KGRKJGETMRETU895U-589TY5MIGM5JGB5SDFESFREWTGR54TY
Server : Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
System : Windows NT SERVER-PC 10.0 build 26200 (Windows 11) AMD64
User : ServerPC ( 0)
PHP Version : 8.2.12
Disable Function : NONE
Directory :  C:/ProgramData/Microsoft/Windows Defender/Support/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : C:/ProgramData/Microsoft/Windows Defender/Support/MPLog-20251120-140245.log
��

2025-11-20T13:42:32.736 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1442, Count: 81, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 78%

2025-11-20T13:42:32.736 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 945, Count: 112, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Desktop\desktop.ini->(UTF-16LE), EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: setup.exe, Pid: 19180, TotalTime: 555, Count: 153, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeCore\142.0.3595.90\Installer\msedge_7z.data, EstimatedImpact: 47%

2025-11-20T13:42:32.736 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 552, Count: 28, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server.exe, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: , Pid: 4, TotalTime: 540, Count: 92, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy9\System Volume Information\{3070b5dc-ba74-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 1%

2025-11-20T13:42:32.736 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 482, Count: 10, MaxTime: 437, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\DO6E63.tmp, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 285, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan->(UTF-16LE), EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 19528, TotalTime: 270, Count: 69, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: taskhostw.exe, Pid: 15856, TotalTime: 255, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\UusSettings.json, EstimatedImpact: 34%

2025-11-20T13:42:32.736 ProcessImageName: RuntimeBroker.exe, Pid: 24512, TotalTime: 243, Count: 19, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, EstimatedImpact: 19%

2025-11-20T13:42:32.736 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 240, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 225, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: svchost.exe, Pid: 19260, TotalTime: 225, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{7ee99ab6-689a-481e-b338-2da6974c8a97}_OnDiskSnapshotProp, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 210, Count: 96, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.276.298.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 154, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 2372, TotalTime: 124, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeUpdate\Install\{7A812816-4763-455F-B140-0C3220F7D758}\MicrosoftEdge_X64_142.0.3595.90_142.0.3595.80.exe, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: MicrosoftEdge_X64_142.0.3595.90_142.0.3595.80.exe, Pid: 12796, TotalTime: 93, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeUpdate\Install\{7A812816-4763-455F-B140-0C3220F7D758}\EDGEMITMP_43F02.tmp\setup.exe, EstimatedImpact: 63%

2025-11-20T13:42:32.736 ProcessImageName: DeviceCensus.exe, Pid: 21412, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3, EstimatedImpact: 2%

2025-11-20T13:42:32.736 ProcessImageName: MicrosoftEdge_X64_142.0.3595.90_142.0.3595.80.exe, Pid: 10420, TotalTime: 62, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeUpdate\Install\{DAD27ADC-C76F-444E-8224-14661A220405}\EDGEMITMP_5EC96.tmp\setup.exe, EstimatedImpact: 58%

2025-11-20T13:42:32.736 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\e780c487dceb427d1cf19f52519f48b87705e5b0.tbres->(UTF-16LE), EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: backgroundTaskHost.exe, Pid: 16340, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1763618599, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: taskhostw.exe, Pid: 19108, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 3%

2025-11-20T13:42:32.736 ProcessImageName: taskhostw.exe, Pid: 5888, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 24%

2025-11-20T13:42:32.736 ProcessImageName: taskhostw.exe, Pid: 9212, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 27%

2025-11-20T13:42:32.736 ProcessImageName: NVIDIA Overlay.exe, Pid: 20964, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\dcca6fb1-6c6a-4a95-8caa-4efc769b0e0c.tmp, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: taskhostw.exe, Pid: 24544, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-20T13:42:32.736 ProcessImageName: HxTsr.exe, Pid: 22556, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 19%

2025-11-20T13:42:32.736 ProcessImageName: taskhostw.exe, Pid: 10456, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-20T13:42:32.736 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: updater.exe, Pid: 22904, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\41f34ad6-9626-42b1-aaba-e7205e69ffd6.tmp, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: taskhostw.exe, Pid: 23220, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 1%

2025-11-20T13:42:32.736 ProcessImageName: updater.exe, Pid: 3528, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: updater.exe, Pid: 24008, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\d830da2f-f866-48ab-91ea-c80b1535d651.tmp, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: FileCoAuth.exe, Pid: 528, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 0%

2025-11-20T13:42:32.736 ProcessImageName: SrTasks.exe, Pid: 17652, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 0%

2025-11-20T13:47:35.184 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T13:52:06.650 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #80026, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T13:52:06.652 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #80027, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T13:52:16.654 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #80037, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T13:52:16.658 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #80038, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T14:02:30.490 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #80269, FileId: 0x1e2000000003419, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T14:02:39.757 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\EA34750B-2EF5-415C-BDE8-3308DE9D0C7A1e4c.1dc5a26544a3c1f

2025-11-20T14:02:39.788 Verifying engine and signature files (source: 0) ...

2025-11-20T14:02:39.788 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{25276C58-91FF-48B3-84AB-FB9ACA19A637}\mpengine.dll] due to PPL.

2025-11-20T14:02:39.788 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{25276C58-91FF-48B3-84AB-FB9ACA19A637}\mpasbase.vdm] (file in cache)

2025-11-20T14:02:39.788 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{25276C58-91FF-48B3-84AB-FB9ACA19A637}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-20T14:02:39.796 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{25276C58-91FF-48B3-84AB-FB9ACA19A637}\mpasdlta.vdm]

2025-11-20T14:02:39.796 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{25276C58-91FF-48B3-84AB-FB9ACA19A637}\mpavbase.vdm] (file in cache)

2025-11-20T14:02:39.796 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{25276C58-91FF-48B3-84AB-FB9ACA19A637}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-20T14:02:39.804 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{25276C58-91FF-48B3-84AB-FB9ACA19A637}\mpavdlta.vdm]

2025-11-20T14:02:39.876 [Engine] IsHybridMode: 0

2025-11-20T14:02:39.876 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-20T14:02:39.881 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-4AB0E44F8D305819D639E8F8A0C85EFC0ADE8165.bin): 0x00000002

2025-11-20T14:02:39.883 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-4AB0E44F8D305819D639E8F8A0C85EFC0ADE8165.bin)

2025-11-20T14:02:39.883 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-20T14:02:39.883 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-20T14:02:39.883 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-20T14:02:39.883 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

2025-11-20T14:02:40.174 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-20T14:02:45.175 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-20T14:02:45.176 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-20T14:02:45.180 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE6F7CA660, lRefCount: 5, hr=0

2025-11-20T14:02:45.180 [Engine] New active engine 00007FFE717EA660 replacing engine 00007FFE6F7CA660. Number of active engines: 2

2025-11-20T14:02:45.183 EngineInit:Global ASOC is enabled

2025-11-20T14:02:45.183 EngineInit:ASOO is enabled for developer volumes

2025-11-20T14:02:45.212 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-20T14:02:45.213 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.213 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-20T14:02:45.213 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-20T14:02:45.213 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-20T14:02:45.215 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.215 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.215 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.215 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-20T14:02:45.217 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.217 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.217 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-20T14:02:45.218 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.218 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.218 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.218 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.219 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.219 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.219 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.220 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-20T14:02:45.220 MpWriteUupSignatureVersion 1.441.359.0, hr = 0

2025-11-20T14:02:45.222 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-20T14:02:45.233 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-20T14:02:45.234 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-20T14:02:45.234 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-20T14:02:45.234 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-20T14:02:45.234 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-20T14:02:45.249 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-20T14:02:45.249 [Plugin] Initializing RTP plugin state...

2025-11-20T14:02:45.249 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-20T14:02:45.249 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 20 - 2025 02:42:33

Last Perf: 11 - 20 - 2025 02:42:32

First RTP Scan: 11 - 20 - 2025 02:42:33

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1468

  Misses:9229

BM Queue:0,44,0

  Proc:0,44,0

  File:0,25,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,2,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:80356

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:644331528

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:17

  TotalStreamCon:19410

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:423175

   TotalHits:813393

   InstanceCacheInserts:29460

   InstanceCacheUpdates:0

   InstanceCacheDeletes:20773

   InstanceCacheHits:1056

   InstanceCacheMisses:145085

   InstanceCacheOverflows:0

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (3339/3387)

   Success: 3387, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-20T14:02:45.249 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{25276C58-91FF-48B3-84AB-FB9ACA19A637}

2025-11-20T14:02:45.249 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C9202372-DAE5-476D-A533-3F661BEC6E13}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C9202372-DAE5-476D-A533-3F661BEC6E13}\mpasbase.vdm in use, hr=0x80070020

2025-11-20T14:02:45.249 [SCC][CID=332592296_7840] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-20T14:02:45.250 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-20T14:02:45.250 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-20T14:02:45.250 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-20T14:02:45.250 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-20T14:02:45.250 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-20T14:02:45.250 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-20-2025 14:02:45

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-20-2025 14:02:45

2025-11-20T14:02:45.253 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-20T14:02:45.253 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-20T14:02:45.253 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-20T14:02:45.253 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-20-2025 14:02:45

END TDT(U) telemetry



2025-11-20T14:02:45.256 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-20T14:02:45.256 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-20T14:02:45.256 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-20T14:02:45.256 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-20T14:02:45.256 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-20T14:02:45.256 MdCoreSvc is supported in this platform and OS

Signature updated on 11-20-2025 14:02:45

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.359.0

AV Signature Version: 1.441.359.0

************************************************************

2025-11-20T14:02:45.258 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-20T14:02:45.258 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\EA34750B-2EF5-415C-BDE8-3308DE9D0C7A1e4c.1dc5a26544a3c1f

2025-11-20T14:02:45.276 Process scan (postsignatureupdatescan) started.

2025-11-20T14:02:45.294 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-20T14:02:45.296 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-20T14:02:45.426 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-20T14:02:45.426 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-20T14:02:45.426 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-20T14:02:45.426 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-20T14:02:45.426 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-20T14:02:45.428 [Engine] Engine 00007FFE6F7CA660 no longer in use. Number of active engines: 1

2025-11-20T14:02:45.428 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-20T14:02:45.428 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-20T14:02:45.574 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 5182, Count: 535, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\501fcff6-09c0-4955-8515-38f734f2a228.tmp, EstimatedImpact: 0%

2025-11-20T14:02:45.574 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 4115, Count: 331, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\e3914773-9c3d-4b50-90c7-40ccd96bc197.tmp, EstimatedImpact: 0%

2025-11-20T14:02:45.574 ProcessImageName: setup.exe, Pid: 22328, TotalTime: 2185, Count: 215, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeCore\142.0.3595.90\dxcompiler.dll, EstimatedImpact: 14%

2025-11-20T14:02:45.574 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1442, Count: 81, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 78%

2025-11-20T14:02:45.574 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 945, Count: 112, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Desktop\desktop.ini->(UTF-16LE), EstimatedImpact: 0%

2025-11-20T14:02:45.574 ProcessImageName: setup.exe, Pid: 19180, TotalTime: 555, Count: 153, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeCore\142.0.3595.90\Installer\msedge_7z.data, EstimatedImpact: 47%

2025-11-20T14:02:45.574 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 552, Count: 28, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server.exe, EstimatedImpact: 0%

2025-11-20T14:02:45.574 ProcessImageName: , Pid: 4, TotalTime: 540, Count: 92, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy9\System Volume Information\{3070b5dc-ba74-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 1%

2025-11-20T14:02:45.574 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 482, Count: 10, MaxTime: 437, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\DO6E63.tmp, EstimatedImpact: 0%

2025-11-20T14:02:45.574 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 300, Count: 65, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan->(UTF-16LE), EstimatedImpact: 0%

2025-11-20T14:02:45.574 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 19528, TotalTime: 270, Count: 71, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-20T14:02:45.574 ProcessImageName: taskhostw.exe, Pid: 15856, TotalTime: 255, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\UusSettings.json, EstimatedImpact: 34%

2025-11-20T14:02:45.574 ProcessImageName: RuntimeBroker.exe, Pid: 24512, TotalTime: 243, Count: 19, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, EstimatedImpact: 19%

2025-11-20T14:02:45.574 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 240, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-20T14:02:45.574 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 225, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-20T14:02:45.574 ProcessImageName: svchost.exe, Pid: 19260, TotalTime: 225, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{7ee99ab6-689a-481e-b338-2da6974c8a97}_OnDiskSnapshotProp, EstimatedImpact: 0%

2025-11-20T14:02:45.591 [Engine] RSIG_UNLOADENGINE, 00007FFE6F7CA660, err=0x0

2025-11-20T14:02:45.606 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C9202372-DAE5-476D-A533-3F661BEC6E13} removed

2025-11-20T14:02:45.749 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-20T14:02:45.758 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-20T14:02:45.758 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-20T14:02:45.758 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-20T14:02:45.758 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-20T14:02:45.758 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-20T14:02:45.758 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-20T14:02:45.761 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-20T14:02:45.761 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-20T14:02:45.761 [RTP] Duplicating the current plugin configuration object...

2025-11-20T14:02:45.761 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-20T14:02:45.761 [RTP] Updating plugin configuration due to recent config changes (0x22) ...

2025-11-20T14:02:45.761 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-20T14:02:45.761 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-20T14:02:45.761 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-20T14:02:45.761 [RTP] No config change detected. Not updating plugin configuration.

2025-11-20T14:02:45.761 [RTP] No config changes found. No configuration switch.

2025-11-20T14:02:45.761 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x22, Changed: 0

2025-11-20T14:02:45.761 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-20T14:02:45.761 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-20T14:02:45.762 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-20T14:02:45.762 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-20T14:02:45.762 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-20T14:02:45.762 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-20T14:02:45.762 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-20T14:02:45.762 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-20T14:02:45.762 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-20T14:02:45.762 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-20T14:02:45.762 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-20T14:02:45.762 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-20T14:02:45.762 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-20T14:02:45.762 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-20T14:02:45.762 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-20T14:02:45.765 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-20T14:02:45.766 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-20T14:02:45.768 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-20T14:02:45.770 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-20T14:02:45.771 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 50559839(ms) from now at 05:05 (04:05 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-20T14:02:47.272 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-20T14:02:47.275 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-20T14:02:47.276 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-20T14:02:48.316 [RTP] Duplicating the current plugin configuration object...

2025-11-20T14:02:48.316 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-20T14:02:48.316 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-20T14:02:48.316 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-20T14:02:48.316 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

2025-11-20T14:02:56.373 Process scan (postsignatureupdatescan) completed.

2025-11-20T14:07:45.208 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-20T14:17:45.177 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T14:22:24.339 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #81008, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T14:22:24.342 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #81011, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T14:22:37.843 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #81017, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T14:22:37.846 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #81018, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T14:32:50.170 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T14:47:55.161 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T14:52:06.460 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #81492, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T14:52:06.463 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #81493, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T14:52:16.473 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #81498, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T14:52:16.478 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #81499, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T15:03:00.158 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T15:18:05.145 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T15:20:10.042 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #82280, FileId: 0xdc000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T15:24:53.810 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Windows\Logs\DISM\dism.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #82666, FileId: 0x6f0000000261a8, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T15:33:10.139 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T15:37:57.558 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume4\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #82847, FileId: 0x3300000000c78a, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T15:48:15.134 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T15:52:07.125 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #83077, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T15:52:07.128 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #83078, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T15:52:17.138 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #83091, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T15:52:17.142 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #83092, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T15:55:04.443 Bm signature throttled:0x0000fab3228bcd4d

2025-11-20T16:02:45.145 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 840, Count: 87, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\dca6fd5c-ffdb-4976-8620-825e452ced59.tmp, EstimatedImpact: 0%

2025-11-20T16:02:45.145 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 631, Count: 53, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\8d5943b2-cdc6-47f7-b5d0-df64c6ff1436.tmp, EstimatedImpact: 0%

2025-11-20T16:02:45.145 ProcessImageName: RuntimeBroker.exe, Pid: 15708, TotalTime: 324, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 23%

2025-11-20T16:02:45.145 ProcessImageName: svchost.exe, Pid: 24088, TotalTime: 296, Count: 2, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 95%

2025-11-20T16:02:45.145 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 240, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-20T16:02:45.145 ProcessImageName: WmiPrvSE.exe, Pid: 17044, TotalTime: 168, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 100%

2025-11-20T16:02:45.145 ProcessImageName: ngentask.exe, Pid: 5572, TotalTime: 165, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 19%

2025-11-20T16:02:45.145 ProcessImageName: taskhostw.exe, Pid: 7592, TotalTime: 120, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-20T16:02:45.145 ProcessImageName: ngentask.exe, Pid: 19056, TotalTime: 90, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 9%

2025-11-20T16:02:45.145 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-20T16:02:45.145 ProcessImageName: ngentask.exe, Pid: 12944, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 16%

2025-11-20T16:02:45.145 ProcessImageName: ngentask.exe, Pid: 18732, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 37%

2025-11-20T16:02:45.145 ProcessImageName: ngentask.exe, Pid: 9024, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 52%

2025-11-20T16:02:45.145 ProcessImageName: taskhostw.exe, Pid: 24480, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 2%

2025-11-20T16:02:45.145 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-20T16:02:45.145 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-20T16:02:45.145 ProcessImageName: ngentask.exe, Pid: 23332, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 15%

2025-11-20T16:02:45.145 ProcessImageName: taskhostw.exe, Pid: 21656, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 26%

2025-11-20T16:02:45.145 ProcessImageName: taskhostw.exe, Pid: 8708, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-20T16:02:45.145 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 25%

2025-11-20T16:02:45.145 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 19528, TotalTime: 15, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\401d44483c00cbf832531ee06b1ff1d7f8a5c686.tbres, EstimatedImpact: 0%

2025-11-20T16:02:45.145 ProcessImageName: StoreDesktopExtension.exe, Pid: 9380, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\zoneinfo64.res, EstimatedImpact: 0%

2025-11-20T16:02:45.145 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1%

2025-11-20T16:02:45.145 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-20T16:03:20.142 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T16:18:25.126 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T16:33:30.129 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T16:48:35.129 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T16:52:07.037 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #84003, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T16:52:07.040 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #84004, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T16:52:17.041 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #84009, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T16:52:17.042 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #84010, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T16:52:17.044 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #84011, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T16:52:17.045 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #84012, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T17:03:40.122 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T17:18:45.111 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T17:33:50.115 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T17:39:49.784 Bm signature throttled:0x00002db31bed458f

2025-11-20T17:48:55.108 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T17:52:06.749 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #86487, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T17:52:06.752 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #86488, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T17:52:16.756 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #86493, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T17:52:16.760 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #86494, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T17:55:06.499 Bm signature throttled:0x0000fab3228bcd4d

2025-11-20T18:01:38.378 Bm signature throttled:0x00002db31bed458f

2025-11-20T18:02:45.113 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 1650, Count: 174, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\dca6fd5c-ffdb-4976-8620-825e452ced59.tmp, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1458, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 89%

2025-11-20T18:02:45.113 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 1456, Count: 121, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\8d5943b2-cdc6-47f7-b5d0-df64c6ff1436.tmp, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1411, Count: 202, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\9ae8d73b9169c6c46e8765bddfce4464e102df4e8c61d447450ceda38fec9d1f\Ontology64.dll, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: RuntimeBroker.exe, Pid: 15708, TotalTime: 324, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 23%

2025-11-20T18:02:45.113 ProcessImageName: svchost.exe, Pid: 24088, TotalTime: 296, Count: 2, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 95%

2025-11-20T18:02:45.113 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 270, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 195, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: WmiPrvSE.exe, Pid: 17044, TotalTime: 168, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 100%

2025-11-20T18:02:45.113 ProcessImageName: ngentask.exe, Pid: 5572, TotalTime: 165, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 19%

2025-11-20T18:02:45.113 ProcessImageName: taskhostw.exe, Pid: 7592, TotalTime: 120, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-20T18:02:45.113 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 120, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Data\12\12e4023f9dfe2864546b5818629eddf81c1ac215.file, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 107, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 105, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 105, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: ngentask.exe, Pid: 19056, TotalTime: 90, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 9%

2025-11-20T18:02:45.113 ProcessImageName: ngentask.exe, Pid: 12944, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 16%

2025-11-20T18:02:45.113 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 1%

2025-11-20T18:02:45.113 ProcessImageName: NVIDIA Overlay.exe, Pid: 20964, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\8951a2b4-39ab-4100-a0b3-2dfef30a883e.tmp, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: ngentask.exe, Pid: 9024, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 52%

2025-11-20T18:02:45.113 ProcessImageName: ngentask.exe, Pid: 18732, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 37%

2025-11-20T18:02:45.113 ProcessImageName: taskhostw.exe, Pid: 24480, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 2%

2025-11-20T18:02:45.113 ProcessImageName: ngentask.exe, Pid: 23332, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 15%

