.749" 322518428 2748 2870 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:15:46.765" 322518444 2748 2870 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\SearchFilterHost.exe"
07/24/21 " 14:15:46.765" 322518444 2748 2870 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:15:50.586" 322522265 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:15:51.252" 322522921 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:15:50.034" 322521705 2338 471c DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000002338 (\Device\HarddiskVolume5\Windows\System32\notepad.exe) is exiting"
07/24/21 " 14:15:57.728" 322529406 0ad8 1c88 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:63221 Action=Filter"
07/24/21 " 14:16:06.506" 322538187 0ad8 1e0c DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:62465 Action=Filter"
07/24/21 " 14:16:06.532" 322538203 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:50260 Action=Filter"
07/24/21 " 14:16:11.430" 322543109 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:16:23.110" 322554781 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessARWUploads "cloudcontrollerimplhelper.cpp" 1914 "Enter ProcessARWUploads"
07/24/21 " 14:16:24.115" 322555796 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessAEUploads "cloudcontrollerimplhelper.cpp" 2006 "Enter ProcessAEUploads"
07/24/21 " 14:16:25.127" 322556796 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessShurikenUploads "cloudcontrollerimplhelper.cpp" 2097 "Enter ProcessShurikenUploads"
07/24/21 " 14:16:25.401" 322557078 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\NOTEPAD.EXE), cmdline (""C:\Windows\system32\NOTEPAD.EXE"" C:\ProgramData\Malwarebytes\MBAMService\exclusions.txt)"
07/24/21 " 14:16:25.610" 322557281 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 10056."
07/24/21 " 14:16:25.612" 322557281 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 10056."
07/24/21 " 14:16:25.618" 322557296 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 10056."
07/24/21 " 14:16:25.619" 322557296 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 10056."
07/24/21 " 14:16:26.038" 322557718 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:16:26.136" 322557812 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessRootkitUploads "cloudcontrollerimplhelper.cpp" 2188 "Enter ProcessRootkitUploads"
07/24/21 " 14:16:27.152" 322558828 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessDopplegangUploads "cloudcontrollerimplhelper.cpp" 2279 "Enter ProcessDopplegangUploads"
07/24/21 " 14:16:25.402" 322557081 16c8 4464 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\NOTEPAD.EXE"
07/24/21 " 14:16:25.402" 322557081 16c8 4464 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:16:27.790" 322559468 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:16:28.164" 322559843 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessMWACUploads "cloudcontrollerimplhelper.cpp" 2372 "Enter ProcessMWACUploads"
07/24/21 " 14:16:29.177" 322560859 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessDDSUploads "cloudcontrollerimplhelper.cpp" 2471 "Enter ProcessDDSUploads"
07/24/21 " 14:16:29.177" 322560859 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessDDSUploads "cloudcontrollerimplhelper.cpp" 2491 "No DDS uploads to process at this time."
07/24/21 " 14:16:27.250" 322558921 0ccc 3dc8 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000000CCC (\Device\HarddiskVolume5\Windows\System32\notepad.exe) is exiting"
07/24/21 " 14:16:30.223" 322561906 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\NOTEPAD.EXE), cmdline (""C:\Windows\system32\NOTEPAD.EXE"" C:\ProgramData\Malwarebytes\MBAMService\LOGS\MBAMSERVICE.LOG)"
07/24/21 " 14:16:30.851" 322562531 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:16:30.224" 322561903 16c8 424c DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\NOTEPAD.EXE"
07/24/21 " 14:16:30.224" 322561903 16c8 424c DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:16:35.864" 322567546 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:16:35.287" 322566958 44ac 16dc DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 00000000000044AC (\Device\HarddiskVolume5\Windows\System32\notepad.exe) is exiting"
07/24/21 " 14:16:57.371" 322589046 0ad8 1e0c DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:64080 Action=Filter"
07/24/21 " 14:16:57.396" 322589078 0ad8 3b48 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:54724 Action=Filter"
07/24/21 " 14:16:57.400" 322589078 0ad8 25ac DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:50665 Action=Filter"
07/24/21 " 14:16:59.458" 322591140 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:16:59.460" 322591140 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:16:59.530" 322591203 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:17:03.657" 322595328 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:17:06.663" 322598343 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:17:34.846" 322626515 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:64517 Action=Filter"
07/24/21 " 14:17:45.731" 322637406 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Users\jendr\AppData\Local\Microsoft\OneDrive\21.119.0613.0001\FileCoAuth.exe), cmdline (""C:\Users\jendr\AppData\Local\Microsoft\OneDrive\21.119.0613.0001\FileCoAuth.exe"" -Embedding)"
07/24/21 " 14:17:45.751" 322637421 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 10052."
07/24/21 " 14:17:45.751" 322637421 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 10052."
07/24/21 " 14:17:45.777" 322637453 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 10052."
07/24/21 " 14:17:45.777" 322637453 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 10052."
07/24/21 " 14:17:45.778" 322637453 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 10052."
07/24/21 " 14:17:45.783" 322637453 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 10052."
07/24/21 " 14:17:45.784" 322637453 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 10052."
07/24/21 " 14:17:46.813" 322638484 0ad8 3f50 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:57365 Action=Filter"
07/24/21 " 14:17:46.828" 322638500 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Windows\System32\DriverStore\FileRepository\nvhdc.inf_amd64_ef8a364c90e72379\Display.NvContainer\NVDisplay.Container.exe."
07/24/21 " 14:17:46.829" 322638500 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Windows\System32\DriverStore\FileRepository\nvhdc.inf_amd64_ef8a364c90e72379\Display.NvContainer\NVDisplay.Container.exe."
07/24/21 " 14:17:45.731" 322637410 0264 4348 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Users\jendr\AppData\Local\Microsoft\OneDrive\21.119.0613.0001\FileCoAuth.exe"
07/24/21 " 14:17:45.731" 322637410 0264 4348 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:17:51.076" 322642750 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:50184 Action=Filter"
07/24/21 " 14:17:51.833" 322643515 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 10052."
07/24/21 " 14:17:51.839" 322643510 2744 1d80 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000002744 (\Device\HarddiskVolume5\Users\jendr\AppData\Local\Microsoft\OneDrive\21.119.0613.0001\FileCoAuth.exe) is exiting"
07/24/21 " 14:18:16.552" 322668234 0ad8 2a04 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:64593 Action=Filter"
07/24/21 " 14:18:16.570" 322668250 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\svchost.exe), cmdline (C:\Windows\system32\svchost.exe -k wsappx -p -s AppXSvc)"
07/24/21 " 14:18:16.622" 322668296 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\SysWOW64\backgroundTaskHost.exe), cmdline (""C:\Windows\SysWOW64\backgroundTaskHost.exe"" -ServerName:App.AppXz2zxkdmw4wwcwh41me91q40p6xy5v793.mca)"
07/24/21 " 14:18:16.626" 322668296 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\backgroundTaskHost.exe), cmdline (""C:\Windows\system32\backgroundTaskHost.exe"" -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca)"
07/24/21 " 14:18:16.631" 322668312 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\System32\svchost.exe), cmdline (C:\Windows\System32\svchost.exe -k wsappx -p -s ClipSVC)"
07/24/21 " 14:18:16.672" 322668343 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 8396."
07/24/21 " 14:18:16.709" 322668390 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\System32\RuntimeBroker.exe), cmdline (C:\Windows\System32\RuntimeBroker.exe -Embedding)"
07/24/21 " 14:18:16.815" 322668484 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\BackgroundTaskHost.exe), cmdline (""C:\Windows\system32\BackgroundTaskHost.exe"" -ServerName:BackgroundTaskHost.WebAccountProvider)"
07/24/21 " 14:18:16.880" 322668562 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\System32\RuntimeBroker.exe), cmdline (C:\Windows\System32\RuntimeBroker.exe -Embedding)"
07/24/21 " 14:18:16.943" 322668625 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\System32\RuntimeBroker.exe), cmdline (C:\Windows\System32\RuntimeBroker.exe -Embedding)"
07/24/21 " 14:18:17.057" 322668734 0ad8 3f50 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:49159 Action=Filter"
07/24/21 " 14:18:17.455" 322669125 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:18:17.465" 322669140 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:18:17.565" 322669234 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\BackgroundTransferHost.exe), cmdline (""BackgroundTransferHost.exe"" -ServerName:BackgroundTransferHost.1)"
07/24/21 " 14:18:17.688" 322669359 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\BackgroundTransferHost.exe), cmdline (""BackgroundTransferHost.exe"" -ServerName:BackgroundTransferHost.1)"
07/24/21 " 14:18:17.796" 322669468 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:61561 Action=Filter"
07/24/21 " 14:18:17.957" 322669625 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:18:17.964" 322669640 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:18:17.996" 322669671 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:18:18.000" 322669671 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:18:18.001" 322669671 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:18:18.061" 322669734 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\backgroundTaskHost.exe), cmdline (""C:\Windows\system32\backgroundTaskHost.exe"" -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca)"
07/24/21 " 14:18:18.210" 322669890 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\BackgroundTransferHost.exe), cmdline (""BackgroundTransferHost.exe"" -ServerName:BackgroundTransferHost.1)"
07/24/21 " 14:18:18.318" 322670000 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:18:18.320" 322670000 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:18:18.321" 322670000 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:18:16.571" 322668250 03a8 33f0 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\svchost.exe"
07/24/21 " 14:18:16.571" 322668250 03a8 33f0 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:16.623" 322668302 0264 4348 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\SysWOW64\backgroundTaskHost.exe"