2025-11-20T18:02:45.113 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 19528, TotalTime: 45, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\401d44483c00cbf832531ee06b1ff1d7f8a5c686.tbres, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: taskhostw.exe, Pid: 21656, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 26%

2025-11-20T18:02:45.113 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 2%

2025-11-20T18:02:45.113 ProcessImageName: PhoneExperienceHost.exe, Pid: 13604, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\1044\StructuredQuerySchema.bin, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: taskhostw.exe, Pid: 8708, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-20T18:02:45.113 ProcessImageName: taskhostw.exe, Pid: 6732, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-20T18:02:45.113 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 25%

2025-11-20T18:02:45.113 ProcessImageName: taskhostw.exe, Pid: 11536, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-20T18:02:45.113 ProcessImageName: updater.exe, Pid: 8596, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\64cdb30b-1bb0-4c92-86d1-8627ec5eece5.tmp, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: StoreDesktopExtension.exe, Pid: 9380, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\zoneinfo64.res, EstimatedImpact: 0%

2025-11-20T18:02:45.113 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 3%

2025-11-20T18:02:45.113 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1%

2025-11-20T18:02:45.113 ProcessImageName: nvngx_update.exe, Pid: 13936, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\1\files\nvngx_mapping.json, EstimatedImpact: 2%

2025-11-20T18:02:45.113 ProcessImageName: svchost.exe, Pid: 20348, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_20964_1015595098\BIT67DD.tmp, EstimatedImpact: 1%

2025-11-20T18:02:45.113 ProcessImageName: nvngx_update.exe, Pid: 16748, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-20T18:04:00.094 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T18:19:05.099 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T18:34:10.087 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T18:49:15.091 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T18:52:05.672 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #87705, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T18:52:05.676 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #87706, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T18:52:15.677 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #87711, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T18:52:15.681 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #87712, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T19:04:20.086 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T19:19:25.083 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T19:22:27.814 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #88027, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T19:22:27.817 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #88030, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T19:22:42.738 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #88033, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T19:22:42.741 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #88034, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T19:22:42.753 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #88035, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T19:22:42.757 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #88036, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T19:34:30.078 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T19:49:35.062 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T19:52:05.251 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #88711, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T19:52:05.254 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #88712, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T19:52:15.263 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #88719, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T19:52:15.266 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #88720, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T19:55:08.668 Bm signature throttled:0x0000fab3228bcd4d

2025-11-20T20:01:09.785 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #88831, FileId: 0x1e3000000003419, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T20:02:45.087 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 2520, Count: 261, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\dca6fd5c-ffdb-4976-8620-825e452ced59.tmp, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 2266, Count: 185, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\8d5943b2-cdc6-47f7-b5d0-df64c6ff1436.tmp, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1501, Count: 220, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\9ae8d73b9169c6c46e8765bddfce4464e102df4e8c61d447450ceda38fec9d1f\Ontology64.dll, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1458, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 89%

2025-11-20T20:02:45.087 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 826, Count: 146, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\1080p\Pearl.2022.1080p.WEB-DL.DD2.0.x264-EVO.mkv, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 330, Count: 64, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: RuntimeBroker.exe, Pid: 15708, TotalTime: 324, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 23%

2025-11-20T20:02:45.087 ProcessImageName: svchost.exe, Pid: 24088, TotalTime: 296, Count: 2, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 95%

2025-11-20T20:02:45.087 ProcessImageName: WmiPrvSE.exe, Pid: 7876, TotalTime: 275, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 74%

2025-11-20T20:02:45.087 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 210, Count: 36, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 180, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Data\12\12e4023f9dfe2864546b5818629eddf81c1ac215.file, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: WmiPrvSE.exe, Pid: 17044, TotalTime: 168, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 100%

2025-11-20T20:02:45.087 ProcessImageName: ngentask.exe, Pid: 5572, TotalTime: 165, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 19%

2025-11-20T20:02:45.087 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 135, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: taskhostw.exe, Pid: 7592, TotalTime: 120, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-20T20:02:45.087 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 107, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 105, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: NVIDIA Overlay.exe, Pid: 20964, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\8951a2b4-39ab-4100-a0b3-2dfef30a883e.tmp, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: ngentask.exe, Pid: 19056, TotalTime: 90, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 9%

2025-11-20T20:02:45.087 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: ngentask.exe, Pid: 12944, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 16%

2025-11-20T20:02:45.087 ProcessImageName: ngentask.exe, Pid: 9024, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 52%

2025-11-20T20:02:45.087 ProcessImageName: ngentask.exe, Pid: 18732, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 37%

2025-11-20T20:02:45.087 ProcessImageName: taskhostw.exe, Pid: 24480, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 2%

2025-11-20T20:02:45.087 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 19528, TotalTime: 60, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\401d44483c00cbf832531ee06b1ff1d7f8a5c686.tbres, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: ngentask.exe, Pid: 23332, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 15%

2025-11-20T20:02:45.087 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 30%

2025-11-20T20:02:45.087 ProcessImageName: taskhostw.exe, Pid: 14228, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 2%

2025-11-20T20:02:45.087 ProcessImageName: taskhostw.exe, Pid: 21656, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 26%

2025-11-20T20:02:45.087 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 2%

2025-11-20T20:02:45.087 ProcessImageName: PhoneExperienceHost.exe, Pid: 13604, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\1044\StructuredQuerySchema.bin, EstimatedImpact: 0%

2025-11-20T20:02:45.087 ProcessImageName: taskhostw.exe, Pid: 8708, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-20T20:02:45.087 ProcessImageName: taskhostw.exe, Pid: 6732, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-20T20:02:45.087 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 25%

2025-11-20T20:02:45.087 ProcessImageName: taskhostw.exe, Pid: 11536, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-20T20:02:45.087 ProcessImageName: updater.exe, Pid: 8596, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\64cdb30b-1bb0-4c92-86d1-8627ec5eece5.tmp, EstimatedImpact: 0%

2025-11-20T20:02:45.088 ProcessImageName: GameBar.exe, Pid: 17788, TotalTime: 15, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.8_8.2501.31001.0_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 1%

2025-11-20T20:02:45.088 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-20T20:02:45.088 ProcessImageName: StoreDesktopExtension.exe, Pid: 9380, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\zoneinfo64.res, EstimatedImpact: 0%

2025-11-20T20:02:45.088 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1%

2025-11-20T20:02:45.088 ProcessImageName: nvngx_update.exe, Pid: 13936, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\1\files\nvngx_mapping.json, EstimatedImpact: 2%

2025-11-20T20:02:45.088 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--kglcheck-.lnk, EstimatedImpact: 14%

2025-11-20T20:02:45.088 ProcessImageName: svchost.exe, Pid: 23932, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_5012_348842400\BIT6A9.tmp, EstimatedImpact: 0%

2025-11-20T20:02:45.088 ProcessImageName: svchost.exe, Pid: 20348, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_20964_1015595098\BIT67DD.tmp, EstimatedImpact: 1%

2025-11-20T20:02:45.088 ProcessImageName: RuntimeBroker.exe, Pid: 6904, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\BackgroundTransferApi\b13a78ca-8359-4574-b1c8-a6d7ebaa3801.down_data, EstimatedImpact: 0%

2025-11-20T20:02:45.088 ProcessImageName: nvngx_update.exe, Pid: 16748, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-20T20:04:40.065 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T20:19:45.057 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T20:34:50.048 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T20:49:55.052 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T20:52:06.405 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #89339, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T20:52:06.408 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #89340, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T20:52:16.413 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #89345, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T20:52:16.416 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #89346, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T20:54:34.894 Bm signature throttled:0x0000fab3228bcd4d

2025-11-20T21:05:00.039 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T21:20:05.047 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T21:35:10.041 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T21:50:15.029 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T21:52:06.139 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #90572, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T21:52:06.143 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #90573, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T21:52:16.140 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #90583, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T21:52:16.141 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #90584, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T21:52:16.143 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #90585, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T21:52:16.144 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #90586, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T22:02:45.066 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 3300, Count: 348, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\dca6fd5c-ffdb-4976-8620-825e452ced59.tmp, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 2853, Count: 239, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\8d5943b2-cdc6-47f7-b5d0-df64c6ff1436.tmp, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1501, Count: 220, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\9ae8d73b9169c6c46e8765bddfce4464e102df4e8c61d447450ceda38fec9d1f\Ontology64.dll, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1458, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 89%

2025-11-20T22:02:45.066 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 826, Count: 146, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\1080p\Pearl.2022.1080p.WEB-DL.DD2.0.x264-EVO.mkv, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 390, Count: 81, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 345, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Data\12\12e4023f9dfe2864546b5818629eddf81c1ac215.file, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: RuntimeBroker.exe, Pid: 15708, TotalTime: 324, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 23%

2025-11-20T22:02:45.066 ProcessImageName: svchost.exe, Pid: 24088, TotalTime: 296, Count: 2, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 95%

2025-11-20T22:02:45.066 ProcessImageName: WmiPrvSE.exe, Pid: 7876, TotalTime: 275, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 74%

2025-11-20T22:02:45.066 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 255, Count: 44, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 180, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: WmiPrvSE.exe, Pid: 17044, TotalTime: 168, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 100%

2025-11-20T22:02:45.066 ProcessImageName: ngentask.exe, Pid: 5572, TotalTime: 165, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 19%

2025-11-20T22:02:45.066 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 150, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 19528, TotalTime: 135, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\401d44483c00cbf832531ee06b1ff1d7f8a5c686.tbres, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: taskhostw.exe, Pid: 7592, TotalTime: 120, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-20T22:02:45.066 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 107, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 105, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: NVIDIA Overlay.exe, Pid: 20964, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\8951a2b4-39ab-4100-a0b3-2dfef30a883e.tmp, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: ngentask.exe, Pid: 19056, TotalTime: 90, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 9%

2025-11-20T22:02:45.066 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: ngentask.exe, Pid: 12944, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 16%

2025-11-20T22:02:45.066 ProcessImageName: ngentask.exe, Pid: 9024, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 52%

2025-11-20T22:02:45.066 ProcessImageName: ngentask.exe, Pid: 18732, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 37%

2025-11-20T22:02:45.066 ProcessImageName: taskhostw.exe, Pid: 24480, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 2%

2025-11-20T22:02:45.066 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 30%

2025-11-20T22:02:45.066 ProcessImageName: ngentask.exe, Pid: 23332, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 15%

2025-11-20T22:02:45.066 ProcessImageName: taskhostw.exe, Pid: 14228, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 2%

2025-11-20T22:02:45.066 ProcessImageName: taskhostw.exe, Pid: 21656, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 26%

2025-11-20T22:02:45.066 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 2%

2025-11-20T22:02:45.066 ProcessImageName: PhoneExperienceHost.exe, Pid: 13604, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\1044\StructuredQuerySchema.bin, EstimatedImpact: 0%

2025-11-20T22:02:45.066 ProcessImageName: taskhostw.exe, Pid: 8708, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-20T22:02:45.066 ProcessImageName: taskhostw.exe, Pid: 6732, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-20T22:02:45.066 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 25%

2025-11-20T22:02:45.066 ProcessImageName: svchost.exe, Pid: 20836, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT6EE.tmp, EstimatedImpact: 1%

2025-11-20T22:02:45.066 ProcessImageName: taskhostw.exe, Pid: 11536, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-20T22:02:45.066 ProcessImageName: updater.exe, Pid: 8596, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\64cdb30b-1bb0-4c92-86d1-8627ec5eece5.tmp, EstimatedImpact: 0%

2025-11-20T22:02:45.067 ProcessImageName: updater.exe, Pid: 22892, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\e7c44c88-342b-4259-a20b-8aab7247ebda.tmp, EstimatedImpact: 0%

2025-11-20T22:02:45.067 ProcessImageName: GameBar.exe, Pid: 17788, TotalTime: 15, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.8_8.2501.31001.0_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 1%

2025-11-20T22:02:45.067 ProcessImageName: StoreDesktopExtension.exe, Pid: 9380, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\zoneinfo64.res, EstimatedImpact: 0%

2025-11-20T22:02:45.067 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1%

2025-11-20T22:02:45.067 ProcessImageName: nvngx_update.exe, Pid: 13936, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\1\files\nvngx_mapping.json, EstimatedImpact: 2%

2025-11-20T22:02:45.067 ProcessImageName: svchost.exe, Pid: 20348, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_20964_1015595098\BIT67DD.tmp, EstimatedImpact: 1%

2025-11-20T22:02:45.067 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--kglcheck-.lnk, EstimatedImpact: 14%

2025-11-20T22:02:45.067 ProcessImageName: svchost.exe, Pid: 23932, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_5012_348842400\BIT6A9.tmp, EstimatedImpact: 0%

2025-11-20T22:02:45.067 ProcessImageName: svchost.exe, Pid: 1620, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_17084_297533512\BITB524.tmp, EstimatedImpact: 0%

2025-11-20T22:02:45.067 ProcessImageName: nvngx_update.exe, Pid: 16748, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-20T22:02:45.067 ProcessImageName: RuntimeBroker.exe, Pid: 6904, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\BackgroundTransferApi\b13a78ca-8359-4574-b1c8-a6d7ebaa3801.down_data, EstimatedImpact: 0%

2025-11-20T22:05:20.035 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T22:20:25.018 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T22:28:17.292 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\setup\logs\Install_2025-11-19_205433_19528-15316.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #91188, FileId: 0xd000000016d0e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T22:28:17.390 Bm signature throttled:0x0000fab3228bcd4d

2025-11-20T22:35:30.015 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T22:50:35.019 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T22:52:05.655 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #91608, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T22:52:05.659 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #91609, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T22:52:15.667 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #91614, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T22:52:15.671 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #91615, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T23:05:40.006 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T23:20:45.003 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T23:28:30.509 Bm signature throttled:0x0000fab3228bcd4d

2025-11-20T23:35:49.998 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T23:50:54.993 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-20T23:52:07.170 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #92229, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T23:52:07.173 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #92230, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T23:52:17.176 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #92239, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-20T23:52:17.180 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #92240, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T00:02:45.028 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 4201, Count: 433, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\2f9b37ce-a19f-44ab-a0a7-96b35f34fad8.tmp, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 3575, Count: 291, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\6d371152-6b21-448f-90a8-41403be57947.tmp, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1501, Count: 220, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\9ae8d73b9169c6c46e8765bddfce4464e102df4e8c61d447450ceda38fec9d1f\Ontology64.dll, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1458, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 89%

2025-11-21T00:02:45.028 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 841, Count: 147, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\1080p\Pearl.2022.1080p.WEB-DL.DD2.0.x264-EVO.mkv, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 800, Count: 54, MaxTime: 453, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\25.209.1026.0002\OneDrive.Sync.Service.dll, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 390, Count: 83, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 345, Count: 62, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Data\12\12e4023f9dfe2864546b5818629eddf81c1ac215.file, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: RuntimeBroker.exe, Pid: 15708, TotalTime: 324, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 23%

2025-11-21T00:02:45.028 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 300, Count: 64, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: svchost.exe, Pid: 24088, TotalTime: 296, Count: 2, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 95%

2025-11-21T00:02:45.028 ProcessImageName: WmiPrvSE.exe, Pid: 7876, TotalTime: 275, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 74%

2025-11-21T00:02:45.028 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 210, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: WmiPrvSE.exe, Pid: 17044, TotalTime: 168, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 100%

2025-11-21T00:02:45.028 ProcessImageName: ngentask.exe, Pid: 5572, TotalTime: 165, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 19%

2025-11-21T00:02:45.028 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 150, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: NVIDIA Overlay.exe, Pid: 20964, TotalTime: 150, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\8951a2b4-39ab-4100-a0b3-2dfef30a883e.tmp, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 19528, TotalTime: 135, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\401d44483c00cbf832531ee06b1ff1d7f8a5c686.tbres, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: backgroundTaskHost.exe, Pid: 23932, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446->(UTF-16LE), EstimatedImpact: 46%

2025-11-21T00:02:45.028 ProcessImageName: taskhostw.exe, Pid: 7592, TotalTime: 120, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-21T00:02:45.028 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 107, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 105, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: ngentask.exe, Pid: 19056, TotalTime: 90, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 9%

2025-11-21T00:02:45.028 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: ngentask.exe, Pid: 12944, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 16%

2025-11-21T00:02:45.028 ProcessImageName: ngentask.exe, Pid: 18732, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 37%

2025-11-21T00:02:45.028 ProcessImageName: ngentask.exe, Pid: 9024, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 52%

2025-11-21T00:02:45.028 ProcessImageName: taskhostw.exe, Pid: 24480, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 2%

2025-11-21T00:02:45.028 ProcessImageName: ngentask.exe, Pid: 23332, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 15%

2025-11-21T00:02:45.028 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 30%

2025-11-21T00:02:45.028 ProcessImageName: taskhostw.exe, Pid: 14228, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 2%

2025-11-21T00:02:45.028 ProcessImageName: taskhostw.exe, Pid: 21656, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 26%

2025-11-21T00:02:45.028 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 2%

2025-11-21T00:02:45.028 ProcessImageName: svchost.exe, Pid: 14060, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BITC417.tmp, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: PhoneExperienceHost.exe, Pid: 13604, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\1044\StructuredQuerySchema.bin, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: taskhostw.exe, Pid: 8708, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-21T00:02:45.028 ProcessImageName: taskhostw.exe, Pid: 18852, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 5%

2025-11-21T00:02:45.028 ProcessImageName: taskhostw.exe, Pid: 6732, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-21T00:02:45.028 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 25%

2025-11-21T00:02:45.028 ProcessImageName: svchost.exe, Pid: 20836, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT6EE.tmp, EstimatedImpact: 1%

2025-11-21T00:02:45.028 ProcessImageName: taskhostw.exe, Pid: 11536, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-21T00:02:45.028 ProcessImageName: svchost.exe, Pid: 22856, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_20964_2131286268\BITD121.tmp, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: updater.exe, Pid: 22892, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\e7c44c88-342b-4259-a20b-8aab7247ebda.tmp, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: updater.exe, Pid: 8596, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\64cdb30b-1bb0-4c92-86d1-8627ec5eece5.tmp, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: GameBar.exe, Pid: 17788, TotalTime: 15, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.8_8.2501.31001.0_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 1%

2025-11-21T00:02:45.028 ProcessImageName: StoreDesktopExtension.exe, Pid: 9380, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\zoneinfo64.res, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1%

2025-11-21T00:02:45.028 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 22816, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: nvngx_update.exe, Pid: 13936, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\1\files\nvngx_mapping.json, EstimatedImpact: 2%

2025-11-21T00:02:45.028 ProcessImageName: svchost.exe, Pid: 20348, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_20964_1015595098\BIT67DD.tmp, EstimatedImpact: 1%

2025-11-21T00:02:45.028 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--kglcheck-.lnk, EstimatedImpact: 14%

2025-11-21T00:02:45.028 ProcessImageName: svchost.exe, Pid: 23932, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_5012_348842400\BIT6A9.tmp, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: taskhostw.exe, Pid: 20760, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: svchost.exe, Pid: 1620, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_17084_297533512\BITB524.tmp, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: RuntimeBroker.exe, Pid: 6904, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\BackgroundTransferApi\b13a78ca-8359-4574-b1c8-a6d7ebaa3801.down_data, EstimatedImpact: 0%

2025-11-21T00:02:45.028 ProcessImageName: nvngx_update.exe, Pid: 16748, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-21T00:05:59.967 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T00:17:09.959 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3

2025-11-21T00:17:09.965 Job Notification: New process added to job (16364)

2025-11-21T00:17:09.968 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched

2025-11-21T00:17:09.969 Aggressive catchup quick scan threshold: 2591975677134 / 25920000000000

2025-11-21T00:17:09.972 Job Notification: New process added to job (14272)

2025-11-21T00:17:09.979 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:16364] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:14272]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-21T00:17:10.024 Job Notification: New process added to job (16356)

2025-11-21T00:17:10.027 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched

2025-11-21T00:17:10.029 Job Notification: New process added to job (6860)

2025-11-21T00:17:10.035 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:16356] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:6860]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-21T00:17:10.051 Job Notification: New process added to job (13660)

2025-11-21T00:17:10.053 Task(GetDeviceTicket -AccessKey F8478A2E-AB5A-620B-9951-8CD04C5921AE ) launched as network service

2025-11-21T00:17:10.451 Job Notification: Process exited from job (13660)

2025-11-21T00:17:10.529 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-21T00:17:10.530 [RTP] Duplicating the current plugin configuration object...

2025-11-21T00:17:10.530 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-21T00:17:10.530 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-21T00:17:10.531 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-21T00:17:10.531 [RTP] No config change detected. Not updating plugin configuration.

2025-11-21T00:17:10.531 [RTP] No config changes found. No configuration switch.

2025-11-21T00:17:10.531 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-21T00:17:10.663 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-21T00:17:10.664 [Cloud] Start of cloud request. Passive mode: 0

2025-11-21T00:17:10.664 [Cloud] Queued cloud request.

2025-11-21T00:17:10.664 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-21T00:17:10.664 [Cloud] Dequeued cloud request.

2025-11-21T00:17:10.664 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-21T00:17:10.664 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0

2025-11-21T00:17:10.664 [Cloud] Start of cloud request. Passive mode: 0

2025-11-21T00:17:10.664 [Cloud] Queued cloud request.

2025-11-21T00:17:10.664 [Cloud] Dequeued cloud request.

2025-11-21T00:17:10.666 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-21T00:17:10.764 [Cloud] End of cloud request.

2025-11-21T00:17:11.188 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T00:17:13.985 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-21T00:17:13.985 [Cloud] End of cloud request.

2025-11-21T00:17:14.505 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T00:17:18.474 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\EC673839-6D7D-48EF-9D45-BFB0509E979A2880.1dc5a7c31b24112

2025-11-21T00:17:18.506 Verifying engine and signature files (source: 0) ...

2025-11-21T00:17:18.506 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{928DB826-42F3-4C5F-9E5B-B9F63878AA69}\mpengine.dll] due to PPL.

2025-11-21T00:17:18.506 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{928DB826-42F3-4C5F-9E5B-B9F63878AA69}\mpasbase.vdm] (file in cache)

2025-11-21T00:17:18.506 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{928DB826-42F3-4C5F-9E5B-B9F63878AA69}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-21T00:17:18.517 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{928DB826-42F3-4C5F-9E5B-B9F63878AA69}\mpasdlta.vdm]

2025-11-21T00:17:18.517 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{928DB826-42F3-4C5F-9E5B-B9F63878AA69}\mpavbase.vdm] (file in cache)

2025-11-21T00:17:18.517 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{928DB826-42F3-4C5F-9E5B-B9F63878AA69}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-21T00:17:18.525 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{928DB826-42F3-4C5F-9E5B-B9F63878AA69}\mpavdlta.vdm]

2025-11-21T00:17:18.599 [Engine] IsHybridMode: 0

2025-11-21T00:17:18.599 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-21T00:17:18.605 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-28C50E1F66BBA298B107DD0F230500DE19C394D4.bin): 0x00000002

2025-11-21T00:17:18.607 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-28C50E1F66BBA298B107DD0F230500DE19C394D4.bin)

2025-11-21T00:17:18.607 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-21T00:17:18.607 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-21T00:17:18.607 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-21T00:17:18.607 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-21T00:17:24.069 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-21T00:17:24.069 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-21T00:17:24.075 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE717EA660, lRefCount: 5, hr=0

2025-11-21T00:17:24.075 [Engine] New active engine 00007FFEBDD1A660 replacing engine 00007FFE717EA660. Number of active engines: 2

2025-11-21T00:17:24.081 EngineInit:Global ASOC is enabled

2025-11-21T00:17:24.081 EngineInit:ASOO is enabled for developer volumes

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T00:17:24.111 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d7b2f43a0b8c2e4f3c16aae9ec24b52c647460bd

Dynamic Signature Compilation Timestamp:11-19-2025 14:09:45

Persistence Type:Duration

Time remaining:864000000

2025-11-21T00:17:24.113 Dynamic signature dropped

2025-11-21T00:17:24.114 MpWriteUupSignatureVersion 1.441.369.0, hr = 0

2025-11-21T00:17:24.115 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-21T00:17:24.127 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-21T00:17:24.129 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-21T00:17:24.129 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-21T00:17:24.129 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-21T00:17:24.129 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-21T00:17:24.141 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-21T00:17:24.141 [Plugin] Initializing RTP plugin state...

2025-11-21T00:17:24.142 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-21T00:17:24.142 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 20 - 2025 15:02:45

Last Perf: 11 - 20 - 2025 15:02:45

First RTP Scan: 11 - 20 - 2025 15:02:45

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1032

  Misses:8121

BM Queue:0,44,0

  Proc:0,44,0

  File:0,7,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:92587

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:772354550

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:17

  TotalStreamCon:39621

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:579736

   TotalHits:998272

   InstanceCacheInserts:34900

   InstanceCacheUpdates:0

   InstanceCacheDeletes:27605

   InstanceCacheHits:1057

   InstanceCacheMisses:182428

   InstanceCacheOverflows:0

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (2773/2936)

   Success: 2936, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0



Top 10 Scans (unit in milliseconds):

  1:    1ms - \Device\HarddiskVolume4\Windows\Temp\EC673839-6D7D-48EF-9D45-BFB0509E979A2880.1dc5a7c31b24112\mpavdlta.vdm

  2:    1ms - \Device\HarddiskVolume4\Windows\Temp\EC673839-6D7D-48EF-9D45-BFB0509E979A2880.1dc5a7c31b24112\mpasdlta.vdm

  3:    1ms - \Device\HarddiskVolume4\Windows\Temp\EC673839-6D7D-48EF-9D45-BFB0509E979A2880.1dc5a7c31b24112\1.441.359.0_to_1.441.369.0_mpasdlta.vdm._p

  4:    0ms - \Device\HarddiskVolume4\Windows\Temp\EC673839-6D7D-48EF-9D45-BFB0509E979A2880.1dc5a7c31b24112\1.441.359.0_to_1.441.369.0_mpasdlta.vdm._p

  5:    0ms - \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\keyValueLKG.dat

  6:    0ms - \Device\HarddiskVolume4\Windows\Prefetch\SVCHOST.EXE-E6789326.pf

  7:    0ms - \Device\HarddiskVolume4\Windows\Prefetch\CONHOST.EXE-F98A1078.pf

  8:    0ms - (no scan recorded)

  9:    0ms - (no scan recorded)

 10:    0ms - (no scan recorded)

**************************END RTP Perf Log*************************



 

 



2025-11-21T00:17:24.142 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{928DB826-42F3-4C5F-9E5B-B9F63878AA69}

2025-11-21T00:17:24.142 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{25276C58-91FF-48B3-84AB-FB9ACA19A637}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{25276C58-91FF-48B3-84AB-FB9ACA19A637}\mpasbase.vdm in use, hr=0x80070020

2025-11-21T00:17:24.142 [SCC][CID=369471406_16308] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-21T00:17:24.143 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-21T00:17:24.143 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-21T00:17:24.143 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-21T00:17:24.143 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-21T00:17:24.144 MdCoreSvc is supported in this platform and OS

2025-11-21T00:17:24.144 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-21-2025 00:17:24

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-21-2025 00:17:24

2025-11-21T00:17:24.147 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-21T00:17:24.147 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-21T00:17:24.147 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-21T00:17:24.148 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-21-2025 00:17:24

END TDT(U) telemetry



2025-11-21T00:17:24.150 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T00:17:24.151 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-21T00:17:24.151 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-21T00:17:24.151 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-21T00:17:24.151 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-21T00:17:24.151 MdCoreSvc is supported in this platform and OS

Signature updated on 11-21-2025 00:17:24

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.369.0

AV Signature Version: 1.441.369.0

************************************************************

2025-11-21T00:17:24.153 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-21T00:17:24.153 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\EC673839-6D7D-48EF-9D45-BFB0509E979A2880.1dc5a7c31b24112

2025-11-21T00:17:24.157 Process scan (postsignatureupdatescan) started.

2025-11-21T00:17:24.192 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-21T00:17:24.193 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

Signature updated via MicrosoftUpdateServer on 11-21-2025 00:17:24

************************************************************

2025-11-21T00:17:24.233 Job Notification: Process exited from job (16356)

2025-11-21T00:17:24.234 Job Notification: Process exited from job (6860)

2025-11-21T00:17:24.267 Job Notification: Process exited from job (16364)

2025-11-21T00:17:24.268 Job Notification: Process exited from job (14272)

2025-11-21T00:17:24.331 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-21T00:17:24.331 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-21T00:17:24.331 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-21T00:17:24.331 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-21T00:17:24.331 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-21T00:17:24.334 [Engine] Engine 00007FFE717EA660 no longer in use. Number of active engines: 1

2025-11-21T00:17:24.334 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-21T00:17:24.334 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-21T00:17:24.488 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 4306, Count: 444, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\2f9b37ce-a19f-44ab-a0a7-96b35f34fad8.tmp, EstimatedImpact: 0%

2025-11-21T00:17:24.488 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 3650, Count: 298, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\6d371152-6b21-448f-90a8-41403be57947.tmp, EstimatedImpact: 0%

2025-11-21T00:17:24.488 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1501, Count: 220, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\9ae8d73b9169c6c46e8765bddfce4464e102df4e8c61d447450ceda38fec9d1f\Ontology64.dll, EstimatedImpact: 0%

2025-11-21T00:17:24.488 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1458, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 89%

2025-11-21T00:17:24.488 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 841, Count: 147, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\1080p\Pearl.2022.1080p.WEB-DL.DD2.0.x264-EVO.mkv, EstimatedImpact: 0%

2025-11-21T00:17:24.488 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 800, Count: 54, MaxTime: 453, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\25.209.1026.0002\OneDrive.Sync.Service.dll, EstimatedImpact: 0%

2025-11-21T00:17:24.488 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 420, Count: 85, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-21T00:17:24.488 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 345, Count: 62, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Data\12\12e4023f9dfe2864546b5818629eddf81c1ac215.file, EstimatedImpact: 0%

2025-11-21T00:17:24.488 ProcessImageName: RuntimeBroker.exe, Pid: 15708, TotalTime: 324, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 23%

2025-11-21T00:17:24.488 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 300, Count: 64, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-21T00:17:24.488 ProcessImageName: svchost.exe, Pid: 24088, TotalTime: 296, Count: 2, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 95%

2025-11-21T00:17:24.488 ProcessImageName: WmiPrvSE.exe, Pid: 7876, TotalTime: 275, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 74%

2025-11-21T00:17:24.488 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 210, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-21T00:17:24.488 ProcessImageName: WmiPrvSE.exe, Pid: 17044, TotalTime: 168, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 100%

2025-11-21T00:17:24.488 ProcessImageName: ngentask.exe, Pid: 5572, TotalTime: 165, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 19%

2025-11-21T00:17:24.488 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 150, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-21T00:17:24.504 [Engine] RSIG_UNLOADENGINE, 00007FFE717EA660, err=0x0

2025-11-21T00:17:24.522 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{25276C58-91FF-48B3-84AB-FB9ACA19A637} removed

2025-11-21T00:17:24.636 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-21T00:17:24.643 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-21T00:17:24.643 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-21T00:17:24.643 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-21T00:17:24.643 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-21T00:17:24.643 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-21T00:17:24.643 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-21T00:17:24.646 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-21T00:17:24.646 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-21T00:17:24.646 [RTP] Duplicating the current plugin configuration object...

2025-11-21T00:17:24.646 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-21T00:17:24.646 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-21T00:17:24.646 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-21T00:17:24.646 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-21T00:17:24.646 [RTP] No config change detected. Not updating plugin configuration.

2025-11-21T00:17:24.646 [RTP] No config changes found. No configuration switch.

2025-11-21T00:17:24.646 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-21T00:17:24.646 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-21T00:17:24.646 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-21T00:17:24.646 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-21T00:17:24.647 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-21T00:17:24.647 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-21T00:17:24.647 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-21T00:17:24.647 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-21T00:17:24.647 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-21T00:17:24.647 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-21T00:17:24.647 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-21T00:17:24.647 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-21T00:17:24.647 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-21T00:17:24.647 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-21T00:17:24.647 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-21T00:17:24.647 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-21T00:17:24.647 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T00:17:24.649 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T00:17:24.650 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T00:17:24.652 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T00:17:24.653 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T00:17:24.655 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 6204756(ms) from now at 03:00 (02:00 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-21T00:17:26.159 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-21T00:17:26.162 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-21T00:17:26.163 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-21T00:17:27.186 [RTP] Duplicating the current plugin configuration object...

2025-11-21T00:17:27.186 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-21T00:17:27.186 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-21T00:17:27.186 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-21T00:17:27.186 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

2025-11-21T00:17:35.259 Process scan (postsignatureupdatescan) completed.

2025-11-21T00:21:04.959 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T00:22:24.102 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-21T00:22:32.717 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #92673, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T00:22:32.720 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #92676, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T00:22:47.596 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #92738, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T00:22:47.596 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #92739, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T00:22:47.600 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #92740, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T00:36:09.951 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T00:51:14.931 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T00:52:06.397 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #93368, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T00:52:06.400 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #93369, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T00:52:16.401 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #93374, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T00:52:16.405 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #93375, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T01:06:19.929 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

Internal signature match:subtype=Lowfi, sigseq=0x0000157ED7C270CE, sigsha=5eded354160aa060b3f2a16db0725661264de9cd, cached=false, source=2, resourceid=0xd25410af

Internal signature match:subtype=Lowfi, sigseq=0x0000157E0CDC0DF7, sigsha=c369bb225296c9bd3c41efbac2dc8050d0bd330f, cached=false, source=2, resourceid=0xd25410af

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF9518016, sigsha=8fa60ffaf004b3696b5767c35f78f1425d04eb09, cached=false, source=2, resourceid=0xd25410af

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=2, resourceid=0xd25410af

Internal signature match:subtype=Lowfi, sigseq=0x0000157E9A88F9AF, sigsha=24927aafaf5d21158460baee3cd6cb672d1399db, cached=false, source=2, resourceid=0xd25410af

Internal signature match:subtype=Lowfi, sigseq=0x0000157E0604A017, sigsha=fc0762adaa0f070c9a39e4f34e45aa075d132c2c, cached=false, source=2, resourceid=0xd25410af

Internal signature match:subtype=Lowfi, sigseq=0x0000157EC0793657, sigsha=7584526bc009845dd423a5c599dbec1c11b3a3fc, cached=false, source=2, resourceid=0xd25410af

Internal signature match:subtype=Lowfi, sigseq=0x0000157EA76F0CD5, sigsha=67cb2fb7f406cdb7e1903789835fa0e437128e42, cached=false, source=2, resourceid=0xd25410af

2025-11-21T01:09:47.005 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-21T01:09:47.005 [Cloud] Start of cloud request. Passive mode: 0

2025-11-21T01:09:47.005 [Cloud] Queued cloud request.

2025-11-21T01:09:47.005 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-21T01:09:47.005 [Cloud] Dequeued cloud request.

2025-11-21T01:09:47.006 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7a5e098e1e89efe54b2df4caab51f54aaf9aebdd

Dynamic Signature Compilation Timestamp:11-21-2025 01:09:47

Persistence Type:Duration

Time remaining:864000000

2025-11-21T01:09:47.284 Dynamic signature received

2025-11-21T01:09:47.284 [Cloud] End of cloud request.

2025-11-21T01:09:47.285 RTSD:RTSD recieved, rescanning impacted resources

2025-11-21T01:09:47.790 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T01:21:24.921 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T01:28:32.518 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T01:36:29.921 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T01:39:44.162 [AutoPurge] Verification Routine tasks have started.

2025-11-21T01:39:44.162 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-21T01:39:44.166 [AutoPurge] Routine task for Cache Maintenance has started.

2025-11-21T01:39:44.167 [AutoPurge] Routine task for Cache Maintenance ...

2025-11-21T01:39:44.167 [AutoPurge] Routine task for MpSFCBuild ...

2025-11-21T01:39:44.167 [AutoPurge] MpCmIsBuildCompleted() - S_OK

2025-11-21T01:39:44.167 [AutoPurge] MpSignalMaintenanceMode ...

2025-11-21T01:39:44.171 [AutoPurge] Cleanup Routine tasks have started.

2025-11-21T01:39:44.173 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0)

2025-11-21T01:39:44.173 [AutoPurge] Purged 0 expired detection item(s) from a total of 0.

2025-11-21T01:39:44.173 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds)

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:65538

Start time:11-21-2025 01:39:44

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-21-2025 01:39:44

2025-11-21T01:39:44.176 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ...

2025-11-21T01:39:44.176 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0 ...

2025-11-21T01:39:44.176 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0 ...

2025-11-21T01:39:44.176 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ...

2025-11-21T01:39:44.176 [AutoPurge] Cleanup Routine tasks have ended.

2025-11-21T01:39:44.178 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:9D24FFF9-676E-447A-8959-41E7FE8500B9, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1)

2025-11-21T01:39:44.178 Scheduled scan with Id 9D24FFF9-676E-447A-8959-41E7FE8500B9 configured CPU priority: normal (LowCpuPriority: 0)

2025-11-21T01:39:44.179 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build.

2025-11-21T01:39:44.179 [SFC] System file cache build is not needed (already completed)

2025-11-21T01:39:44.179 QuickScan:ScanID:9D24FFF9-676E-447A-8959-41E7FE8500B9: Quick Scan skipped since it already ran during the past 7 days

2025-11-21T01:39:44.179 QuickScan:ScanID:9D24FFF9-676E-447A-8959-41E7FE8500B9: Quick scan finished with error 1223

2025-11-21T01:39:44.179 OnDemandScanWorker: Scan Cancelled! scanId:9D24FFF9-676E-447A-8959-41E7FE8500B9, hr = 0x80508018

!ERROR

Begin Quick Scan

Scan ID:{9D24FFF9-676E-447A-8959-41E7FE8500B9}

Scan Source:1

Start Time:11-21-2025 01:39:44

Unsuccessful Scan

Return Code:1223

************************************************************



2025-11-21T01:39:44.227 EnsureProtectedFolderAcls(), hr = 0x0

2025-11-21T01:39:44.230 [AutoPurge] MpReinforceServiceAcls: 0

2025-11-21T01:39:44.240 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0

2025-11-21T01:39:44.242 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed.

2025-11-21T01:39:44.243 [AutoPurge] Verification Routine tasks have ended.