07/24/21 " 14:18:16.623" 322668302 0264 4348 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:16.627" 322668306 0264 40a8 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\backgroundTaskHost.exe"
07/24/21 " 14:18:16.627" 322668306 0264 40a8 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:16.632" 322668311 03a8 33f0 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\System32\svchost.exe"
07/24/21 " 14:18:16.632" 322668311 03a8 33f0 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:18.775" 322670453 0ad8 25ac DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:61593 Action=Filter"
07/24/21 " 14:18:16.938" 322668609 0588 16b0 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000000588 (\Device\HarddiskVolume5\Windows\System32\backgroundTaskHost.exe) is exiting"
07/24/21 " 14:18:17.560" 322669231 0264 0530 DEBUG MBAMChameleon VerifyFile "fileverify.cpp" 479 "Opening \??\C:\Windows\system32\BackgroundTransferHost.exe for verification"
07/24/21 " 14:18:17.650" 322669321 4048 08a0 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000004048 (\Device\HarddiskVolume5\Windows\System32\BackgroundTransferHost.exe) is exiting"
07/24/21 " 14:18:17.759" 322669430 417c 2e7c DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 000000000000417C (\Device\HarddiskVolume5\Windows\System32\backgroundTaskHost.exe) is exiting"
07/24/21 " 14:18:16.709" 322668388 0264 40a8 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\System32\RuntimeBroker.exe"
07/24/21 " 14:18:16.709" 322668388 0264 40a8 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:16.815" 322668494 0264 4348 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\BackgroundTaskHost.exe"
07/24/21 " 14:18:16.815" 322668494 0264 4348 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:16.881" 322668560 0264 4758 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\System32\RuntimeBroker.exe"
07/24/21 " 14:18:16.881" 322668560 0264 4758 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:16.944" 322668623 0264 4758 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\System32\RuntimeBroker.exe"
07/24/21 " 14:18:16.944" 322668623 0264 4758 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:17.566" 322669245 0264 0530 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\BackgroundTransferHost.exe"
07/24/21 " 14:18:17.566" 322669245 0264 0530 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:17.689" 322669368 0264 4758 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\BackgroundTransferHost.exe"
07/24/21 " 14:18:17.689" 322669368 0264 4758 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:18.061" 322669740 0264 415c DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\backgroundTaskHost.exe"
07/24/21 " 14:18:18.061" 322669740 0264 415c DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:18.211" 322669890 0264 40a8 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\BackgroundTransferHost.exe"
07/24/21 " 14:18:18.211" 322669890 0264 40a8 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:18.043" 322669714 37ac 1c08 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 00000000000037AC (\Device\HarddiskVolume5\Windows\System32\BackgroundTransferHost.exe) is exiting"
07/24/21 " 14:18:18.309" 322669980 4464 4318 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000004464 (\Device\HarddiskVolume5\Windows\System32\BackgroundTransferHost.exe) is exiting"
07/24/21 " 14:18:18.965" 322670636 451c 2a0c DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 000000000000451C (\Device\HarddiskVolume5\Windows\System32\backgroundTaskHost.exe) is exiting"
07/24/21 " 14:18:30.046" 322681718 0ad8 25ac DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:64981 Action=Filter"
07/24/21 " 14:18:37.815" 322689484 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:49915 Action=Filter"
07/24/21 " 14:18:37.822" 322689500 0ad8 1e0c DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:61806 Action=Filter"
07/24/21 " 14:18:37.847" 322689515 0ad8 1e0c DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:53198 Action=Filter"
07/24/21 " 14:18:37.854" 322689531 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:64583 Action=Filter"
07/24/21 " 14:18:37.958" 322689640 0ad8 30ac DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:62560 Action=Filter"
07/24/21 " 14:18:37.986" 322689656 0ad8 1c88 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:63302 Action=Filter"
07/24/21 " 14:18:47.065" 322698734 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\backgroundTaskHost.exe), cmdline (""C:\Windows\system32\backgroundTaskHost.exe"" -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca)"
07/24/21 " 14:18:47.976" 322699656 0ad8 1c88 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:52798 Action=Filter"
07/24/21 " 14:18:48.055" 322699734 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 2508."
07/24/21 " 14:18:48.065" 322699734 0ad8 1e0c DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:64863 Action=Filter"
07/24/21 " 14:18:48.161" 322699843 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 2508."
07/24/21 " 14:18:48.167" 322699843 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 2508."
07/24/21 " 14:18:48.172" 322699843 0ad8 3b48 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:59941 Action=Filter"
07/24/21 " 14:18:48.243" 322699921 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 2508."