2025-11-21T01:39:44.250 Engine:Setting original file name "WIARPC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiarpc.dll.mui_0c913b87", hr=0x0

2025-11-21T01:39:44.283 Engine:Setting original file name "nlsbres.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..ocale-nls.resources_31bf3856ad364e35_10.0.26100.4484_nb-no_339b02f7f61c146e\winnlsres.dll.mui", hr=0x0

2025-11-21T01:39:44.630 Engine:Setting original file name "IEXPLORE.EXE" for "c:\program files (x86)\internet explorer\en-us\iexplore.exe.mui", hr=0x0

2025-11-21T01:39:44.669 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_en-us_1258b52c940aadb7_winload.efi.mui_35ee487d", hr=0x0

2025-11-21T01:39:45.262 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sr-..-rs_d1943ecc8317ab66_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-21T01:39:45.430 Engine:Setting original file name " " for "c:\program files (x86)\steam\bin\cef\cef.win7x64\dxcompiler.dll", hr=0x0

2025-11-21T01:39:45.479 Engine:Setting original file name "dual_engine_adapter.dll" for "c:\program files (x86)\microsoft\edgecore\142.0.3595.80\dual_engine_adapter_x64.dll", hr=0x0

2025-11-21T01:39:45.653 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\winsxs\wow64_microsoft-windows-bcp47languages_31bf3856ad364e35_10.0.26100.7019_none_40ac55a9bb1ab239\bcp47langs.dll", hr=0x0

2025-11-21T01:39:45.669 Engine:Setting original file name "MAPI32.DLL.MUI" for "c:\windows\system32\nb-no\mapistub.dll.mui", hr=0x0

2025-11-21T01:39:45.854 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-21T01:39:45.895 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_ar-sa_af75f4ef024a79a1_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-21T01:39:45.975 Engine:Setting original file name "Apphelp" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a4bb088d5aa4193f97a4bdef0c1f8c71\apphelp.dll.mui", hr=0x0

2025-11-21T01:39:46.029 Engine:Setting original file name "F12Chooser.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-ie-iechooser.resources_31bf3856ad364e35_11.0.26100.1_nb-no_a7630c027f26ac69\iechooser.exe.mui", hr=0x0

2025-11-21T01:39:46.073 Engine:Setting original file name "THEMESERVICE.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-themeservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_5e5bf64d5b3ca824_themeservice.dll.mui_9e71f1ab", hr=0x0

2025-11-21T01:39:46.116 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_ad141a64b8fd6038_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:46.189 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-21T01:39:46.192 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-21T01:39:46.193 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-21T01:39:46.232 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\wow64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.26100.712_none_5cfec91758ee0662\windows.security.credentials.ui.credentialpicker.dll", hr=0x0

2025-11-21T01:39:46.310 Engine:Setting original file name "mavinject32.exe" for "c:\windows\winsxs\wow64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_592d553ad6e77100\mavinject.exe", hr=0x0

2025-11-21T01:39:46.441 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_bfcde09794ad7074_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-21T01:39:46.451 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\zh-cn\memtest.efi.mui", hr=0x0

2025-11-21T01:39:46.582 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_nb-no_022ea2e874b2cab6_winresume.efi.mui_f412814e", hr=0x0

2025-11-21T01:39:46.657 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lt-lt_11cd7cc1c62eb609_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:46.956 Engine:Setting original file name "WmiApSrv.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiapsrv.exe.mui_b1567840", hr=0x0

2025-11-21T01:39:47.021 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kk-kz_bb9a512b689c9b87_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:47.050 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_b5793645604cae79_memtest.efi.mui_71e15c22", hr=0x0

2025-11-21T01:39:47.071 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_he-il_3abd6f82e93c03e5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:47.081 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.26100.1_en-us_c3d82ef5c0380efa_wudfpf.sys.mui_f61e9e86", hr=0x0

2025-11-21T01:39:47.376 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaihdrx.dll", hr=0x0

2025-11-21T01:39:47.550 Engine:Setting original file name "l3codec.acm.mui" for "c:\windows\system32\nb-no\l3codeca.acm.mui", hr=0x0

2025-11-21T01:39:47.664 Engine:Setting original file name "w32topl.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_10.0.26100.1_none_cbd0eec659c2eb5c_w32topl.dll_1a0f388b", hr=0x0

2025-11-21T01:39:47.678 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ms-my_6f80e6fda2cebe8f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:47.966 Engine:Setting original file name "NVPTXJITCOMPILER32.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvptxjitcompiler64.dll", hr=0x0

2025-11-21T01:39:48.008 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5de87d4a39ffc584310f0b06dff9fcd0\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-21T01:39:48.095 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_38f499759ea365c4_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:48.152 Engine:Setting original file name "ddputils.lib.mui" for "c:\windows\system32\nb-no\ddputils.dll.mui", hr=0x0

2025-11-21T01:39:48.198 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-21T01:39:48.201 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-21T01:39:48.201 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-21T01:39:48.285 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kn-in_6e7a81f857a45cbe_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:48.322 Engine:Setting original file name "officeimm.odf" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\office.odf", hr=0x0

2025-11-21T01:39:48.546 Engine:Setting original file name ""AcGenral.dll"" for "c:\windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_10.0.26100.7019_none_a8119654a230db44\acgenral.dll", hr=0x0

2025-11-21T01:39:48.636 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sr-..-rs_7327597d7718c882_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:48.666 Engine:Setting original file name "Hyper-V Host Compute Service Diagnostics Tool" for "c:\windows\winsxs\amd64_hyperv-compute-cont..sticstool.resources_31bf3856ad364e35_10.0.26100.1_en-us_61074b8c7d2f38cf\hcsdiag.exe.mui", hr=0x0

2025-11-21T01:39:48.684 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.32530.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-21T01:39:48.727 Engine:Setting original file name "davsvc.dll.mui" for "c:\windows\system32\nb-no\webclnt.dll.mui", hr=0x0

2025-11-21T01:39:48.761 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\nb-no\wsepno.dll.mui", hr=0x0

2025-11-21T01:39:48.775 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x0

2025-11-21T01:39:48.817 Engine:Setting original file name "bootstr.exe.mui" for "c:\windows\system32\nb-no\bootstr.dll.mui", hr=0x0

2025-11-21T01:39:48.840 Engine:Setting original file name "msvcp140_2_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_2_app.dll", hr=0x0

2025-11-21T01:39:49.113 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-libraryloader-l1-1-0.dll", hr=0x0

2025-11-21T01:39:49.119 Engine:Setting original file name "dvsvc.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..rationsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_5c873aff49ea76e6\dcsvc.dll.mui", hr=0x0

2025-11-21T01:39:49.151 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_qps-ploc_5c9773f9ea1ce396_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:49.153 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_cs-cz_7086b4650c9e547c_memtest.efi.mui_71e15c22", hr=0x0

2025-11-21T01:39:49.263 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa78d0db4729269ff4beb393d45ca94a\dnsapi.dll.mui", hr=0x0

2025-11-21T01:39:49.279 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hr-hr_86baa9ad7eed6d52_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:49.324 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ja-jp_ed01f249e53f7235_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-21T01:39:49.367 Engine:Setting original file name "D3DX10.dll" for "c:\windows\system32\d3dx10_43.dll", hr=0x0

2025-11-21T01:39:49.461 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_da-dk_f5abc0a0339bc397_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:49.739 Engine:Setting original file name "Auto Enrollment DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..utoenroll.resources_31bf3856ad364e35_10.0.26100.1_en-us_b82b35a9c2228d6b\pautoenr.dll.mui", hr=0x0

2025-11-21T01:39:49.837 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\windows\winsxs\amd64_microsoft-textinput-helpers.resources_31bf3856ad364e35_10.0.26100.1_nb-no_2c9a52bac4b766e3\ime_textinputhelpers.dll.mui", hr=0x0

2025-11-21T01:39:49.852 Engine:Setting original file name "Ribbons" for "c:\windows\winsxs\amd64_microsoft-windows-ribbons.resources_31bf3856ad364e35_10.0.26100.1_en-us_f85e1124efc279b5\ribbons.scr.mui", hr=0x0

2025-11-21T01:39:49.906 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_18153ede37451276\memtest.exe.mui", hr=0x0

2025-11-21T01:39:49.955 Engine:Setting original file name "scecli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\978b70ff94ed14c641fe52c5237facec\scecli.dll.mui", hr=0x0

2025-11-21T01:39:49.980 Engine:Setting original file name "mpsdrv.sys.mui" for "c:\windows\winsxs\backup\amd64_networking-mpssvc-drv.resources_31bf3856ad364e35_10.0.26100.1_nb-no_05849dc2762f9d2d_mpsdrv.sys.mui_b2aea3b6", hr=0x0

2025-11-21T01:39:50.002 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-tw_21b451d70c8c2957_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-21T01:39:50.176 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_2b309b875a6f3e1e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:50.248 Engine:Setting original file name "Vulkan Runtime" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\vulkan-1.dll", hr=0x0

2025-11-21T01:39:50.293 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-p..i-ntprint.resources_31bf3856ad364e35_10.0.26100.1_en-us_6ff199c21e8ad886\ntprint.dll.mui", hr=0x0

2025-11-21T01:39:50.363 Engine:Setting original file name "bootstr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..environment-strings_31bf3856ad364e35_10.0.26100.1_none_f575b80d757af501\bootstr.dll", hr=0x0

2025-11-21T01:39:50.391 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_zh-cn_fd81e6b68df3d1a9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:50.714 Engine:Setting original file name "liblzma.dll" for "c:\program files\windowsapps\microsoft.6365217ce6eb4_102.2509.19002.0_x64__8wekyb3d8bbwe\lzma.dll", hr=0x0

2025-11-21T01:39:50.833 Engine:Setting original file name "wuapi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\uus\x86\nb-no\c120e79170c204b0e5f1ece795e86e83\wuapicore.dll.mui", hr=0x0

2025-11-21T01:39:50.914 Engine:Setting original file name "Ontology.dll" for "c:\users\serverpc\appdata\local\nvidia corporation\nvidia app\nvbackend\applicationontology\ontology64.dll", hr=0x0

2025-11-21T01:39:51.063 Engine:Setting original file name "VpnSohDesktop.dll" for "c:\windows\system32\windows.perception.stub.dll", hr=0x0

2025-11-21T01:39:51.150 Engine:Setting original file name "kernel32" for "c:\windows\syswow64\kernel32.dll", hr=0x0

2025-11-21T01:39:51.182 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.549981c3f5f10_4.2308.1005.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-21T01:39:51.477 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_b38289243d899c4c_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:51.549 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_82eb3d34cd19fa50_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:51.688 Engine:Setting original file name "Steamclient.dll" for "c:\program files (x86)\steam\steamclient64.dll", hr=0x0

2025-11-21T01:39:51.763 Engine:Setting original file name "VrdUmde.dll" for "c:\windows\winsxs\amd64_gpuvirtualizationumed_31bf3856ad364e35_10.0.26100.1150_none_17421023ba072774\vrdumed.dll", hr=0x0

2025-11-21T01:39:51.786 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.efi.mui", hr=0x0

2025-11-21T01:39:51.934 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.winmd", hr=0x0

2025-11-21T01:39:52.310 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_lt-lt_ba1ae95b692b9594_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-21T01:39:52.460 Engine:Setting original file name "windows.ui.xaml.resources.win81.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ctui-resourceswin81_31bf3856ad364e35_10.0.26100.1301_none_b7b52abe3d381205_windows.ui.xaml.resources.win81.dll_d426e245", hr=0x0

2025-11-21T01:39:52.602 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-timezone-l1-1-0.dll", hr=0x0

2025-11-21T01:39:52.648 Engine:Setting original file name "jscript9.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\c3275836e276aea69afa458336037853\jscript9legacy.dll.mui", hr=0x0

2025-11-21T01:39:52.985 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x0

2025-11-21T01:39:53.047 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-profile-l1-1-0.dll", hr=0x0

2025-11-21T01:39:53.287 Engine:Setting original file name "Windows.FileExplorer.Common.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\84c8a2171c12d91e854ffb6a27b39453\windows.fileexplorer.common.dll.mui", hr=0x0

2025-11-21T01:39:53.505 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.26100.1_en-us_99a73e6649d69102\ndisimplatcim.dll.mui", hr=0x0

2025-11-21T01:39:53.554 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-21T01:39:53.631 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-localization-l1-2-0.dll", hr=0x0

2025-11-21T01:39:53.698 Engine:Setting original file name "Placeholder.dll" for "c:\windows\microsoft.net\framework\v4.0.30319\wpf\penimc_v0400.dll", hr=0x0

2025-11-21T01:39:53.722 Engine:Setting original file name "NvCamera.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\nvcameraallowlisting32.dll", hr=0x0

2025-11-21T01:39:54.002 Engine:Setting original file name ".NET Host Policy -" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\hostpolicy.dll", hr=0x0

2025-11-21T01:39:54.415 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sv-se_cac4b549037c269f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:54.420 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-21T01:39:54.455 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-21T01:39:54.473 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\winsxs\amd64_microsoft-windows-appx-deployment-server_31bf3856ad364e35_10.0.26100.7171_none_fd3893d466902045\applytrustoffline.exe", hr=0x0

2025-11-21T01:39:54.641 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\wow64_microsoft-windows-a..on-logger.resources_31bf3856ad364e35_10.0.26100.1_en-us_a0e09b8ec526451d\aeevts.dll.mui", hr=0x0

2025-11-21T01:39:54.745 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-21T01:39:54.946 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\4f8d3bb436c7\apex_particleschecked_x86.dll", hr=0x0

2025-11-21T01:39:55.028 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_it-it_72537c4985790e22_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:55.157 Engine:Setting original file name "EsclWiaDriver.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_esclwiadriver.dll.mui_d4a5b959", hr=0x0

2025-11-21T01:39:55.281 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_da-dk_be356ba870c91e76\msprivs.dll.mui", hr=0x0

2025-11-21T01:39:55.283 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-21T01:39:55.297 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_es-es_bdfd06f72820647a_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-21T01:39:55.415 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pl-pl\msprivs.dll.mui", hr=0x0

2025-11-21T01:39:55.433 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-21T01:39:55.455 Engine:Setting original file name "rmactivate.exe.mui" for "c:\windows\syswow64\en-us\rmactivate_isv.exe.mui", hr=0x0

2025-11-21T01:39:55.704 Engine:Setting original file name "apex.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\73be2921551d\apex_turbulencefschecked_x86.dll", hr=0x0

2025-11-21T01:39:55.732 Engine:Setting original file name "ScrCons" for "c:\windows\winsxs\amd64_microsoft-windows-w..consumers.resources_31bf3856ad364e35_10.0.26100.1_en-us_5d0e2df387a86d5d\scrcons.exe.mui", hr=0x0

2025-11-21T01:39:55.741 Engine:Setting original file name "PtpProv" for "c:\windows\winsxs\amd64_microsoft-windows-t..-provider.resources_31bf3856ad364e35_10.0.26100.1_en-us_eec70481b215edf0\ptpprov.dll.mui", hr=0x0

2025-11-21T01:39:55.788 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\resources\themes\aero\nb-no\aerolite.msstyles.mui", hr=0x0

2025-11-21T01:39:56.084 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_cd255b4d1be69fe9_winload.efi.mui_35ee487d", hr=0x0

2025-11-21T01:39:56.122 Engine:Setting original file name "pegi.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_en-us_58f534214187451c\pegi.rs.mui", hr=0x0

2025-11-21T01:39:56.129 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-iexpress.resources_31bf3856ad364e35_11.0.26100.1_en-us_f84c0d683fdc407b\wextract.exe.mui", hr=0x0

2025-11-21T01:39:56.627 Engine:Setting original file name "updater.exe" for "c:\program files (x86)\google\update\googleupdate.exe", hr=0x0

2025-11-21T01:39:56.806 Engine:Setting original file name "ServicingBase.dll" for "c:\windows\system32\servicingcommon.dll", hr=0x0

2025-11-21T01:39:56.835 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.exe.mui", hr=0x0

2025-11-21T01:39:57.040 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\edgecore\142.0.3595.80\vulkan-1.dll", hr=0x0

2025-11-21T01:39:57.104 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_c77eb7b609c47f12\diagpackage.dll.mui", hr=0x0

2025-11-21T01:39:57.246 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\system32\wbem\en-us\netadaptercim.dll.mui", hr=0x0

2025-11-21T01:39:57.281 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\syswow64\nb-no\wextract.exe.mui", hr=0x0

2025-11-21T01:39:57.400 Engine:Setting original file name "NvTelemetry.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvinstallerutil.dll", hr=0x0

2025-11-21T01:39:57.449 Engine:Setting original file name "NvMessageBusBroadcast.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\localsystem\_nvmsgbusbroadcast.dll", hr=0x0

2025-11-21T01:39:57.663 Engine:Setting original file name "NVOPENCL.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvopencl64.dll", hr=0x0

2025-11-21T01:39:57.671 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x0

2025-11-21T01:39:57.753 Engine:Setting original file name "Ribbons" for "c:\windows\system32\nb-no\ribbons.scr.mui", hr=0x0

2025-11-21T01:39:57.935 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_de-de_bb6100e4729f7310\msprivs.dll.mui", hr=0x0

2025-11-21T01:39:58.099 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_en-gb_943f70b729277031_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:58.137 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570\dnsapi.dll.mui", hr=0x0

2025-11-21T01:39:58.142 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x0

2025-11-21T01:39:58.241 Engine:Setting original file name "expediteupdater" for "c:\program files\microsoft update health tools\expediteupdater.exe", hr=0x0

2025-11-21T01:39:58.294 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5fc58c6fab06ca1651cc2f24f6b3294e\dnsapi.dll.mui", hr=0x0

2025-11-21T01:39:58.350 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25101.25.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1025.47515.dll", hr=0x0

2025-11-21T01:39:58.423 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-21T01:39:58.466 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-21T01:39:58.542 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pt-br\msprivs.dll.mui", hr=0x0

2025-11-21T01:39:58.580 Engine:Setting original file name "vcomp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-21T01:39:58.639 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_pt-br_45b1cef334010120_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-21T01:39:58.691 Engine:Setting original file name "DismProvPS.DLL" for "c:\windows\system32\dism\dismcoreps.dll", hr=0x0

2025-11-21T01:39:58.807 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x0

2025-11-21T01:39:58.844 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.efi", hr=0x0

2025-11-21T01:39:58.848 Engine:Setting original file name "ProfSvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-profsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_63afbc426d007f3f_profsvc.dll.mui_32482e9e", hr=0x0

2025-11-21T01:39:58.959 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25101.25.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x0

2025-11-21T01:39:58.964 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2cfe4c864d785675f415b7e6aa962e4\msinfo32.exe.mui", hr=0x0

2025-11-21T01:39:59.319 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\6dfad87d7e49db84e1a96c1c1b32fef6\msidntld.dll.mui", hr=0x0

2025-11-21T01:39:59.338 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7\memtest.exe.mui", hr=0x0

2025-11-21T01:39:59.456 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pa-in_9c6b14ad918eaffd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:59.478 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ar-sa_51090f9ff64b96bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:39:59.534 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.26100.1_en-us_c94c280205b42295\bubbles.scr.mui", hr=0x0

2025-11-21T01:39:59.821 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\nb-no\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x0

2025-11-21T01:39:59.846 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-console-l1-2-0.dll", hr=0x0

2025-11-21T01:39:59.862 Engine:Setting original file name "SETUP.EXE.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-wow64-legacy.resources_31bf3856ad364e35_10.0.26100.1_nb-no_735ab890ce560efa\setup16.exe.mui", hr=0x0

2025-11-21T01:40:00.013 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x0

2025-11-21T01:40:00.049 Engine:Setting original file name "RarExt.dll" for "c:\program files\winrar\rarext32.dll", hr=0x0

2025-11-21T01:40:00.093 Engine:Setting original file name "pcw.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-pcw_31bf3856ad364e35_10.0.26100.1150_none_4bf8e6d5066a4f9f_pcw.sys_dbeb0bbd", hr=0x0

2025-11-21T01:40:00.189 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\syswow64\nb-no\ieadvpack.dll.mui", hr=0x0

2025-11-21T01:40:00.223 Engine:Setting original file name "EmbyServer.dll" for "c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe", hr=0x0

2025-11-21T01:40:00.494 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2535f07be6867822893c0bd7f299affd\dwmcore.dll.mui", hr=0x0

2025-11-21T01:40:00.507 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_am-et_12002fbedc3ad139_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:00.550 Engine:Setting original file name "mavinject64.exe" for "c:\windows\winsxs\amd64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_4ed8aae8a286af05\mavinject.exe", hr=0x0

2025-11-21T01:40:00.725 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_b1cb38b404e84204\seclogon.dll.mui", hr=0x0

2025-11-21T01:40:00.774 Engine:Setting original file name "AuditPolicyGP.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\1e37baae98dce76981781b53776e70b9\auditpolicygpinterop.dll.mui", hr=0x0

2025-11-21T01:40:00.861 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9c4e95300400790b8d8a05d9bf7e1f5c\winnlsres.dll.mui", hr=0x0

2025-11-21T01:40:00.876 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e981bfd75ae177a858ec5c78a5cfda25\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-21T01:40:00.934 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-21T01:40:01.130 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ru-ru_e71c93fcf7d6f33e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:01.198 Engine:Setting original file name "qualityupdateassistant" for "c:\windows\system32\qualityupdateassistant.dll", hr=0x0

2025-11-21T01:40:01.210 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ro-ro_2c617f480dd85974_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:01.348 Engine:Setting original file name "wersvc" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2f884580919ab799dbe1ecd0f275799\wersvc.dll.mui", hr=0x0

2025-11-21T01:40:01.446 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_fa-ir_f7555235024374d9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:01.478 Engine:Setting original file name "ClrCompression" for "c:\program files\windowsapps\microsoft.net.native.runtime.1.7_1.7.25531.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-21T01:40:01.517 Engine:Setting original file name "WIASERVC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiaservc.dll.mui_54051b53", hr=0x0

2025-11-21T01:40:01.522 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-21T01:40:01.557 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ru-ru_0752c1c778fe6e7c_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-21T01:40:01.669 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-21T01:40:02.077 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_id-id_6be80829898706a2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:02.082 Engine:Setting original file name "STI.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_en-us_d64b3cbf22b2a8d1_sti.dll.mui_00a4f15b", hr=0x0

2025-11-21T01:40:02.100 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9035fe481934c33719e75dea902d1698\bcastdvruserservice.dll.mui", hr=0x0

2025-11-21T01:40:02.128 Engine:Setting original file name "NVIDIA Debug Dump" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvdebugdump.exe", hr=0x0

2025-11-21T01:40:02.147 Engine:Setting original file name "acpiex.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-acpiex_31bf3856ad364e35_10.0.26100.1150_none_d0b1f61a88e2f0e9_acpiex.sys_6a8b9aed", hr=0x0

2025-11-21T01:40:02.168 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_60b47cf61af27adc_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-21T01:40:02.188 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x0

2025-11-21T01:40:02.401 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sv-se_29319a980f7b0983_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-21T01:40:02.509 Engine:Setting original file name "pshed.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-pshed_31bf3856ad364e35_10.0.26100.1_none_633b3602ca01eb94_pshed.dll_f6ac239e", hr=0x0

2025-11-21T01:40:02.605 Engine:Setting original file name "ClipSVC.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-client-li..m-service.resources_31bf3856ad364e35_10.0.26100.1_en-us_3f436cbd520195fd_clipsvc.dll.mui_18823613", hr=0x0

2025-11-21T01:40:02.630 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_cy-gb_976c80cbdb5c65c1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:02.924 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_uk-ua_c5d15aec526b5235_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:02.998 Engine:Setting original file name "msfltr32.acm" for "c:\windows\winsxs\wow64_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_10.0.26100.1_none_e82ddbd17df6cb5b\msacm32.dll", hr=0x0

2025-11-21T01:40:03.058 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-21T01:40:03.075 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-21T01:40:03.129 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_6dcfa7c5391fe7a2_dnsapi.dll.mui_97465f8a", hr=0x0

2025-11-21T01:40:03.268 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_3cda2262e7ef70ab_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:03.388 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_10.0.26100.7171_none_f70fffd91c8f0404\winload.exe", hr=0x0

2025-11-21T01:40:03.560 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_et-ee_9786a4bcaafec5cb_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:03.839 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files\mozilla firefox\updated\dxcompiler.dll", hr=0x0

2025-11-21T01:40:03.907 Engine:Setting original file name "Device_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\device\nb-no\edb83efa185c0a23d97fafe6a71cd608\diagpackage.dll.mui", hr=0x0

2025-11-21T01:40:03.932 Engine:Setting original file name "rtutils.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasrtutils_31bf3856ad364e35_10.0.26100.3037_none_a90518339a5ed736_rtutils.dll_243724ab", hr=0x0

2025-11-21T01:40:04.053 Engine:Setting original file name "udiapi.dll" for "c:\windows\system32\udiapiclient.dll", hr=0x0

2025-11-21T01:40:04.075 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-21T01:40:04.139 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaidvc.dll", hr=0x0

2025-11-21T01:40:04.144 Engine:Setting original file name "DWrite" for "c:\windows\winsxs\amd64_microsoft-windows-directwrite.resources_31bf3856ad364e35_10.0.26100.1_en-us_8e75f00536c95f8c\dwrite.dll.mui", hr=0x0

2025-11-21T01:40:04.154 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\windows\syswow64\nb-no\mfc40u.dll.mui", hr=0x0

2025-11-21T01:40:04.270 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.26100.1_en-us_12a038f1fa40c367_wlrmdr.exe.mui_ee563c83", hr=0x0

2025-11-21T01:40:04.377 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.xaml.winmd", hr=0x0

2025-11-21T01:40:04.457 Engine:Setting original file name "raspptp.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasbase-raspptp_31bf3856ad364e35_10.0.26100.1882_none_358d932997f7087d_raspptp.sys_25e89db1", hr=0x0

2025-11-21T01:40:04.551 Engine:Setting original file name "l3codec.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\17e7113a56f3171dc40844c9d3ee9e47\l3codeca.acm.mui", hr=0x0

2025-11-21T01:40:04.591 Engine:Setting original file name "bridgeres.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-networkbridge_31bf3856ad364e35_10.0.26100.2454_none_a3b07853b6183928_bridgeres.dll_55e40455", hr=0x0

2025-11-21T01:40:04.839 Engine:Setting original file name "mf.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..oundation.resources_31bf3856ad364e35_10.0.26100.1_en-us_8b9cc1ab2476fea1\mfpmp.exe.mui", hr=0x0

2025-11-21T01:40:05.010 Engine:Setting original file name "FreeImage.dll" for "c:\program files (x86)\steam\steamapps\common\wallpaper_engine\bin\freeimage64.dll", hr=0x0

2025-11-21T01:40:05.016 Engine:Setting original file name "tier0_s.dll" for "c:\program files (x86)\steam\tier0_s64.dll", hr=0x0

2025-11-21T01:40:05.034 Engine:Setting original file name "nvaudcap.dll" for "c:\windows\syswow64\nvaudcap32v.dll", hr=0x0

2025-11-21T01:40:05.074 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mi-nz_b80bad72b6b0ee53_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:05.105 Engine:Setting original file name "CertCli" for "c:\windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_10.0.26100.1_en-us_61b2ff4b086153b8\certcli.dll.mui", hr=0x0

2025-11-21T01:40:05.109 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\en-us\wsepno.dll.mui", hr=0x0

2025-11-21T01:40:05.137 Engine:Setting original file name "ConfigurationRemotingServer.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\configurationremotingserver.exe", hr=0x0

2025-11-21T01:40:05.148 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_sr-..-rs_e67ffd847af5d250_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:05.153 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\power\en-us\diagpackage.dll.mui", hr=0x0

2025-11-21T01:40:05.292 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay8-payload_31bf3856ad364e35_1.0.26100.4202_none_bb7ce817a226517c\dpnaddr.dll", hr=0x0

2025-11-21T01:40:05.558 Engine:Setting original file name "msfltr32.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8836c193640d589410b5cc3dbe67e146\msacm32.dll.mui", hr=0x0

2025-11-21T01:40:05.657 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_6a24110114ad15ad_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-21T01:40:05.681 Engine:Setting original file name "usk.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\7c8e526d244ad657f882f8bbba0149ec\usk.rs.mui", hr=0x0

2025-11-21T01:40:05.694 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-21T01:40:05.715 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay4-payload_31bf3856ad364e35_1.0.26100.4202_none_186a372066698d60\dpmodemx.dll", hr=0x0

2025-11-21T01:40:05.906 Engine:Setting original file name "Register-CimProvider2.exe.mui" for "c:\windows\syswow64\en-us\register-cimprovider.exe.mui", hr=0x0

2025-11-21T01:40:06.008 Engine:Setting original file name "metabase.dll.mui" for "c:\windows\winsxs\wow64_microsoft-windows-iis-metabase.resources_31bf3856ad364e35_10.0.26100.1_en-us_8ff50fedc8451a7b\metadata.dll.mui", hr=0x0

2025-11-21T01:40:06.013 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x0

2025-11-21T01:40:06.099 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_de-de_ab2a1f0520f5ef2b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:06.168 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_6fced6fbf4c0e3e0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:06.312 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\en-us\diagpackage.dll.mui", hr=0x0

2025-11-21T01:40:06.334 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_7478bb53490dd7a8_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-21T01:40:06.388 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\windows\system32\nb-no\msidntld.dll.mui", hr=0x0

2025-11-21T01:40:06.393 Engine:Setting original file name "glu32" for "c:\windows\winsxs\amd64_microsoft-windows-opengl.resources_31bf3856ad364e35_10.0.26100.1_en-us_9c3b296d3d668ac3\glu32.dll.mui", hr=0x0

2025-11-21T01:40:06.415 Engine:Setting original file name "mf.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mediafoundation_31bf3856ad364e35_10.0.26100.7171_none_384874e2bca9ce3f\mfpmp.exe", hr=0x0

2025-11-21T01:40:06.441 Engine:Setting original file name "msedgeupdate.dll" for "c:\program files (x86)\microsoft\edgeupdate\1.3.207.5\microsoftedgeupdateondemand.exe", hr=0x0

2025-11-21T01:40:06.457 Engine:Setting original file name "scesrv" for "c:\windows\system32\nb-no\scesrv.dll.mui", hr=0x0

2025-11-21T01:40:06.471 Engine:Setting original file name "DWWIN" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ae2b7dc24859d1fa2a509d5b642451b4\dwwin.exe.mui", hr=0x0

2025-11-21T01:40:06.614 Engine:Setting original file name "nvcuvid.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcuvid64.dll", hr=0x0

2025-11-21T01:40:06.649 Engine:Setting original file name "AppHostNameRegistrationVerifier.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\baf91a75f57ca8730dd9a6f926a58dd0\apphostregistrationverifier.exe.mui", hr=0x0

2025-11-21T01:40:06.659 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_en-gb_9672c12aaba943d2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:06.816 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-rtlsupport-l1-1-0.dll", hr=0x0

2025-11-21T01:40:06.838 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-21T01:40:06.868 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_gu-in_97d53b15f69aaeca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:06.916 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_84875939fc6b99b1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:06.936 Engine:Setting original file name "ServDeps.exe.mui" for "c:\windows\syswow64\wbem\nb-no\servdeps.dll.mui", hr=0x0

2025-11-21T01:40:06.969 Engine:Setting original file name "schtasks.exe" for "c:\windows\winsxs\amd64_microsoft-windows-sctasks_31bf3856ad364e35_10.0.26100.6725_none_25e27f3a6574108c\schtasks.exe", hr=0x0

2025-11-21T01:40:06.980 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_e38364b045f31518_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:07.035 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_el-gr_b382575af3d00da3_memtest.efi.mui_71e15c22", hr=0x0

2025-11-21T01:40:07.199 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.26100.1_en-us_0e875971ea5fda56\ieadvpack.dll.mui", hr=0x0

2025-11-21T01:40:07.246 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-datetime-l1-1-0.dll", hr=0x0

2025-11-21T01:40:07.271 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-21T01:40:07.303 Engine:Setting original file name "user32" for "c:\windows\system32\user32.dll", hr=0x0

2025-11-21T01:40:07.385 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.642.119.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-21T01:40:07.397 Engine:Setting original file name "shutdownui" for "c:\windows\winsxs\amd64_microsoft-windows-shutdownext.resources_31bf3856ad364e35_10.0.26100.1_en-us_9bd0f22e3578c871\shutdownext.dll.mui", hr=0x0

2025-11-21T01:40:07.569 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4\memtest.exe.mui", hr=0x0

2025-11-21T01:40:07.610 Engine:Setting original file name ".NET Host Resolver - 8.0.20" for "c:\users\serverpc\appdata\local\temp\emby-server-updater\hostfxr.dll", hr=0x0

2025-11-21T01:40:07.629 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_bs-..-ba_3017f7e2648d7e73_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:07.715 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_quz-pe_0266e81632046792_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:07.826 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lb-lu_cb546bb0b0d79a98_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:07.864 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\amd64_microsoft-windows-a..perience-ait-static_31bf3856ad364e35_10.0.26100.7019_none_ccd1f49f5e2b3b28\aitstatic.exe", hr=0x0

2025-11-21T01:40:07.968 Engine:Setting original file name "UNPShared.dll" for "c:\windows\winsxs\amd64_microsoft-windows-update-upshared_31bf3856ad364e35_10.0.26100.5074_none_29764f36135e6d4c\upshared.dll", hr=0x0

2025-11-21T01:40:08.049 Engine:Setting original file name "messagin.dll" for "c:\program files\bitdefender agent\27.1.1.23\messaging.dll", hr=0x0

2025-11-21T01:40:08.128 Engine:Setting original file name "WindowsCodecs" for "c:\windows\syswow64\windowscodecs.dll", hr=0x0

2025-11-21T01:40:08.166 Engine:Setting original file name "WerMgr" for "c:\windows\system32\wermgr.exe", hr=0x0

2025-11-21T01:40:08.218 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d\memtest.exe.mui", hr=0x0

2025-11-21T01:40:08.221 Engine:Setting original file name "imapi.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bd7c223153b9576fe4c4e66ebf1c6ece\imapi.dll.mui", hr=0x0

2025-11-21T01:40:08.358 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hi-in_8555c5797fc8795e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:08.434 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\esrb.rs.mui", hr=0x0

2025-11-21T01:40:08.527 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-21T01:40:08.551 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_zh-tw_ff4ad39908e2da78_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:08.555 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-21T01:40:08.606 Engine:Setting original file name "microsoftedgedevtools.exe" for "c:\windows\system32\microsoftedgecp.exe", hr=0x0

2025-11-21T01:40:08.629 Engine:Setting original file name "la57setup.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ec428185df2994f7d7954c1efe1b2738\la57setup.exe.mui", hr=0x0

2025-11-21T01:40:08.637 Engine:Setting original file name "wuapi.dll" for "c:\windows\uus\x86\wuapicore.dll", hr=0x0

2025-11-21T01:40:08.700 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\system32\en-us\dsprop.dll.mui", hr=0x0

2025-11-21T01:40:08.959 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-21T01:40:08.991 Engine:Setting original file name "etweseproviderresources.dll" for "c:\windows\winsxs\backup\amd64_microsoft-etw-ese_31bf3856ad364e35_10.0.26100.1_none_cc4e7afeeee8d3b1_etweseproviderresources.dll_f21e8ea7", hr=0x0

2025-11-21T01:40:09.071 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_2821a024e044bada_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:09.073 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-21T01:40:09.117 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bf8ce2a53903d9e6d302aee07de95dd9\mfc40u.dll.mui", hr=0x0

2025-11-21T01:40:09.131 Engine:Setting original file name "TAPISRV.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-tapiservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_83c985f74a352be9\tapisrv.dll.mui", hr=0x0

2025-11-21T01:40:09.323 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lo-la_099683f3cb70d44f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:09.325 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x0

2025-11-21T01:40:09.417 Engine:Setting original file name "wininet.dll" for "c:\windows\systemresources\wininet.dll.mun", hr=0x0

2025-11-21T01:40:09.451 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\nb-no\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x0

2025-11-21T01:40:09.470 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_hu-hu_9dd052ebcaf187fd_memtest.efi.mui_71e15c22", hr=0x0

2025-11-21T01:40:09.474 Engine:Setting original file name "PrintBrmEng.exe.mui" for "c:\windows\system32\spool\tools\en-us\printbrmengine.exe.mui", hr=0x0

2025-11-21T01:40:09.476 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_it-it_4087c8eabdc39e5f_memtest.efi.mui_71e15c22", hr=0x0

2025-11-21T01:40:09.512 Engine:Setting original file name "audioadg.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f411807b0749e7d602e77baf3c1c4e60\audiodg.exe.mui", hr=0x0

2025-11-21T01:40:09.586 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x0

2025-11-21T01:40:09.667 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-t..iprovider.resources_31bf3856ad364e35_10.0.26100.1_en-us_41b711b4f2db4fe7\rdpsign.exe.mui", hr=0x0

2025-11-21T01:40:09.804 Engine:Setting original file name "Video_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\video\nb-no\2ca5a0690699da595bd35a22420a1c04\diagpackage.dll.mui", hr=0x0

2025-11-21T01:40:09.813 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-21T01:40:09.835 Engine:Setting original file name "FvSDKTestClientPublic" for "c:\program files\nvidia corporation\frameviewsdk\sdk\fvsdktestclient_public.exe", hr=0x0

2025-11-21T01:40:09.881 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\qps-ploc\msprivs.dll.mui", hr=0x0

2025-11-21T01:40:09.884 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-21T01:40:10.039 Engine:Setting original file name "mini_installer.exe" for "c:\program files (x86)\microsoft\edgeupdate\download\{56eb18f8-b008-4cbd-b6d2-8c97fe7e9062}\142.0.3595.90\microsoftedge_x64_142.0.3595.90_142.0.3595.80.exe", hr=0x0

2025-11-21T01:40:10.079 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\windows\system32\nb-no\pnpclean.dll.mui", hr=0x0

2025-11-21T01:40:10.092 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_or-in_f89501f89f876dc5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:10.126 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.26100.7171_none_4ad020869b677502\taskmgr.exe.mun", hr=0x0

2025-11-21T01:40:10.178 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_ca98740be1962356_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:10.239 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x0

2025-11-21T01:40:10.291 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_it-it_f0fca0072ba86c5a\msprivs.dll.mui", hr=0x0

2025-11-21T01:40:10.333 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps-ploc_7ccda1c46b445ed4\memtest.exe.mui", hr=0x0

2025-11-21T01:40:10.352 Engine:Setting original file name "NETBIOS.SYS" for "c:\windows\winsxs\backup\amd64_microsoft-windows-netbios_31bf3856ad364e35_10.0.26100.1_none_56d5608ad3abe945_netbios.sys_6f23c4df", hr=0x0

2025-11-21T01:40:10.549 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\systemresources\etwcoreuicomponentsresources.dll.mun", hr=0x0

2025-11-21T01:40:10.561 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pt-br_55b72b827c87f88f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:10.686 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_0dc0948c02e4507b_memtest.efi.mui_71e15c22", hr=0x0

2025-11-21T01:40:10.701 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mt-mt_b4ebaa02b8bfece3_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:10.738 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.devices.winmd", hr=0x0

2025-11-21T01:40:10.778 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_576ce8a1070e9744_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:10.794 Engine:Setting original file name "FileInfo.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-fileinfominifilter_31bf3856ad364e35_10.0.26100.1150_none_729c4b9be137bb96_fileinfo.sys_9be2dfcd", hr=0x0

2025-11-21T01:40:10.883 Engine:Setting original file name "aclui.dll" for "c:\windows\winsxs\amd64_microsoft-windows-aclui_31bf3856ad364e35_10.0.26100.7019_none_f0f7bbb4638cf785\aclui.dll.mun", hr=0x0

2025-11-21T01:40:10.887 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\73be2921551d\apex_fieldsamplerchecked_x86.dll", hr=0x0

2025-11-21T01:40:10.949 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.777.2143.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-21T01:40:11.017 Engine:Setting original file name "qualityupdateassistant" for "c:\program files\microsoft update health tools\qualityupdateassistant.dll", hr=0x0

2025-11-21T01:40:11.046 Engine:Setting original file name "NVPPE.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvppex.dll", hr=0x0

2025-11-21T01:40:11.130 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_en-us_4761fcc7ecd6d884_winresume.efi.mui_f412814e", hr=0x0

2025-11-21T01:40:11.338 Engine:Setting original file name "NVPrxy.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvprxy32.dll", hr=0x0

2025-11-21T01:40:11.447 Engine:Setting original file name "Mystify" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\589bec7339e102473dc7566c3b9b0f45\mystify.scr.mui", hr=0x0

2025-11-21T01:40:11.473 Engine:Setting original file name "volmgrx.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..memanager.resources_31bf3856ad364e35_10.0.26100.1_en-us_a18734abf077f9b4_volmgrx.sys.mui_b0c205d7", hr=0x0

2025-11-21T01:40:11.509 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-21T01:40:11.599 Engine:Setting original file name "libcrypto" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\libcrypto-3-x64.dll", hr=0x0

2025-11-21T01:40:11.655 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hi-in_83227505fd46a5bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:11.703 Engine:Setting original file name "CertCa" for "c:\windows\winsxs\amd64_microsoft-windows-c..ertca-dll.resources_31bf3856ad364e35_10.0.26100.1_nb-no_25e015431023bb9b\certca.dll.mui", hr=0x0

2025-11-21T01:40:11.818 Engine:Setting original file name "PCW_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_ddc581f4a364804b\diagpackage.dll.mui", hr=0x0

2025-11-21T01:40:11.917 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..subsystem.resources_31bf3856ad364e35_10.0.26100.1_nb-no_ab8620bc0ed41a36\scardsvr.dll.mui", hr=0x0

2025-11-21T01:40:11.936 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_6.0.3624.51421.dll", hr=0x0

2025-11-21T01:40:12.015 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-21T01:40:12.053 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_06d4a9c0547686dc\msprivs.dll.mui", hr=0x0

2025-11-21T01:40:12.224 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mapi_31bf3856ad364e35_10.0.26100.7019_none_473a9ee5c9a5ebee\mapistub.dll", hr=0x0

2025-11-21T01:40:12.359 Engine:Setting original file name "mofcomp.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_nb-no_8c87dcbbb8114be3_mofcomp.exe.mui_35badf56", hr=0x0

2025-11-21T01:40:12.364 Engine:Setting original file name "MspsProv.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..oning-wmi.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd6de3cbb42de1cb\mspsprov.dll.mui", hr=0x0

2025-11-21T01:40:12.412 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x0

2025-11-21T01:40:12.517 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.26100.7019_none_4a484d6501b73a17\wwanapi.dll", hr=0x0

2025-11-21T01:40:12.591 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ne-np_591939d32e7d4223_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:12.669 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.xboxidentityprovider_12.130.16001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-21T01:40:12.845 Engine:Setting original file name "Operativsystemet Microsoft� Windows�" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e2a170892be5347a116ae0806fb5309d\pcalua.exe.mui", hr=0x0

2025-11-21T01:40:12.931 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x0

2025-11-21T01:40:12.947 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x0

2025-11-21T01:40:13.243 Engine:Setting original file name "imageres.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-imageres_31bf3856ad364e35_10.0.26100.1_none_d9b14b936072a0bc\imageres.dll.mun", hr=0x0

2025-11-21T01:40:13.457 Engine:Setting original file name "vcruntime140.dll" for "c:\config.msi\1c742.rbf", hr=0x0

2025-11-21T01:40:13.505 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-21T01:40:13.549 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_kk-kz_71b9c9e0d19e9ee0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:13.760 Engine:Setting original file name "Apps_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\apps\nb-no\d2a92c7cfed83dc547a21508b5b0ea0f\diagpackage.dll.mui", hr=0x0

2025-11-21T01:40:13.784 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32.dll", hr=0x0

2025-11-21T01:40:13.839 Engine:Setting original file name "CertPKICmdlet" for "c:\windows\system32\en-us\certpkicmdlet.dll.mui", hr=0x0

2025-11-21T01:40:13.915 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ed4232cecc06e9efb72d2a7c142b63b4\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x0

2025-11-21T01:40:13.926 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.424.1611.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-21T01:40:14.008 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_0cb2119581e88ce0\diagpackage.dll.mui", hr=0x0

2025-11-21T01:40:14.186 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\system32\bcp47langs.dll", hr=0x0