07/24/21 " 14:18:47.066" 322698745 0264 40a8 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\backgroundTaskHost.exe"
07/24/21 " 14:18:47.066" 322698745 0264 40a8 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:47.329" 322699000 0bbc 3e84 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000000BBC (\Device\HarddiskVolume5\Windows\System32\backgroundTaskHost.exe) is exiting"
07/24/21 " 14:18:51.929" 322703609 0ad8 3b48 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:61024 Action=Filter"
07/24/21 " 14:18:51.957" 322703625 0ad8 25ac DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:54536 Action=Filter"
07/24/21 " 14:18:51.961" 322703640 0ad8 1e0c DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:61998 Action=Filter"
07/24/21 " 14:18:54.783" 322706453 0ad8 3f50 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:63350 Action=Filter"
07/24/21 " 14:18:54.809" 322706484 0ad8 3f50 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:52587 Action=Filter"
07/24/21 " 14:18:54.837" 322706515 0ad8 3b48 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:62852 Action=Filter"
07/24/21 " 14:18:54.949" 322706625 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:57016 Action=Filter"
07/24/21 " 14:18:55.172" 322706843 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:63443 Action=Filter"
07/24/21 " 14:18:56.139" 322707812 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:59996 Action=Filter"
07/24/21 " 14:18:56.170" 322707843 0ad8 1c88 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:58238 Action=Filter"
07/24/21 " 14:18:56.195" 322707875 0ad8 2a04 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:51408 Action=Filter"
07/24/21 " 14:18:56.789" 322708468 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Program Files\Mozilla Firefox\firefox.exe), cmdline (""C:\Program Files\Mozilla Firefox\firefox.exe"" -contentproc --channel=""15280.308.733597909\1746122897"" -childID 43 -isForBrowser -prefsHandle 4224 -prefMapHandle 4848 -prefsLen 10959 -prefMapSize 252804 -jsInit 1524 285176 -parentBuildID 20210716144314 -appdir ""C:\Program Files\Mozilla Firefox\browser"" - 15280 ""\\.\pipe\gecko-crash-server-pipe.15280"" 6416 tab)"
07/24/21 " 14:18:56.796" 322708468 0ad8 05e4 DEBUG ArwSDK Combo__ProcessDropping "arde.combo.processdropping.cpp" 130 "tid: 3d3c - Process self executes: 15280:3092 - ""C:\Program Files\Mozilla Firefox\firefox.exe"" -contentproc --channel=""15280.308.733597909\1746122897"" -childID 43 -isForBrowser -prefsHandle 4224 -prefMapHandle 4848 -prefsLen 10959 -prefMapSize 252804 -jsInit 1524 285176 -parentBuildID 20210716144314 -appdir ""C:\Program Files\Mozilla Firefox\browser"" - 15280 ""\\.\pipe\gecko-crash-server-pipe.15280"" 6416 tab"
07/24/21 " 14:18:56.853" 322708531 0ad8 100c INFO AEControllerImpl mb::aecontrollerimpl::AEControllerImplHelper::DoAppInjectedNotification "aecontrollerimplhelper.cpp" 2591 "App Injected (Mozilla Firefox (and add-ons))"
07/24/21 " 14:18:57.058" 322708734 0ad8 1e0c DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:59726 Action=Filter"
07/24/21 " 14:18:57.084" 322708765 0ad8 25ac DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:60068 Action=Filter"
07/24/21 " 14:18:57.881" 322709562 0ad8 1c88 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:62109 Action=Filter"
07/24/21 " 14:18:57.908" 322709578 0ad8 2a04 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:54897 Action=Filter"
07/24/21 " 14:18:57.913" 322709593 0ad8 1e0c DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:55404 Action=Filter"
07/24/21 " 14:18:57.929" 322709609 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Program Files\Mozilla Firefox\firefox.exe), cmdline (""C:\Program Files\Mozilla Firefox\firefox.exe"" -contentproc --channel=""15280.315.632536565\1068102419"" -childID 44 -isForBrowser -prefsHandle 7020 -prefMapHandle 7088 -prefsLen 10959 -prefMapSize 252804 -jsInit 1524 285176 -parentBuildID 20210716144314 -appdir ""C:\Program Files\Mozilla Firefox\browser"" - 15280 ""\\.\pipe\gecko-crash-server-pipe.15280"" 1212 tab)"
07/24/21 " 14:18:57.935" 322709609 0ad8 05e4 DEBUG ArwSDK Combo__ProcessDropping "arde.combo.processdropping.cpp" 130 "tid: 3d3c - Process self executes: 15280:3092 - ""C:\Program Files\Mozilla Firefox\firefox.exe"" -contentproc --channel=""15280.315.632536565\1068102419"" -childID 44 -isForBrowser -prefsHandle 7020 -prefMapHandle 7088 -prefsLen 10959 -prefMapSize 252804 -jsInit 1524 285176 -parentBuildID 20210716144314 -appdir ""C:\Program Files\Mozilla Firefox\browser"" - 15280 ""\\.\pipe\gecko-crash-server-pipe.15280"" 1212 tab"
07/24/21 " 14:18:57.985" 322709656 0ad8 100c INFO AEControllerImpl mb::aecontrollerimpl::AEControllerImplHelper::DoAppInjectedNotification "aecontrollerimplhelper.cpp" 2591 "App Injected (Mozilla Firefox (and add-ons))"
07/24/21 " 14:18:56.790" 322708469 3bb0 0c14 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Program Files\Mozilla Firefox\firefox.exe"
07/24/21 " 14:18:56.790" 322708469 3bb0 0c14 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:18:59.461" 322711140 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:18:59.463" 322711140 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:18:57.930" 322709609 3bb0 0c14 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Program Files\Mozilla Firefox\firefox.exe"
07/24/21 " 14:18:57.930" 322709609 3bb0 0c14 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:19:00.012" 322711687 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.013" 322711687 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.013" 322711687 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.013" 322711687 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.014" 322711687 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.014" 322711687 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.014" 322711687 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.016" 322711687 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.018" 322711687 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.018" 322711687 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.018" 322711687 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.018" 322711687 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.020" 322711703 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.021" 322711703 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.021" 322711703 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.132" 322711812 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:19:00.133" 322711812 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:19:00.133" 322711812 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:19:00.135" 322711812 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:19:00.138" 322711812 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:19:00.138" 322711812 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:19:00.144" 322711812 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:19:00.146" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:00.147" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:00.147" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:00.147" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:00.149" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:00.150" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:00.150" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:00.151" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:00.151" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:00.151" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:00.152" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:19:00.152" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:19:00.152" 322711828 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:19:00.204" 322711875 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.206" 322711875 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.207" 322711875 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.207" 322711875 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.208" 322711890 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.208" 322711890 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.301" 322711984 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.301" 322711984 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.302" 322711984 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.302" 322711984 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.315" 322711984 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.315" 322711984 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.316" 322711984 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.337" 322712015 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.337" 322712015 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.337" 322712015 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.338" 322712015 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.338" 322712015 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:18:58.329" 322710000 4168 3154 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000004168 (\Device\HarddiskVolume5\Program Files\Mozilla Firefox\firefox.exe) is exiting"
07/24/21 " 14:19:00.408" 322712078 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.408" 322712078 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.408" 322712078 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.473" 322712156 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.474" 322712156 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.474" 322712156 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:00.475" 322712156 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:19:05.158" 322716828 0ad8 2a04 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:51527 Action=Filter"
07/24/21 " 14:19:05.165" 322716843 0ad8 25ac DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:61648 Action=Filter"
07/24/21 " 14:19:09.362" 322721031 0ad8 3f50 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:58500 Action=Filter"
07/24/21 " 14:19:09.385" 322721062 0ad8 3b48 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:54929 Action=Filter"
07/24/21 " 14:19:08.548" 322720219 2ff0 4458 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000002FF0 (\Device\HarddiskVolume5\Windows\System32\SearchProtocolHost.exe) is exiting"
07/24/21 " 14:19:08.556" 322720227 3810 1e28 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000003810 (\Device\HarddiskVolume5\Windows\System32\SearchFilterHost.exe) is exiting"
07/24/21 " 14:19:17.283" 322728953 0ad8 1e0c DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:56129 Action=Filter"
07/24/21 " 14:19:17.365" 322729046 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 2508."
07/24/21 " 14:19:17.405" 322729078 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 2508."
07/24/21 " 14:19:16.845" 322728516 26d4 46b8 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 00000000000026D4 (\Device\HarddiskVolume5\Windows\SysWOW64\backgroundTaskHost.exe) is exiting"
07/24/21 " 14:19:19.268" 322730937 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe."
07/24/21 " 14:19:19.269" 322730937 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe."
07/24/21 " 14:19:19.269" 322730937 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe."
07/24/21 " 14:19:19.269" 322730937 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe."
07/24/21 " 14:19:19.269" 322730937 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe."
07/24/21 " 14:19:19.270" 322730953 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe."
07/24/21 " 14:19:19.270" 322730953 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe."
07/24/21 " 14:19:19.270" 322730953 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe."
07/24/21 " 14:19:19.271" 322730953 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe."
07/24/21 " 14:19:19.271" 322730953 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe."
07/24/21 " 14:19:19.271" 322730953 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe."
07/24/21 " 14:19:19.271" 322730953 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe."
07/24/21 " 14:19:24.619" 322736296 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:59619 Action=Filter"
07/24/21 " 14:19:24.647" 322736328 0ad8 30ac DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:52814 Action=Filter"
07/24/21 " 14:19:28.102" 322739781 0ad8 1c88 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:57464 Action=Filter"
07/24/21 " 14:19:28.129" 322739812 0ad8 3f50 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:62601 Action=Filter"
07/24/21 " 14:19:30.044" 322741718 0ad8 3f50 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:59057 Action=Filter"
07/24/21 " 14:19:30.072" 322741750 0ad8 1e0c DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:50133 Action=Filter"
07/24/21 " 14:19:30.164" 322741843 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:30.166" 322741843 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:30.168" 322741843 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:30.169" 322741843 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:30.184" 322741859 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:30.185" 322741859 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:30.187" 322741859 0ad8 3cc0 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:54799 Action=Filter"
07/24/21 " 14:19:31.906" 322743578 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:31.906" 322743578 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:31.910" 322743593 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:31.911" 322743593 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:32.546" 322744218 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:32.546" 322744218 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:32.547" 322744218 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:32.553" 322744234 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe."