2025-11-21T01:40:14.266 Engine:Setting original file name "gpapi.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-g..licy-base.resources_31bf3856ad364e35_10.0.26100.1_en-us_be2843fbd972ca37_gpapi.dll.mui_ef0a9748", hr=0x0

2025-11-21T01:40:14.327 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x0

2025-11-21T01:40:14.339 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\winsxs\amd64_microsoft-windows-aerolite.resources_31bf3856ad364e35_10.0.26100.1_en-us_bc993ceae8fc48bf\aerolite.msstyles.mui", hr=0x0

2025-11-21T01:40:14.635 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\en-us\utilman.exe.mui", hr=0x0

2025-11-21T01:40:14.796 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x0

2025-11-21T01:40:14.871 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-21T01:40:14.880 Engine:Setting original file name "sqlite3" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\sqlite3.dll", hr=0x0

2025-11-21T01:40:14.948 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x0

2025-11-21T01:40:15.025 Engine:Setting original file name "w32time.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-time-tool.resources_31bf3856ad364e35_10.0.26100.1_en-us_7b897a2738f484fc\w32tm.exe.mui", hr=0x0

2025-11-21T01:40:15.030 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd473133072db5bb\diagpackage.dll.mui", hr=0x0

2025-11-21T01:40:15.058 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_80a1d04cb31f8eca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:15.062 Engine:Setting original file name "ERC" for "c:\windows\system32\nb-no\wercplsupport.dll.mui", hr=0x0

2025-11-21T01:40:15.101 Engine:Setting original file name "vdsutil.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-v..skservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_59d12af3dce743c1_vdsutil.dll.mui_0caf9b0e", hr=0x0

2025-11-21T01:40:15.186 Engine:Setting original file name "AppLockerCSP.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appidcore.resources_31bf3856ad364e35_10.0.26100.1_en-us_564c6ad9b132641f_applockercsp.dll.mui_d2a0df70", hr=0x0

2025-11-21T01:40:15.248 Engine:Setting original file name "dnsrslvr.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570_dnsrslvr.dll.mui_1e1a1ed1", hr=0x0

2025-11-21T01:40:15.321 Engine:Setting original file name "PSAPI" for "c:\windows\winsxs\backup\wow64_microsoft-windows-basedependencies_31bf3856ad364e35_10.0.26100.1_none_09ea4476c5bcc4c0_psapi.dll_e8b5b4d1", hr=0x0

2025-11-21T01:40:15.346 Engine:Setting original file name "AcPlugin.dll" for "c:\program files\windowsapps\microsoft.applicationcompatibilityenhancements_1.2511.9.0_x64__8wekyb3d8bbwe\amd64\acplugin_test.dll", hr=0x0

2025-11-21T01:40:15.360 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\426c2b1101abec586136a4bbd67a716e\narrator.exe.mui", hr=0x0

2025-11-21T01:40:15.376 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..tiator_ui.resources_31bf3856ad364e35_10.0.26100.1_en-us_7967a83a130d426e\iscsicpl.dll.mui", hr=0x0

2025-11-21T01:40:15.472 Engine:Setting original file name "WindowsMediaPlayerPlayDVD_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_587c1f8aa98a4a71\diagpackage.dll.mui", hr=0x0

2025-11-21T01:40:15.654 Engine:Setting original file name "scecli" for "c:\windows\system32\nb-no\scecli.dll.mui", hr=0x0

2025-11-21T01:40:15.676 Engine:Setting original file name "scesrv" for "c:\windows\winsxs\amd64_microsoft-windows-s..ionengine.resources_31bf3856ad364e35_10.0.26100.1_en-us_e63bd45b831a32e3\scesrv.dll.mui", hr=0x0

2025-11-21T01:40:15.712 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_bg-bg_af9bba51d24fbf0e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:15.779 Engine:Setting original file name "nvhda.sys" for "c:\windows\system32\driverstore\filerepository\nvhda.inf_amd64_c32d8360d192a82e\nvhda64v.sys", hr=0x0

2025-11-21T01:40:15.797 Engine:Setting original file name "wmiutils.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiutils.dll.mui_42583eaf", hr=0x0

2025-11-21T01:40:15.813 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_te-in_e10bae4a47776b9f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:15.844 Engine:Setting original file name "BdncProxy.dll" for "c:\program files\bitdefender agent\27.1.1.23\crash_handler\bdnc.dll", hr=0x0

2025-11-21T01:40:15.925 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.26100.1_nb-no_e175a2f7bf27ee8d_ws2ifsl.sys.mui_b672c7b4", hr=0x0

2025-11-21T01:40:15.991 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_eu-es_e55e702bbb854a24_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:16.031 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-msinfo32-exe.resources_31bf3856ad364e35_10.0.26100.1_en-us_53ae64398a08feba\msinfo32.exe.mui", hr=0x0

2025-11-21T01:40:16.090 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-21T01:40:16.440 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x86__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-21T01:40:16.464 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x0

2025-11-21T01:40:16.568 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\updated\crashreporter.exe", hr=0x0

2025-11-21T01:40:16.577 Engine:Setting original file name "NxCooking.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\v2.7.6\physxcooking.dll", hr=0x0

2025-11-21T01:40:16.610 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-21T01:40:16.752 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x0

2025-11-21T01:40:16.838 Engine:Setting original file name "filterLib.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\4fffc8576907b0b5da815790887fb244\fltlib.dll.mui", hr=0x0

2025-11-21T01:40:16.871 Engine:Setting original file name "srpuxgp.dll" for "c:\windows\systemresources\srpuxnativesnapin.dll.mun", hr=0x0

2025-11-21T01:40:16.875 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-21T01:40:17.082 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_nl-nl_0d26e65c98dbf6f7_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:17.093 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sl-si_8549ba61ed8af84b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:17.097 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x0

2025-11-21T01:40:17.285 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_pl-pl_9d43c82914fc6152_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:17.373 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-21T01:40:17.489 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ca-es_584cefb2c144b7d8_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:17.499 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\winsxs\amd64_microsoft-windows-qedwipes_31bf3856ad364e35_10.0.26100.1_none_5473011012d79dc1\qedwipes.dll.mun", hr=0x0

2025-11-21T01:40:17.676 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_et-ee_4da61d721400c924_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:17.724 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_fb2fbffb5205c552_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:17.984 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..xe-common.resources_31bf3856ad364e35_10.0.26100.1_en-us_58b62bf54b9ae38a\msinfo32.exe.mui", hr=0x0

2025-11-21T01:40:18.122 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.70.1338.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-21T01:40:18.128 Engine:Setting original file name "netcfgx.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-tcpip.resources_31bf3856ad364e35_10.0.26100.1_en-us_c93621b935b09922_tcpipcfg.dll.mui_a5479fc1", hr=0x0

2025-11-21T01:40:18.178 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_f4c1513bcd79893e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:18.230 Engine:Setting original file name "nvxdsync.exe" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\session\nvxdsyncplugin.dll", hr=0x0

2025-11-21T01:40:18.408 Engine:Setting original file name "ReShade" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\reshadefxc64.exe", hr=0x0

2025-11-21T01:40:18.458 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-21T01:40:18.508 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_0fbfb1c9f2926e3e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:18.539 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\power\nb-no\2803551e72f3605cc0b181750700647e\diagpackage.dll.mui", hr=0x0

2025-11-21T01:40:18.601 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_th-th_25ee4fb15dc2e739_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:18.608 Engine:Setting original file name "Umpo.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-u..erservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_a887c532823d0a08_umpo.dll.mui_cac12e54", hr=0x0

2025-11-21T01:40:18.612 Engine:Setting original file name "bootres" for "c:\windows\boot\resources\nb-no\bootres.dll.mui", hr=0x0

2025-11-21T01:40:18.637 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\b74f41bc269d13282681d018820fb031\ddores.dll.mui", hr=0x0

2025-11-21T01:40:18.666 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x0

2025-11-21T01:40:18.675 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\mscordaccore_amd64_amd64_8.0.2125.47513.dll", hr=0x0

2025-11-21T01:40:18.808 Engine:Setting original file name "dxmasf.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_10.0.26100.7019_none_b1abcb083360b859\msdxm.ocx", hr=0x0

2025-11-21T01:40:18.945 Engine:Setting original file name "Bubbles" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ee15dd2b573766654f76694ac2f468d4\bubbles.scr.mui", hr=0x0

2025-11-21T01:40:18.989 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_tr-tr_2c24c8b8ddbbff8a_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:19.013 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_es-mx_9dca765f230af946_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-21T01:40:19.039 Engine:Setting original file name "CUDART64_65_19.DLL" for "c:\program files (x86)\nvidia corporation\physx\common\cudart64_65.dll", hr=0x0

2025-11-21T01:40:19.193 Engine:Setting original file name "wcp.dll" for "c:\windows\system32\ssshim.dll", hr=0x0

2025-11-21T01:40:19.296 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.exe", hr=0x0

2025-11-21T01:40:19.333 OriginalFileName Maintenance::10932 files in Moac, 0 skipped (cached), 420 filename set

2025-11-21T01:40:19.333 [AutoPurge] Routine task for Cache Maintenance has ended.

2025-11-21T01:51:34.918 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T01:52:06.529 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #94376, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T01:52:06.532 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #94377, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T01:52:16.540 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #94384, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T01:52:16.544 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #94385, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T02:01:05.519 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #94964, FileId: 0xdd000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T02:06:39.915 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T02:07:10.438 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

2025-11-21T02:07:10.447 [DLP] DlpEngineConfigStorage::OnConfigChange DlpDwordSettingsMap:

2025-11-21T02:07:10.448 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-21T02:07:10.448 [RTP] Duplicating the current plugin configuration object...

2025-11-21T02:07:10.448 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-21T02:07:10.448 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-21T02:07:10.448 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-21T02:07:10.448 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-21T02:07:10.448 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-21T02:07:10.448 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-21T02:07:10.448 [RTP] No config change detected. Not updating plugin configuration.

2025-11-21T02:07:10.448 [RTP] No config changes found. No configuration switch.

2025-11-21T02:07:10.448 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-21T02:07:10.448 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-21T02:07:10.448 [RTP] [RtpConfig] Config change detected, type: 16

2025-11-21T02:07:10.448 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-21T02:07:10.448 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-21T02:07:10.448 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-21T02:07:10.448 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-21T02:07:10.448 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-21T02:07:10.448 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-21T02:07:10.448 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-21T02:07:10.448 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-21T02:07:10.448 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-21T02:07:10.448 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-21T02:07:10.448 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-21T02:07:10.448 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-21T02:07:10.449 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-21T02:07:10.449 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-21T02:07:10.449 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T02:07:10.450 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T02:07:10.452 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T02:07:10.453 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T02:07:10.454 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T02:07:10.456 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 7165255(ms) from now at 05:06 (04:06 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-21T02:07:13.004 [RTP] Duplicating the current plugin configuration object...

2025-11-21T02:07:13.004 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-21T02:07:13.004 [RTP] Updating plugin configuration due to recent config changes (0x41e) ...

2025-11-21T02:07:13.004 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-21T02:07:13.004 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x218

2025-11-21T02:17:24.030 ProcessImageName: RuntimeBroker.exe, Pid: 20648, TotalTime: 2771, Count: 40, MaxTime: 2171, MaxTimeFile: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, EstimatedImpact: 0%

2025-11-21T02:17:24.030 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1630, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 87%

2025-11-21T02:17:24.030 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 870, Count: 88, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\1542b677-e443-4dc0-aec0-9b00339f08c7.tmp, EstimatedImpact: 0%

2025-11-21T02:17:24.030 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 675, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\42320b63-089c-4fff-b98b-6333ababa7f7.tmp, EstimatedImpact: 0%

2025-11-21T02:17:24.030 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 225, Count: 55, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-21T02:17:24.030 ProcessImageName: taskhostw.exe, Pid: 20336, TotalTime: 210, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-21T02:17:24.030 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\http.sys, EstimatedImpact: 0%

2025-11-21T02:17:24.030 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan->(UTF-16LE), EstimatedImpact: 0%

2025-11-21T02:17:24.030 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-21T02:17:24.030 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 30, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\e780c487dceb427d1cf19f52519f48b87705e5b0.tbres->(UTF-16LE), EstimatedImpact: 0%

2025-11-21T02:17:24.030 ProcessImageName: taskhostw.exe, Pid: 13672, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 4%

2025-11-21T02:17:24.030 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_691320.acf, EstimatedImpact: 0%

2025-11-21T02:17:24.030 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-21T02:17:24.030 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\b1021fdb-dcff-4cdf-b81f-c8b51c4dc943.tmp, EstimatedImpact: 0%

2025-11-21T02:17:24.030 ProcessImageName: taskhostw.exe, Pid: 20336, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-21T02:17:24.030 ProcessImageName: Spotify.exe, Pid: 17104, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-21T02:21:44.908 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T02:28:31.676 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\0468BE1C-0D62-4B8D-A330-C67188DC790D6338.1dc5a8e867897ee

2025-11-21T02:28:31.707 Verifying engine and signature files (source: 0) ...

2025-11-21T02:28:31.707 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A615C42-5C8D-47D9-BAC9-507C06100742}\mpengine.dll] due to PPL.

2025-11-21T02:28:31.707 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A615C42-5C8D-47D9-BAC9-507C06100742}\mpasbase.vdm] (file in cache)

2025-11-21T02:28:31.707 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A615C42-5C8D-47D9-BAC9-507C06100742}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-21T02:28:31.717 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A615C42-5C8D-47D9-BAC9-507C06100742}\mpasdlta.vdm]

2025-11-21T02:28:31.717 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A615C42-5C8D-47D9-BAC9-507C06100742}\mpavbase.vdm] (file in cache)

2025-11-21T02:28:31.717 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A615C42-5C8D-47D9-BAC9-507C06100742}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-21T02:28:31.725 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A615C42-5C8D-47D9-BAC9-507C06100742}\mpavdlta.vdm]

2025-11-21T02:28:31.797 [Engine] IsHybridMode: 0

2025-11-21T02:28:31.798 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-21T02:28:31.804 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A9AAFD45BD9810BCD03ADA4EBA4FE1456A435FDA.bin): 0x00000002

2025-11-21T02:28:31.805 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A9AAFD45BD9810BCD03ADA4EBA4FE1456A435FDA.bin)

2025-11-21T02:28:31.805 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-21T02:28:31.805 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-21T02:28:31.805 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-21T02:28:31.805 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-21T02:28:37.542 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-21T02:28:37.543 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-21T02:28:37.550 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFEBDD1A660, lRefCount: 5, hr=0

2025-11-21T02:28:37.550 [Engine] New active engine 00007FFE717EA660 replacing engine 00007FFEBDD1A660. Number of active engines: 2

2025-11-21T02:28:37.556 EngineInit:Global ASOC is enabled

2025-11-21T02:28:37.556 EngineInit:ASOO is enabled for developer volumes

2025-11-21T02:28:37.588 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-21T02:28:37.588 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.588 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-21T02:28:37.589 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-21T02:28:37.589 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-21T02:28:37.589 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.590 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.590 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.590 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-21T02:28:37.591 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.591 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.591 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-21T02:28:37.591 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.592 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.592 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.592 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.592 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.593 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.593 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.593 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T02:28:37.595 MpWriteUupSignatureVersion 1.441.372.0, hr = 0

2025-11-21T02:28:37.596 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-21T02:28:37.609 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-21T02:28:37.610 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-21T02:28:37.610 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-21T02:28:37.610 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-21T02:28:37.610 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-21T02:28:37.625 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-21T02:28:37.625 [Plugin] Initializing RTP plugin state...

2025-11-21T02:28:37.625 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-21T02:28:37.625 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 21 - 2025 01:17:24

Last Perf: 11 - 21 - 2025 01:17:24

First RTP Scan: 11 - 21 - 2025 01:17:25

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1057

  Misses:2929

BM Queue:0,26,0

  Proc:0,26,0

  File:0,7,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:97167

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:800582418

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:17

  TotalStreamCon:18745

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:610467

   TotalHits:1038462

   InstanceCacheInserts:36013

   InstanceCacheUpdates:0

   InstanceCacheDeletes:33954

   InstanceCacheHits:1079

   InstanceCacheMisses:185979

   InstanceCacheOverflows:0

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (653/654)

   Success: 654, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-21T02:28:37.625 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A615C42-5C8D-47D9-BAC9-507C06100742}

2025-11-21T02:28:37.626 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{928DB826-42F3-4C5F-9E5B-B9F63878AA69}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{928DB826-42F3-4C5F-9E5B-B9F63878AA69}\mpasbase.vdm in use, hr=0x80070020

2025-11-21T02:28:37.626 [SCC][CID=377344953_22456] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-21T02:28:37.626 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-21T02:28:37.626 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-21T02:28:37.627 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-21T02:28:37.627 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-21T02:28:37.627 MdCoreSvc is supported in this platform and OS

2025-11-21T02:28:37.627 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-21-2025 02:28:37

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-21-2025 02:28:37

2025-11-21T02:28:37.630 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-21T02:28:37.630 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-21T02:28:37.631 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-21T02:28:37.631 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-21-2025 02:28:37

END TDT(U) telemetry



2025-11-21T02:28:37.633 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T02:28:37.633 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-21T02:28:37.633 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-21T02:28:37.633 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-21T02:28:37.633 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-21T02:28:37.633 MdCoreSvc is supported in this platform and OS

Signature updated on 11-21-2025 02:28:37

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.372.0

AV Signature Version: 1.441.372.0

************************************************************

2025-11-21T02:28:37.635 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-21T02:28:37.635 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\0468BE1C-0D62-4B8D-A330-C67188DC790D6338.1dc5a8e867897ee

2025-11-21T02:28:37.657 Process scan (postsignatureupdatescan) started.

2025-11-21T02:28:37.685 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-21T02:28:37.687 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-21T02:28:37.837 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-21T02:28:37.837 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-21T02:28:37.837 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-21T02:28:37.837 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-21T02:28:37.838 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-21T02:28:37.840 [Engine] Engine 00007FFEBDD1A660 no longer in use. Number of active engines: 1

2025-11-21T02:28:37.840 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-21T02:28:37.840 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-21T02:28:38.000 ProcessImageName: RuntimeBroker.exe, Pid: 20648, TotalTime: 2771, Count: 40, MaxTime: 2171, MaxTimeFile: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, EstimatedImpact: 0%

2025-11-21T02:28:38.000 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1630, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 87%

2025-11-21T02:28:38.000 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 900, Count: 96, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\1542b677-e443-4dc0-aec0-9b00339f08c7.tmp, EstimatedImpact: 0%

2025-11-21T02:28:38.000 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 705, Count: 59, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\42320b63-089c-4fff-b98b-6333ababa7f7.tmp, EstimatedImpact: 0%

2025-11-21T02:28:38.000 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 390, Count: 98, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-21T02:28:38.000 ProcessImageName: WmiPrvSE.exe, Pid: 23560, TotalTime: 270, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf->(UTF-16LE), EstimatedImpact: 24%

2025-11-21T02:28:38.000 ProcessImageName: taskhostw.exe, Pid: 20336, TotalTime: 210, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-21T02:28:38.000 ProcessImageName: svchost.exe, Pid: 21172, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 1%

2025-11-21T02:28:38.000 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 92, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\http.sys, EstimatedImpact: 0%

2025-11-21T02:28:38.000 ProcessImageName: taskhostw.exe, Pid: 23340, TotalTime: 75, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 0%

2025-11-21T02:28:38.000 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 75, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan->(UTF-16LE), EstimatedImpact: 0%

2025-11-21T02:28:38.000 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-21T02:28:38.000 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 35%

2025-11-21T02:28:38.000 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 30, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\e780c487dceb427d1cf19f52519f48b87705e5b0.tbres->(UTF-16LE), EstimatedImpact: 0%

2025-11-21T02:28:38.017 [Engine] RSIG_UNLOADENGINE, 00007FFEBDD1A660, err=0x0

2025-11-21T02:28:38.035 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{928DB826-42F3-4C5F-9E5B-B9F63878AA69} removed

2025-11-21T02:28:38.116 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-21T02:28:38.123 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-21T02:28:38.123 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-21T02:28:38.123 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-21T02:28:38.124 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-21T02:28:38.124 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-21T02:28:38.124 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-21T02:28:38.127 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-21T02:28:38.127 [RTP] Duplicating the current plugin configuration object...

2025-11-21T02:28:38.127 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-21T02:28:38.127 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-21T02:28:38.127 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-21T02:28:38.127 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-21T02:28:38.127 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-21T02:28:38.127 [RTP] No config change detected. Not updating plugin configuration.

2025-11-21T02:28:38.127 [RTP] No config changes found. No configuration switch.

2025-11-21T02:28:38.127 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-21T02:28:38.127 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-21T02:28:38.127 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-21T02:28:38.127 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-21T02:28:38.127 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-21T02:28:38.127 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-21T02:28:38.127 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-21T02:28:38.127 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-21T02:28:38.127 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-21T02:28:38.127 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-21T02:28:38.127 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-21T02:28:38.127 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-21T02:28:38.127 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-21T02:28:38.127 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-21T02:28:38.128 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-21T02:28:38.128 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-21T02:28:38.128 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T02:28:38.130 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T02:28:38.132 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T02:28:38.133 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T02:28:38.135 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T02:28:38.136 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 1291473(ms) from now at 03:50 (02:50 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-21T02:28:39.654 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-21T02:28:39.658 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-21T02:28:39.659 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-21T02:28:40.644 [RTP] Duplicating the current plugin configuration object...

2025-11-21T02:28:40.644 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-21T02:28:40.644 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-21T02:28:40.644 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-21T02:28:40.644 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

2025-11-21T02:28:50.592 Process scan (postsignatureupdatescan) completed.

2025-11-21T02:33:37.576 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-21T02:36:49.899 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T02:51:54.905 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T02:52:06.688 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #100684, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T02:52:06.691 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #100685, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T02:52:16.695 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #100696, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T02:52:16.699 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #100697, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T03:06:59.898 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T03:22:04.892 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T03:28:34.478 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T03:37:09.891 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T03:52:14.884 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T03:52:15.593 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #101591, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T03:52:15.596 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #101592, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T03:52:22.074 ReportLowfi(c:\program files\google\chrome\application\142.0.7444.176\installer\chrmstp.exe, 0x437a0835) from 0x0006b6bd6566d2d9

Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0x4b03b077

2025-11-21T03:52:22.313 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Windows\SystemTemp\chrome_installer.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #101892, FileId: 0xed0000000248e9, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T03:52:22.362 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Windows\SystemTemp\chrome_installer.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #101898, FileId: 0xed0000000248e9, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T03:52:24.026 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #101924, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T03:52:24.030 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #101925, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T03:52:34.026 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #101954, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T03:52:34.030 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #101955, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T03:52:34.042 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #101956, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T03:52:34.046 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #101957, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T04:07:19.871 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T04:22:24.867 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T04:28:35.567 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T04:28:37.519 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 825, Count: 89, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\23c2aff5-05ef-4860-8828-88de121017c5.tmp, EstimatedImpact: 0%

2025-11-21T04:28:37.519 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 675, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ff5a42db-bc49-48b8-9b2e-88e919b425b1.tmp, EstimatedImpact: 0%

2025-11-21T04:28:37.519 ProcessImageName: RuntimeBroker.exe, Pid: 20648, TotalTime: 369, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 27%

2025-11-21T04:28:37.519 ProcessImageName: DeviceCensus.exe, Pid: 24772, TotalTime: 357, Count: 16, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 12%

2025-11-21T04:28:37.519 ProcessImageName: taskhostw.exe, Pid: 13960, TotalTime: 345, Count: 80, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-21T04:28:37.519 ProcessImageName: updater.exe, Pid: 11120, TotalTime: 107, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping11120_1409529794\142.0.7444.176_chrome_installer_uncompressed.exe, EstimatedImpact: 0%

2025-11-21T04:28:37.519 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 107, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-21T04:28:37.519 ProcessImageName: svchost.exe, Pid: 21172, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\UUS\State\_active.uusver, EstimatedImpact: 3%

2025-11-21T04:28:37.519 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-21T04:28:37.519 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Desktop\Spotify.lnk, EstimatedImpact: 0%

2025-11-21T04:28:37.519 ProcessImageName: setup.exe, Pid: 23080, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Google\Chrome\Application\new_chrome.exe, EstimatedImpact: 3%

2025-11-21T04:28:37.519 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-21T04:28:37.519 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\e37a4970-2dd1-438c-a55a-caf1d11efbe7\content.phf, EstimatedImpact: 0%

2025-11-21T04:28:37.519 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 30, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-21T04:28:37.519 ProcessImageName: StoreDesktopExtension.exe, Pid: 18188, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-21T04:28:37.519 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 0%

2025-11-21T04:28:37.519 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 13%

2025-11-21T04:28:37.519 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.276.298.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-21T04:28:37.519 ProcessImageName: updater.exe, Pid: 24008, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-21T04:37:29.865 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T04:52:06.978 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #102587, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T04:52:06.981 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #102588, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T04:52:16.981 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #102593, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T04:52:16.985 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #102594, FileId: 0xad000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T04:52:34.870 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T05:07:39.859 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T05:22:37.583 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #102999, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T05:22:37.587 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #103002, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T05:22:44.852 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T05:22:51.083 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #103010, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T05:37:49.848 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T05:52:06.597 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #103450, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T05:52:06.600 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #103451, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T05:52:16.611 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #103458, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T05:52:16.614 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #103459, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T05:52:54.839 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T06:07:59.841 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T06:23:04.841 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T06:28:37.494 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 1560, Count: 175, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\23c2aff5-05ef-4860-8828-88de121017c5.tmp, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1534, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 82%

2025-11-21T06:28:37.494 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 1290, Count: 105, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ff5a42db-bc49-48b8-9b2e-88e919b425b1.tmp, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: RuntimeBroker.exe, Pid: 20648, TotalTime: 369, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 27%

2025-11-21T06:28:37.494 ProcessImageName: DeviceCensus.exe, Pid: 24772, TotalTime: 357, Count: 16, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 12%

2025-11-21T06:28:37.494 ProcessImageName: taskhostw.exe, Pid: 13960, TotalTime: 345, Count: 80, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-21T06:28:37.494 ProcessImageName: updater.exe, Pid: 11120, TotalTime: 107, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping11120_1409529794\142.0.7444.176_chrome_installer_uncompressed.exe, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 107, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 105, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 105, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: svchost.exe, Pid: 21172, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\UUS\State\_active.uusver, EstimatedImpact: 3%

2025-11-21T06:28:37.494 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Desktop\Spotify.lnk, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: setup.exe, Pid: 23080, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Google\Chrome\Application\new_chrome.exe, EstimatedImpact: 3%

2025-11-21T06:28:37.494 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\e37a4970-2dd1-438c-a55a-caf1d11efbe7\content.phf, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 30, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: StoreDesktopExtension.exe, Pid: 18188, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: taskhostw.exe, Pid: 20632, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-21T06:28:37.494 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: taskhostw.exe, Pid: 10532, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 1%

2025-11-21T06:28:37.494 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 13%

2025-11-21T06:28:37.494 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 0, Count: 10, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.276.298.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: updater.exe, Pid: 24008, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-21T06:28:37.494 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\robots.txt, EstimatedImpact: 0%

2025-11-21T06:28:37.525 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T06:38:09.839 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T06:52:04.445 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #104711, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T06:52:04.449 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #104712, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T06:52:14.453 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #104717, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T06:52:14.456 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #104718, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T06:53:14.825 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T07:08:19.827 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T07:23:24.815 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T07:38:29.811 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T07:52:05.846 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #105421, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T07:52:05.849 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #105422, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T07:52:15.850 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #105429, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T07:52:15.853 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #105431, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T07:53:34.807 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T08:01:11.618 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #105527, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T08:08:39.802 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T08:23:44.807 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T08:28:37.467 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 2356, Count: 262, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\34897b58-0aae-4f5f-b322-99abcdae19f9.tmp, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 1830, Count: 157, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ff5a42db-bc49-48b8-9b2e-88e919b425b1.tmp, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1534, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 82%

2025-11-21T08:28:37.467 ProcessImageName: RuntimeBroker.exe, Pid: 20648, TotalTime: 369, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 27%

2025-11-21T08:28:37.467 ProcessImageName: DeviceCensus.exe, Pid: 24772, TotalTime: 357, Count: 16, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 12%

2025-11-21T08:28:37.467 ProcessImageName: taskhostw.exe, Pid: 13960, TotalTime: 345, Count: 80, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-21T08:28:37.467 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 165, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 120, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: updater.exe, Pid: 11120, TotalTime: 107, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping11120_1409529794\142.0.7444.176_chrome_installer_uncompressed.exe, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 107, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: svchost.exe, Pid: 21172, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\UUS\State\_active.uusver, EstimatedImpact: 3%

2025-11-21T08:28:37.467 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 75, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Desktop\Spotify.lnk, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: setup.exe, Pid: 23080, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Google\Chrome\Application\new_chrome.exe, EstimatedImpact: 3%

2025-11-21T08:28:37.467 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\e37a4970-2dd1-438c-a55a-caf1d11efbe7\content.phf, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: StoreDesktopExtension.exe, Pid: 18188, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: taskhostw.exe, Pid: 20632, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-21T08:28:37.467 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: taskhostw.exe, Pid: 23972, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-21T08:28:37.467 ProcessImageName: taskhostw.exe, Pid: 10532, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 1%

2025-11-21T08:28:37.467 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 13%

2025-11-21T08:28:37.467 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 0, Count: 15, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.276.298.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: updater.exe, Pid: 24008, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-21T08:28:37.467 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\robots.txt, EstimatedImpact: 0%

2025-11-21T08:28:39.587 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T08:38:49.797 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T08:52:06.764 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #106116, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T08:52:06.767 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #106117, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T08:52:16.767 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #106122, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T08:52:16.767 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #106123, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T08:52:16.769 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #106124, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T08:52:16.771 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #106125, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T08:53:54.781 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T09:08:59.757 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T09:24:04.751 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T09:39:09.727 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T09:52:07.297 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #106871, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T09:52:07.300 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #106872, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T09:52:12.358 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #106883, FileId: 0xde000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T09:52:17.311 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #106887, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T09:52:17.315 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #106888, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T09:54:14.719 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T10:09:19.713 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T10:22:41.003 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #107374, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T10:22:41.007 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #107377, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T10:22:55.067 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #107394, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T10:22:55.071 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #107395, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T10:24:24.703 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T10:28:37.385 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 3226, Count: 349, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\34897b58-0aae-4f5f-b322-99abcdae19f9.tmp, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 2415, Count: 210, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ff5a42db-bc49-48b8-9b2e-88e919b425b1.tmp, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1534, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 82%

2025-11-21T10:28:37.385 ProcessImageName: RuntimeBroker.exe, Pid: 20648, TotalTime: 369, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 27%

2025-11-21T10:28:37.385 ProcessImageName: DeviceCensus.exe, Pid: 24772, TotalTime: 357, Count: 16, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 12%

2025-11-21T10:28:37.385 ProcessImageName: taskhostw.exe, Pid: 13960, TotalTime: 345, Count: 80, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-21T10:28:37.385 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 195, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 180, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 122, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: updater.exe, Pid: 11120, TotalTime: 107, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping11120_1409529794\142.0.7444.176_chrome_installer_uncompressed.exe, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 105, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: svchost.exe, Pid: 21172, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\UUS\State\_active.uusver, EstimatedImpact: 3%

2025-11-21T10:28:37.385 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Desktop\Spotify.lnk, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 26%

2025-11-21T10:28:37.385 ProcessImageName: setup.exe, Pid: 23080, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Google\Chrome\Application\new_chrome.exe, EstimatedImpact: 3%

2025-11-21T10:28:37.385 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: NVIDIA Overlay.exe, Pid: 20964, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\component_crx_cache\hfnkpimlhhgieaddgfemjhofmfblmnib_1.90f52c2a14c0176f905de4c83f22862d53016e2b7b0ef55702d03fac7be1c4f6, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\e37a4970-2dd1-438c-a55a-caf1d11efbe7\content.phf, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: StoreDesktopExtension.exe, Pid: 18188, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: taskhostw.exe, Pid: 20632, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-21T10:28:37.385 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: taskhostw.exe, Pid: 25256, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-21T10:28:37.385 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 15, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\cb2ac2c8-d619-47f2-9aa3-26696a19395e.tmp, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: backgroundTaskHost.exe, Pid: 10532, TotalTime: 15, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1763690456, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: taskhostw.exe, Pid: 23972, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-21T10:28:37.385 ProcessImageName: taskhostw.exe, Pid: 10532, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 1%

2025-11-21T10:28:37.385 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8)->(SCRIPT0000), EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 13%

2025-11-21T10:28:37.385 ProcessImageName: taskhostw.exe, Pid: 17568, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: updater.exe, Pid: 22584, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\5d3bff0e-f859-4f53-accd-ec8d68c1e87d.tmp, EstimatedImpact: 0%

2025-11-21T10:28:37.385 ProcessImageName: updater.exe, Pid: 24008, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-21T10:28:41.559 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T10:39:29.701 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T10:52:05.568 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #108022, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T10:52:05.571 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #108023, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T10:52:15.575 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #108028, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T10:52:15.579 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #108029, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T10:54:34.697 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T11:09:39.684 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T11:24:44.688 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T11:39:49.683 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T11:52:07.671 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #108732, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T11:52:07.674 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #108733, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T11:52:17.673 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #108740, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T11:52:17.677 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #108741, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T11:53:55.179 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #108901, FileId: 0x8000000034b11, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T11:54:54.676 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T11:59:11.442 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #108999, FileId: 0xdf000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T12:09:59.662 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T12:25:04.659 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T12:28:37.352 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 4007, Count: 435, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\34897b58-0aae-4f5f-b322-99abcdae19f9.tmp, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 3076, Count: 263, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\afe8a112-5537-426d-95f6-a9836e3aad51.tmp, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1534, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 82%

2025-11-21T12:28:37.352 ProcessImageName: RuntimeBroker.exe, Pid: 20648, TotalTime: 369, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 27%

2025-11-21T12:28:37.352 ProcessImageName: DeviceCensus.exe, Pid: 24772, TotalTime: 357, Count: 16, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 12%

2025-11-21T12:28:37.352 ProcessImageName: taskhostw.exe, Pid: 13960, TotalTime: 345, Count: 80, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-21T12:28:37.352 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 240, Count: 44, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 240, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 122, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 120, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: updater.exe, Pid: 11120, TotalTime: 107, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping11120_1409529794\142.0.7444.176_chrome_installer_uncompressed.exe, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: svchost.exe, Pid: 21172, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\UUS\State\_active.uusver, EstimatedImpact: 3%

2025-11-21T12:28:37.352 ProcessImageName: PhoneExperienceHost.exe, Pid: 13604, TotalTime: 60, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\desktop.ini, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 26%

2025-11-21T12:28:37.352 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Desktop\Spotify.lnk, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: setup.exe, Pid: 23080, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Google\Chrome\Application\new_chrome.exe, EstimatedImpact: 3%

2025-11-21T12:28:37.352 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: NVIDIA Overlay.exe, Pid: 20964, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\component_crx_cache\hfnkpimlhhgieaddgfemjhofmfblmnib_1.90f52c2a14c0176f905de4c83f22862d53016e2b7b0ef55702d03fac7be1c4f6, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\e37a4970-2dd1-438c-a55a-caf1d11efbe7\content.phf, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: StoreDesktopExtension.exe, Pid: 18188, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: taskhostw.exe, Pid: 20632, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-21T12:28:37.352 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: taskhostw.exe, Pid: 25256, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-21T12:28:37.352 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 15, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\cb2ac2c8-d619-47f2-9aa3-26696a19395e.tmp, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: backgroundTaskHost.exe, Pid: 10532, TotalTime: 15, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1763690456, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: taskhostw.exe, Pid: 23972, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-21T12:28:37.352 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8)->(SCRIPT0000), EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: taskhostw.exe, Pid: 10532, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 1%

2025-11-21T12:28:37.352 ProcessImageName: taskhostw.exe, Pid: 11012, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 9%

2025-11-21T12:28:37.352 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 13%

2025-11-21T12:28:37.352 ProcessImageName: taskhostw.exe, Pid: 17568, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: updater.exe, Pid: 22584, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\5d3bff0e-f859-4f53-accd-ec8d68c1e87d.tmp, EstimatedImpact: 0%

2025-11-21T12:28:37.352 ProcessImageName: updater.exe, Pid: 24008, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-21T12:28:43.546 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T12:40:09.656 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T12:52:05.393 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #109662, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T12:52:05.397 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #109663, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T12:52:15.399 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #109668, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T12:52:15.403 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #109669, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T12:55:14.650 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T13:10:19.648 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T13:25:24.653 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T13:40:29.642 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T13:52:07.278 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #110390, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T13:52:07.282 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #110391, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T13:52:17.287 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #110398, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T13:52:17.288 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #110399, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T13:52:17.290 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #110400, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T13:52:17.292 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #110401, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T13:55:34.633 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T13:59:37.384 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #110553, FileId: 0xb400000002367b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T14:10:39.633 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T14:25:44.631 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T14:28:37.315 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 4742, Count: 522, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\34897b58-0aae-4f5f-b322-99abcdae19f9.tmp, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 3661, Count: 316, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\afe8a112-5537-426d-95f6-a9836e3aad51.tmp, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1534, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 82%

2025-11-21T14:28:37.315 ProcessImageName: RuntimeBroker.exe, Pid: 20648, TotalTime: 369, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 27%

2025-11-21T14:28:37.315 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 360, Count: 57, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: DeviceCensus.exe, Pid: 24772, TotalTime: 357, Count: 16, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 12%

2025-11-21T14:28:37.315 ProcessImageName: taskhostw.exe, Pid: 13960, TotalTime: 345, Count: 80, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-21T14:28:37.315 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 285, Count: 52, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 135, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 122, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: updater.exe, Pid: 11120, TotalTime: 107, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping11120_1409529794\142.0.7444.176_chrome_installer_uncompressed.exe, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 90, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\cb2ac2c8-d619-47f2-9aa3-26696a19395e.tmp, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: svchost.exe, Pid: 21172, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\UUS\State\_active.uusver, EstimatedImpact: 3%

2025-11-21T14:28:37.315 ProcessImageName: PhoneExperienceHost.exe, Pid: 13604, TotalTime: 60, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\desktop.ini, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Desktop\Spotify.lnk, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 26%

2025-11-21T14:28:37.315 ProcessImageName: NVIDIA Overlay.exe, Pid: 20964, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\component_crx_cache\hfnkpimlhhgieaddgfemjhofmfblmnib_1.90f52c2a14c0176f905de4c83f22862d53016e2b7b0ef55702d03fac7be1c4f6, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: setup.exe, Pid: 23080, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Google\Chrome\Application\new_chrome.exe, EstimatedImpact: 3%

2025-11-21T14:28:37.315 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\e37a4970-2dd1-438c-a55a-caf1d11efbe7\content.phf, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: StoreDesktopExtension.exe, Pid: 18188, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: taskhostw.exe, Pid: 20632, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-21T14:28:37.315 ProcessImageName: taskhostw.exe, Pid: 25256, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-21T14:28:37.315 ProcessImageName: backgroundTaskHost.exe, Pid: 10532, TotalTime: 15, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1763690456, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: taskhostw.exe, Pid: 10532, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 1%

2025-11-21T14:28:37.315 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8)->(SCRIPT0000), EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: taskhostw.exe, Pid: 23972, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-21T14:28:37.315 ProcessImageName: taskhostw.exe, Pid: 11012, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 9%

2025-11-21T14:28:37.315 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 13%

2025-11-21T14:28:37.315 ProcessImageName: taskhostw.exe, Pid: 17568, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: updater.exe, Pid: 22584, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\5d3bff0e-f859-4f53-accd-ec8d68c1e87d.tmp, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: updater.exe, Pid: 24008, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-21T14:28:37.315 ProcessImageName: updater.exe, Pid: 2120, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\496f1b65-f971-4ab5-b044-3ac32add87e6.tmp, EstimatedImpact: 0%

2025-11-21T14:28:45.435 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T14:40:49.626 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T14:42:14.921 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\590AF155-E001-497B-82C9-7FBB3F29FA926304.1dc5af5065ea182

2025-11-21T14:42:14.961 Verifying engine and signature files (source: 0) ...

2025-11-21T14:42:14.961 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F201DCC8-58E9-4A40-A834-EFC3193FECC5}\mpengine.dll] due to PPL.