07/24/21 " 14:19:40.202" 322751875 0ad8 1c88 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:51554 Action=Filter"
07/24/21 " 14:19:40.242" 322751921 0ad8 30ac DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:61877 Action=Filter"
07/24/21 " 14:19:40.246" 322751921 0ad8 2a04 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:56317 Action=Filter"
07/24/21 " 14:19:40.828" 322752500 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Program Files\Mozilla Firefox\firefox.exe), cmdline (""C:\Program Files\Mozilla Firefox\firefox.exe"" -contentproc --channel=""15280.322.174564261\642334045"" -childID 45 -isForBrowser -prefsHandle 8220 -prefMapHandle 6552 -prefsLen 10959 -prefMapSize 252804 -jsInit 1524 285176 -parentBuildID 20210716144314 -appdir ""C:\Program Files\Mozilla Firefox\browser"" - 15280 ""\\.\pipe\gecko-crash-server-pipe.15280"" 9664 tab)"
07/24/21 " 14:19:40.835" 322752515 0ad8 05e4 DEBUG ArwSDK Combo__ProcessDropping "arde.combo.processdropping.cpp" 130 "tid: 3d3c - Process self executes: 15280:3092 - ""C:\Program Files\Mozilla Firefox\firefox.exe"" -contentproc --channel=""15280.322.174564261\642334045"" -childID 45 -isForBrowser -prefsHandle 8220 -prefMapHandle 6552 -prefsLen 10959 -prefMapSize 252804 -jsInit 1524 285176 -parentBuildID 20210716144314 -appdir ""C:\Program Files\Mozilla Firefox\browser"" - 15280 ""\\.\pipe\gecko-crash-server-pipe.15280"" 9664 tab"
07/24/21 " 14:19:40.896" 322752578 0ad8 100c INFO AEControllerImpl mb::aecontrollerimpl::AEControllerImplHelper::DoAppInjectedNotification "aecontrollerimplhelper.cpp" 2591 "App Injected (Mozilla Firefox (and add-ons))"
07/24/21 " 14:19:40.828" 322752507 3bb0 0c14 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Program Files\Mozilla Firefox\firefox.exe"
07/24/21 " 14:19:40.828" 322752507 3bb0 0c14 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:19:45.597" 322757265 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\NOTEPAD.EXE), cmdline (""C:\Windows\system32\NOTEPAD.EXE"" C:\ProgramData\Malwarebytes\MBAMService\LOGS\MBAMSERVICE.LOG)"
07/24/21 " 14:19:45.686" 322757359 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\SearchProtocolHost.exe), cmdline (""C:\Windows\system32\SearchProtocolHost.exe"" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-3267400732-2583111342-1326098953-100116_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-3267400732-2583111342-1326098953-100116 1 -2147483646 ""Software\Microsoft\Windows Search"" ""Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)"" ""C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc"" ""DownLevelDaemon"" ""1"")"
07/24/21 " 14:19:45.702" 322757375 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\SearchFilterHost.exe), cmdline (""C:\Windows\system32\SearchFilterHost.exe"" 0 800 804 812 8192 808 784 )"
07/24/21 " 14:19:46.250" 322757921 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:19:45.597" 322757276 16c8 158c DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\NOTEPAD.EXE"
07/24/21 " 14:19:45.597" 322757276 16c8 158c DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:19:45.687" 322757366 2748 2870 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\SearchProtocolHost.exe"
07/24/21 " 14:19:45.687" 322757366 2748 2870 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:19:45.703" 322757382 2748 2870 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\SearchFilterHost.exe"
07/24/21 " 14:19:45.703" 322757382 2748 2870 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:19:46.861" 322758532 3fc4 3478 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000003FC4 (\Device\HarddiskVolume5\Windows\System32\RuntimeBroker.exe) is exiting"
07/24/21 " 14:19:51.995" 322763671 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:20:18.033" 322789703 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\backgroundTaskHost.exe), cmdline (""C:\Windows\system32\backgroundTaskHost.exe"" -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca)"
07/24/21 " 14:20:18.033" 322789703 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxTsr.exe), cmdline (""C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxTsr.exe"" -ServerName:Hx.IPC.Server)"
07/24/21 " 14:20:18.113" 322789796 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\System32\RuntimeBroker.exe), cmdline (C:\Windows\System32\RuntimeBroker.exe -Embedding)"
07/24/21 " 14:20:18.171" 322789843 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\BackgroundTaskHost.exe), cmdline (""C:\Windows\system32\BackgroundTaskHost.exe"" -ServerName:BackgroundTaskHost.WebAccountProvider)"
07/24/21 " 14:20:18.643" 322790312 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:20:18.644" 322790312 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:20:18.672" 322790343 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:20:18.697" 322790375 0ad8 37cc DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::IsFileSignatureValidPerWinVerifyTrust "rtpcontrollerimplhelper.cpp" 6517 "Signature validation using WinVerifyTrust (with local cache revocation check) for 'C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.1110_none_91a01826cc8bca4c\GdiPlus.dll'"
07/24/21 " 14:20:18.697" 322790375 0ad8 37cc DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::IsFileSignatureValidPerWinVerifyTrust "rtpcontrollerimplhelper.cpp" 6558 "WinVerifyTrust failed for file='C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.1110_none_91a01826cc8bca4c\GdiPlus.dll', result=0x800b0100, last error='Es war keine Signatur im Antragsteller vorhanden. (0x800b0100)'"
07/24/21 " 14:20:18.697" 322790375 0ad8 37cc DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::ValidateAndExtractCertificateInfo "rtpcontrollerimplhelper.cpp" 6510 "Certificate validation completed for C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.1110_none_91a01826cc8bca4c\GdiPlus.dll, CertSubjectCName: "
07/24/21 " 14:20:18.707" 322790375 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 14740."
07/24/21 " 14:20:18.034" 322789713 0264 40a8 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\backgroundTaskHost.exe"
07/24/21 " 14:20:18.034" 322789705 0264 4758 DEBUG MBAMChameleon VerifyFile "fileverify.cpp" 479 "Opening \??\C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxTsr.exe for verification"
07/24/21 " 14:20:18.034" 322789713 0264 40a8 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:20:18.270" 322789941 3bd4 2430 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000003BD4 (\Device\HarddiskVolume5\Windows\System32\backgroundTaskHost.exe) is exiting"
07/24/21 " 14:20:18.034" 322789713 0264 4758 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxTsr.exe"
07/24/21 " 14:20:18.285" 322789956 1fa4 3e10 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000001FA4 (\Device\HarddiskVolume5\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxTsr.exe) is exiting"
07/24/21 " 14:20:18.034" 322789713 0264 4758 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:20:18.114" 322789793 0264 4758 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\System32\RuntimeBroker.exe"
07/24/21 " 14:20:18.114" 322789793 0264 4758 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:20:18.172" 322789851 0264 0530 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\BackgroundTaskHost.exe"
07/24/21 " 14:20:18.172" 322789851 0264 0530 DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:20:18.695" 322790374 0ad8 2630 DEBUG MBAMProtection MbamMessage "protector.c" 762 "SET_EVENT_TIMEOUT - MessageId (26475), Timeout (60)"
07/24/21 " 14:20:18.695" 322790374 0ad8 2630 DEBUG MBAMProtection SetEventTimeout "comm.c" 630 "Set event timeout for message 26475 to 60 seconds"
07/24/21 " 14:20:19.367" 322791038 4744 43d4 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000004744 (\Device\HarddiskVolume5\Windows\System32\backgroundTaskHost.exe) is exiting"
07/24/21 " 14:20:42.387" 322814062 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe), cmdline (""C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"" /ua /installsource scheduler)"
07/24/21 " 14:20:42.422" 322814093 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe."
07/24/21 " 14:20:42.387" 322814066 0614 0b2c DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"
07/24/21 " 14:20:42.387" 322814066 0614 0b2c DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:20:42.436" 322814107 42b4 18d0 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 00000000000042B4 (\Device\HarddiskVolume5\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe) is exiting"
07/24/21 " 14:20:57.500" 322829171 0ad8 30ac DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:63208 Action=Filter"
07/24/21 " 14:20:57.046" 322828717 3f48 1f28 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000003F48 (\Device\HarddiskVolume5\Program Files\Mozilla Firefox\firefox.exe) is exiting"
07/24/21 " 14:20:59.348" 322831031 0ad8 1c88 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:57735 Action=Filter"
07/24/21 " 14:20:59.473" 322831156 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:20:59.473" 322831156 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe."
07/24/21 " 14:20:58.095" 322829766 11fc 1e88 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 00000000000011FC (\Device\HarddiskVolume5\Program Files\Mozilla Firefox\firefox.exe) is exiting"
07/24/21 " 14:21:00.481" 322832156 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:21:00.541" 322832218 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:21:00.543" 322832218 0ad8 1134 DEBUG RTPControllerImpl mb::rtpcontrollerimpl::RTPControllerImpl::HandleFileCreateNotification "rtpcontrollerimplhelper.cpp" 1468 "Could not get file path for process id 4632."
07/24/21 " 14:20:59.389" 322831060 1ed8 34a0 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000001ED8 (\Device\HarddiskVolume5\Windows\System32\RuntimeBroker.exe) is exiting"
07/24/21 " 14:21:08.533" 322840204 2664 2bd8 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000002664 (\Device\HarddiskVolume5\Windows\System32\SearchProtocolHost.exe) is exiting"
07/24/21 " 14:21:08.539" 322840210 131c 4318 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 000000000000131C (\Device\HarddiskVolume5\Windows\System32\SearchFilterHost.exe) is exiting"
07/24/21 " 14:21:12.070" 322843750 0ad8 1c88 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:61745 Action=Filter"
07/24/21 " 14:21:12.097" 322843765 0ad8 2a04 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:59308 Action=Filter"
07/24/21 " 14:21:29.181" 322860859 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessARWUploads "cloudcontrollerimplhelper.cpp" 1914 "Enter ProcessARWUploads"
07/24/21 " 14:21:30.196" 322861875 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessAEUploads "cloudcontrollerimplhelper.cpp" 2006 "Enter ProcessAEUploads"
07/24/21 " 14:21:31.211" 322862890 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessShurikenUploads "cloudcontrollerimplhelper.cpp" 2097 "Enter ProcessShurikenUploads"
07/24/21 " 14:21:32.219" 322863890 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessRootkitUploads "cloudcontrollerimplhelper.cpp" 2188 "Enter ProcessRootkitUploads"
07/24/21 " 14:21:33.225" 322864906 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessDopplegangUploads "cloudcontrollerimplhelper.cpp" 2279 "Enter ProcessDopplegangUploads"
07/24/21 " 14:21:34.227" 322865906 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessMWACUploads "cloudcontrollerimplhelper.cpp" 2372 "Enter ProcessMWACUploads"
07/24/21 " 14:21:35.237" 322866906 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessDDSUploads "cloudcontrollerimplhelper.cpp" 2471 "Enter ProcessDDSUploads"
07/24/21 " 14:21:35.237" 322866906 0ad8 3a80 DEBUG CloudCtrlImpl CloudControllerImplHelper::ProcessDDSUploads "cloudcontrollerimplhelper.cpp" 2491 "No DDS uploads to process at this time."
07/24/21 " 14:21:36.831" 322868502 1aac 2244 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 0000000000001AAC (\Device\HarddiskVolume5\Program Files\Mozilla Firefox\firefox.exe) is exiting"
07/24/21 " 14:21:49.314" 322880984 0ad8 3f50 DEBUG MwacLib NetworkEventHandler::onConnectRequest "networkeventhandler.cpp" 433 "Outbound UDP connection: ProcessId=4056 (C:\Windows\System32\svchost.exe) RemoteAddress=192.168.178.1:53 LocalAddress=192.168.178.45:61904 Action=Filter"
07/24/21 " 14:21:51.980" 322883656 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\wermgr.exe), cmdline (C:\Windows\system32\wermgr.exe -upload)"
07/24/21 " 14:21:52.017" 322883687 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Windows\System32\wermgr.exe."
07/24/21 " 14:21:52.020" 322883703 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Windows\System32\wermgr.exe."
07/24/21 " 14:21:52.020" 322883703 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Windows\System32\wermgr.exe."
07/24/21 " 14:21:52.037" 322883718 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Windows\System32\wermgr.exe."
07/24/21 " 14:21:52.038" 322883718 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Windows\System32\wermgr.exe."
07/24/21 " 14:21:52.038" 322883718 0ad8 2624 DEBUG MBAMShimImpl MBAMShimImpl::ProcessFileSystemCreationEvent "mbamshimimpl.cpp" 613 "No ZoneId info available on file, C:\Windows\System32\wermgr.exe."
07/24/21 " 14:21:51.980" 322883659 0614 0b2c DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1938 "Process create - \??\C:\Windows\system32\wermgr.exe"
07/24/21 " 14:21:51.975" 322883646 0614 0b2c DEBUG MBAMChameleon VerifyFile "fileverify.cpp" 479 "Opening \??\C:\Windows\system32\wermgr.exe for verification"
07/24/21 " 14:21:52.211" 322883882 18fc 41e4 DEBUG MBAMChameleon ProcessNotify "procprot.c" 591 "CreateProcess: Process 00000000000018FC (\Device\HarddiskVolume5\Windows\System32\wermgr.exe) is exiting"
07/24/21 " 14:21:51.980" 322883659 0614 0b2c DEBUG MBAMProtection RtpProcessCreateNotifyRoutine "filter.c" 1998 "Process create - game mode list is empty"
07/24/21 " 14:22:00.115" 322891796 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\SearchProtocolHost.exe), cmdline (""C:\Windows\system32\SearchProtocolHost.exe"" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-3267400732-2583111342-1326098953-100117_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-3267400732-2583111342-1326098953-100117 1 -2147483646 ""Software\Microsoft\Windows Search"" ""Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)"" ""C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc"" ""DownLevelDaemon"" ""1"")"
07/24/21 " 14:22:00.133" 322891812 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\SearchFilterHost.exe), cmdline (""C:\Windows\system32\SearchFilterHost.exe"" 0 800 804 812 8192 808 784 )"
07/24/21 " 14:22:01.620" 322893296 0ad8 3c34 DEBUG RtpSDK RtpUserImpl::MessageLoop "rtpuserimpl.cpp" 719 "Request process disposition for (C:\Windows\system32\NOTEPAD.EXE), cmdline (""C:\Windows\system32\NOTEPAD.EXE"" C:\ProgramData\Malwarebytes\MBAMService\LOGS\MBAMSERVICE.LOG)" |