2025-11-21T14:42:14.961 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F201DCC8-58E9-4A40-A834-EFC3193FECC5}\mpasbase.vdm] (file in cache)

2025-11-21T14:42:14.961 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F201DCC8-58E9-4A40-A834-EFC3193FECC5}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-21T14:42:14.969 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F201DCC8-58E9-4A40-A834-EFC3193FECC5}\mpasdlta.vdm]

2025-11-21T14:42:14.969 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F201DCC8-58E9-4A40-A834-EFC3193FECC5}\mpavbase.vdm] (file in cache)

2025-11-21T14:42:14.969 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F201DCC8-58E9-4A40-A834-EFC3193FECC5}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-21T14:42:14.978 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F201DCC8-58E9-4A40-A834-EFC3193FECC5}\mpavdlta.vdm]

2025-11-21T14:42:15.050 [Engine] IsHybridMode: 0

2025-11-21T14:42:15.051 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-21T14:42:15.056 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-D224D1E28F245586084F4135C17EA1930FA8D20F.bin): 0x00000002

2025-11-21T14:42:15.058 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-D224D1E28F245586084F4135C17EA1930FA8D20F.bin)

2025-11-21T14:42:15.058 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-21T14:42:15.058 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-21T14:42:15.058 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-21T14:42:15.058 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-21T14:42:20.420 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-21T14:42:20.420 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-21T14:42:20.424 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE717EA660, lRefCount: 5, hr=0

2025-11-21T14:42:20.424 [Engine] New active engine 00007FFEBC4FA660 replacing engine 00007FFE717EA660. Number of active engines: 2

2025-11-21T14:42:20.427 EngineInit:Global ASOC is enabled

2025-11-21T14:42:20.427 EngineInit:ASOO is enabled for developer volumes

2025-11-21T14:42:20.455 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-21T14:42:20.455 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.455 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-21T14:42:20.455 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-21T14:42:20.455 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-21T14:42:20.455 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.455 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.455 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.455 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-21T14:42:20.455 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.456 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.456 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-21T14:42:20.456 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.456 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.456 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.456 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.456 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.456 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.456 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.456 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-21T14:42:20.457 MpWriteUupSignatureVersion 1.441.385.0, hr = 0

2025-11-21T14:42:20.458 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-21T14:42:20.470 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-21T14:42:20.471 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-21T14:42:20.471 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-21T14:42:20.471 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-21T14:42:20.471 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-21T14:42:20.485 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-21T14:42:20.485 [Plugin] Initializing RTP plugin state...

2025-11-21T14:42:20.485 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-21T14:42:20.485 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 21 - 2025 03:28:37

Last Perf: 11 - 21 - 2025 03:28:37

First RTP Scan: 11 - 21 - 2025 03:28:37

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1363

  Misses:8716

BM Queue:0,33,0

  Proc:0,31,0

  File:0,7,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:111235

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:941669768

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:17

  TotalStreamCon:16642

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:727387

   TotalHits:1252849

   InstanceCacheInserts:42173

   InstanceCacheUpdates:0

   InstanceCacheDeletes:34140

   InstanceCacheHits:1162

   InstanceCacheMisses:205192

   InstanceCacheOverflows:0

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:1ms (3404/3387)

   Success: 3387, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-21T14:42:20.485 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F201DCC8-58E9-4A40-A834-EFC3193FECC5}

2025-11-21T14:42:20.485 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A615C42-5C8D-47D9-BAC9-507C06100742}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A615C42-5C8D-47D9-BAC9-507C06100742}\mpasbase.vdm in use, hr=0x80070020

2025-11-21T14:42:20.485 [SCC][CID=421368093_17872] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-21T14:42:20.486 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-21T14:42:20.486 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-21T14:42:20.486 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-21T14:42:20.486 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-21T14:42:20.486 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-21T14:42:20.487 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-21-2025 14:42:20

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-21-2025 14:42:20

2025-11-21T14:42:20.489 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-21T14:42:20.489 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-21T14:42:20.490 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-21T14:42:20.490 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-21-2025 14:42:20

END TDT(U) telemetry



2025-11-21T14:42:20.492 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T14:42:20.492 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-21T14:42:20.492 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-21T14:42:20.492 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-21T14:42:20.492 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-21T14:42:20.492 MdCoreSvc is supported in this platform and OS

Signature updated on 11-21-2025 14:42:20

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.385.0

AV Signature Version: 1.441.385.0

************************************************************

2025-11-21T14:42:20.494 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-21T14:42:20.494 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\590AF155-E001-497B-82C9-7FBB3F29FA926304.1dc5af5065ea182

2025-11-21T14:42:20.508 Process scan (postsignatureupdatescan) started.

2025-11-21T14:42:20.532 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-21T14:42:20.533 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-21T14:42:20.661 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-21T14:42:20.661 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-21T14:42:20.661 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-21T14:42:20.661 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-21T14:42:20.661 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-21T14:42:20.664 [Engine] Engine 00007FFE717EA660 no longer in use. Number of active engines: 1

2025-11-21T14:42:20.664 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-21T14:42:20.664 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-21T14:42:20.826 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 4787, Count: 532, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\34897b58-0aae-4f5f-b322-99abcdae19f9.tmp, EstimatedImpact: 0%

2025-11-21T14:42:20.826 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 3721, Count: 321, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\afe8a112-5537-426d-95f6-a9836e3aad51.tmp, EstimatedImpact: 0%

2025-11-21T14:42:20.826 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1534, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 82%

2025-11-21T14:42:20.826 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 375, Count: 63, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-21T14:42:20.826 ProcessImageName: RuntimeBroker.exe, Pid: 20648, TotalTime: 369, Count: 20, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 27%

2025-11-21T14:42:20.826 ProcessImageName: DeviceCensus.exe, Pid: 24772, TotalTime: 357, Count: 16, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 12%

2025-11-21T14:42:20.826 ProcessImageName: taskhostw.exe, Pid: 13960, TotalTime: 345, Count: 80, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-21T14:42:20.826 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 300, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-21T14:42:20.826 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 150, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-21T14:42:20.826 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 122, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-21T14:42:20.826 ProcessImageName: updater.exe, Pid: 11120, TotalTime: 107, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping11120_1409529794\142.0.7444.176_chrome_installer_uncompressed.exe, EstimatedImpact: 0%

2025-11-21T14:42:20.826 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 90, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\cb2ac2c8-d619-47f2-9aa3-26696a19395e.tmp, EstimatedImpact: 0%

2025-11-21T14:42:20.826 ProcessImageName: svchost.exe, Pid: 21172, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\UUS\State\_active.uusver, EstimatedImpact: 3%

2025-11-21T14:42:20.826 ProcessImageName: PhoneExperienceHost.exe, Pid: 13604, TotalTime: 60, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\desktop.ini, EstimatedImpact: 0%

2025-11-21T14:42:20.826 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Desktop\Spotify.lnk, EstimatedImpact: 0%

2025-11-21T14:42:20.841 [Engine] RSIG_UNLOADENGINE, 00007FFE717EA660, err=0x0

2025-11-21T14:42:20.856 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A615C42-5C8D-47D9-BAC9-507C06100742} removed

2025-11-21T14:42:20.983 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-21T14:42:20.990 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-21T14:42:20.990 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-21T14:42:20.990 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-21T14:42:20.990 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-21T14:42:20.990 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-21T14:42:20.990 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-21T14:42:20.993 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-21T14:42:20.993 [RTP] Duplicating the current plugin configuration object...

2025-11-21T14:42:20.993 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-21T14:42:20.993 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-21T14:42:20.993 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-21T14:42:20.993 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-21T14:42:20.993 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-21T14:42:20.993 [RTP] No config change detected. Not updating plugin configuration.

2025-11-21T14:42:20.993 [RTP] No config changes found. No configuration switch.

2025-11-21T14:42:20.993 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-21T14:42:20.993 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-21T14:42:20.993 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-21T14:42:20.993 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-21T14:42:20.993 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-21T14:42:20.993 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-21T14:42:20.993 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-21T14:42:20.993 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-21T14:42:20.993 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-21T14:42:20.994 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-21T14:42:20.994 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-21T14:42:20.994 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-21T14:42:20.994 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-21T14:42:20.994 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-21T14:42:20.994 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-21T14:42:20.994 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-21T14:42:20.994 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T14:42:20.996 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T14:42:20.997 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T14:42:20.999 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T14:42:21.000 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T14:42:21.002 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 42005131(ms) from now at 03:22 (02:22 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-21T14:42:22.506 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-21T14:42:22.509 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-21T14:42:22.510 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-21T14:42:23.520 [RTP] Duplicating the current plugin configuration object...

2025-11-21T14:42:23.520 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-21T14:42:23.520 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-21T14:42:23.520 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-21T14:42:23.520 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

2025-11-21T14:42:31.952 Process scan (postsignatureupdatescan) completed.

2025-11-21T14:47:20.451 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-21T14:52:07.278 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #111791, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T14:52:07.281 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #111792, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T14:52:17.293 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #111800, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T14:52:17.297 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #111801, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T14:55:54.623 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T15:10:59.613 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T15:22:45.035 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #112639, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T15:22:45.038 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #112642, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T15:22:58.988 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #112649, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T15:22:58.991 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #112650, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T15:26:04.604 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T15:41:09.602 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T15:42:12.803 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume4\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #116473, FileId: 0x2a0000000096cf, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T15:52:06.436 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #116650, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T15:52:06.439 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #116651, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T15:52:16.436 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #116658, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T15:52:16.440 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #116659, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T15:56:14.592 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T16:11:19.602 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T16:26:24.593 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T16:28:47.507 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T16:41:29.587 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T16:42:20.390 ProcessImageName: SrTasks.exe, Pid: 6496, TotalTime: 3431, Count: 1080, MaxTime: 296, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 7%

2025-11-21T16:42:20.390 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1422, Count: 84, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\bfs.sys, EstimatedImpact: 81%

2025-11-21T16:42:20.390 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 886, Count: 87, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9812c55a-673b-491d-98b5-c196d695cfe6.tmp, EstimatedImpact: 0%

2025-11-21T16:42:20.390 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 646, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\97f14c1b-571e-4b38-9c29-806fd1a9c80e.tmp, EstimatedImpact: 0%

2025-11-21T16:42:20.390 ProcessImageName: taskhostw.exe, Pid: 6908, TotalTime: 405, Count: 83, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 25%

2025-11-21T16:42:20.390 ProcessImageName: RuntimeBroker.exe, Pid: 15500, TotalTime: 384, Count: 22, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 24%

2025-11-21T16:42:20.390 ProcessImageName: WmiPrvSE.exe, Pid: 17848, TotalTime: 153, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 100%

2025-11-21T16:42:20.390 ProcessImageName: ngentask.exe, Pid: 6392, TotalTime: 150, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 16%

2025-11-21T16:42:20.390 ProcessImageName: ngentask.exe, Pid: 15700, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 18%

2025-11-21T16:42:20.390 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 105, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-21T16:42:20.390 ProcessImageName: ngentask.exe, Pid: 6476, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 22%

2025-11-21T16:42:20.390 ProcessImageName: taskhostw.exe, Pid: 24420, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\BTHUSB.SYS, EstimatedImpact: 3%

2025-11-21T16:42:20.390 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-21T16:42:20.390 ProcessImageName: ngentask.exe, Pid: 22832, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-21T16:42:20.390 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-21T16:42:20.390 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-21T16:42:20.390 ProcessImageName: ngentask.exe, Pid: 19432, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 26%

2025-11-21T16:42:20.390 ProcessImageName: ngentask.exe, Pid: 6496, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 34%

2025-11-21T16:42:20.390 ProcessImageName: StoreDesktopExtension.exe, Pid: 22088, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-21T16:42:20.390 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 25%

2025-11-21T16:42:20.390 ProcessImageName: taskhostw.exe, Pid: 24580, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 3%

2025-11-21T16:42:20.390 ProcessImageName: updater.exe, Pid: 3628, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-21T16:52:05.330 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #117372, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T16:52:05.333 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #117373, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T16:52:15.340 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #117378, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T16:52:15.343 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #117379, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T16:56:34.583 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T17:11:39.580 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T17:26:44.573 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T17:39:53.014 Bm signature throttled:0x00002db31bed458f

2025-11-21T17:41:49.569 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T17:52:07.271 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #118831, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T17:52:07.274 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #118832, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T17:52:17.280 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #118839, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T17:52:17.284 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #118840, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T17:56:54.558 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T18:01:38.130 Bm signature throttled:0x00002db31bed458f

2025-11-21T18:11:59.552 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T18:27:04.555 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T18:28:49.481 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T18:42:09.540 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T18:42:20.360 ProcessImageName: SrTasks.exe, Pid: 6496, TotalTime: 3431, Count: 1080, MaxTime: 296, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 7%

2025-11-21T18:42:20.360 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 1713, Count: 172, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9812c55a-673b-491d-98b5-c196d695cfe6.tmp, EstimatedImpact: 0%

2025-11-21T18:42:20.360 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 1562, Count: 240, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\en-GB\Emby.Resources.resources.dll, EstimatedImpact: 0%

2025-11-21T18:42:20.360 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1422, Count: 84, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\bfs.sys, EstimatedImpact: 81%

2025-11-21T18:42:20.360 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 1381, Count: 107, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\97f14c1b-571e-4b38-9c29-806fd1a9c80e.tmp, EstimatedImpact: 0%

2025-11-21T18:42:20.360 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1216, Count: 195, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\e60c1a038e1886e936e51bf063c60be29b6aa7c194f787331aac46e2f567edff\Ontology64.dll, EstimatedImpact: 0%

2025-11-21T18:42:20.360 ProcessImageName: taskhostw.exe, Pid: 6908, TotalTime: 405, Count: 83, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 25%

2025-11-21T18:42:20.360 ProcessImageName: RuntimeBroker.exe, Pid: 15500, TotalTime: 384, Count: 22, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 24%

2025-11-21T18:42:20.360 ProcessImageName: WmiPrvSE.exe, Pid: 22596, TotalTime: 258, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\smbdirect.sys, EstimatedImpact: 64%

2025-11-21T18:42:20.360 ProcessImageName: WmiPrvSE.exe, Pid: 17848, TotalTime: 153, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 100%

2025-11-21T18:42:20.360 ProcessImageName: ngentask.exe, Pid: 6392, TotalTime: 150, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 16%

2025-11-21T18:42:20.360 ProcessImageName: ngentask.exe, Pid: 15700, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 18%

2025-11-21T18:42:20.360 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 120, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-21T18:42:20.360 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 105, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-21T18:42:20.360 ProcessImageName: ngentask.exe, Pid: 6476, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 22%

2025-11-21T18:42:20.360 ProcessImageName: taskhostw.exe, Pid: 24420, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\BTHUSB.SYS, EstimatedImpact: 3%

2025-11-21T18:42:20.360 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 75, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-21T18:42:20.360 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-21T18:42:20.360 ProcessImageName: ngentask.exe, Pid: 22832, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-21T18:42:20.360 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 45, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\9f092fb8-1005-4904-a69b-a17ce648851b.tmp, EstimatedImpact: 0%

2025-11-21T18:42:20.360 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 1%

2025-11-21T18:42:20.360 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-21T18:42:20.360 ProcessImageName: ngentask.exe, Pid: 19432, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 26%

2025-11-21T18:42:20.360 ProcessImageName: ngentask.exe, Pid: 6496, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 34%

2025-11-21T18:42:20.360 ProcessImageName: taskhostw.exe, Pid: 24376, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 26%

2025-11-21T18:42:20.360 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\oem20.PNF, EstimatedImpact: 5%

2025-11-21T18:42:20.360 ProcessImageName: StoreDesktopExtension.exe, Pid: 22088, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-21T18:42:20.360 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 25%

2025-11-21T18:42:20.360 ProcessImageName: taskhostw.exe, Pid: 24580, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 3%

2025-11-21T18:42:20.360 ProcessImageName: nvngx_update.exe, Pid: 9984, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 5%

2025-11-21T18:42:20.360 ProcessImageName: updater.exe, Pid: 3628, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-21T18:42:20.360 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 1%

2025-11-21T18:42:20.360 ProcessImageName: NVIDIA Overlay.exe, Pid: 20964, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\c5419794-cbdf-4431-9bef-4a1659d2be14.tmp, EstimatedImpact: 4%

2025-11-21T18:42:20.361 ProcessImageName: nvngx_update.exe, Pid: 18496, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-21T18:45:49.633 ReportLowfi(c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe, 0x83161cd9) from 0x0002c9bd4055ee43

2025-11-21T18:45:49.633 ReportLowfi(c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe , 0x83161cd9) from 0x0002c9bd4055ee43

2025-11-21T18:52:07.260 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #120287, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T18:52:07.264 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #120288, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T18:52:17.261 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #120294, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T18:52:17.262 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #120295, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T18:52:17.264 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #120296, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T18:52:17.265 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #120297, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T18:57:14.538 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T19:12:19.542 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T19:27:24.539 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T19:42:29.529 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T19:52:05.812 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #129684, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T19:52:05.816 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #129685, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T19:52:15.823 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #129690, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T19:52:15.827 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #129691, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T19:57:34.527 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T20:01:14.911 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #129784, FileId: 0xe0000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T20:12:39.513 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T20:22:48.961 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #130012, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T20:22:48.964 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #130015, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T20:23:03.694 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #130025, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T20:23:03.699 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #130026, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T20:27:44.512 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T20:28:51.510 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T20:33:56.704 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\setup\logs\Install_2025-11-20_222817_17868-20128.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #130274, FileId: 0x101000000004cea, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T20:33:56.775 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T20:42:20.338 ProcessImageName: ffmpeg.exe, Pid: 17932, TotalTime: 65990, Count: 8156, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\libx265_main12.dll, EstimatedImpact: 35%

2025-11-21T20:42:20.338 ProcessImageName: SrTasks.exe, Pid: 6496, TotalTime: 3431, Count: 1080, MaxTime: 296, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 7%

2025-11-21T20:42:20.338 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 2598, Count: 415, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\en-GB\Emby.Resources.resources.dll, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 2553, Count: 259, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9812c55a-673b-491d-98b5-c196d695cfe6.tmp, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 2026, Count: 160, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\97f14c1b-571e-4b38-9c29-806fd1a9c80e.tmp, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1422, Count: 84, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\bfs.sys, EstimatedImpact: 81%

2025-11-21T20:42:20.338 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1216, Count: 195, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\e60c1a038e1886e936e51bf063c60be29b6aa7c194f787331aac46e2f567edff\Ontology64.dll, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: taskhostw.exe, Pid: 6908, TotalTime: 405, Count: 83, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 25%

2025-11-21T20:42:20.338 ProcessImageName: RuntimeBroker.exe, Pid: 15500, TotalTime: 384, Count: 22, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 24%

2025-11-21T20:42:20.338 ProcessImageName: WmiPrvSE.exe, Pid: 22596, TotalTime: 258, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\smbdirect.sys, EstimatedImpact: 64%

2025-11-21T20:42:20.338 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 180, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: WmiPrvSE.exe, Pid: 17848, TotalTime: 153, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 100%

2025-11-21T20:42:20.338 ProcessImageName: ngentask.exe, Pid: 6392, TotalTime: 150, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 16%

2025-11-21T20:42:20.338 ProcessImageName: ngentask.exe, Pid: 15700, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 18%

2025-11-21T20:42:20.338 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 120, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 1%

2025-11-21T20:42:20.338 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 120, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 105, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 90, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: ngentask.exe, Pid: 6476, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 22%

2025-11-21T20:42:20.338 ProcessImageName: taskhostw.exe, Pid: 24420, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\BTHUSB.SYS, EstimatedImpact: 3%

2025-11-21T20:42:20.338 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 7840, TotalTime: 75, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 1%

2025-11-21T20:42:20.338 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: ngentask.exe, Pid: 22832, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-21T20:42:20.338 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 45, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\9f092fb8-1005-4904-a69b-a17ce648851b.tmp, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: taskhostw.exe, Pid: 24700, TotalTime: 45, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 4%

2025-11-21T20:42:20.338 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 1%

2025-11-21T20:42:20.338 ProcessImageName: ngentask.exe, Pid: 19432, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 26%

2025-11-21T20:42:20.338 ProcessImageName: taskhostw.exe, Pid: 24376, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 26%

2025-11-21T20:42:20.338 ProcessImageName: ngentask.exe, Pid: 6496, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 34%

2025-11-21T20:42:20.338 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context->(Base64), EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: NVIDIA Overlay.exe, Pid: 20964, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\c5419794-cbdf-4431-9bef-4a1659d2be14.tmp, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\oem20.PNF, EstimatedImpact: 5%

2025-11-21T20:42:20.338 ProcessImageName: svchost.exe, Pid: 3564, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT7569.tmp, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: StoreDesktopExtension.exe, Pid: 22088, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 25%

2025-11-21T20:42:20.338 ProcessImageName: taskhostw.exe, Pid: 24580, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 3%

2025-11-21T20:42:20.338 ProcessImageName: nvngx_update.exe, Pid: 9984, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 5%

2025-11-21T20:42:20.338 ProcessImageName: taskhostw.exe, Pid: 8936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 1%

2025-11-21T20:42:20.338 ProcessImageName: updater.exe, Pid: 6024, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9ab8cbd3-cf46-41e8-8dea-0918f07d3b85.tmp, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: updater.exe, Pid: 3628, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-21T20:42:20.338 ProcessImageName: backgroundTaskHost.exe, Pid: 18116, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\310091\1763146039, EstimatedImpact: 1%

2025-11-21T20:42:20.338 ProcessImageName: nvngx_update.exe, Pid: 18496, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-21T20:42:49.511 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T20:52:05.777 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #130574, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T20:52:05.781 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #130575, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T20:52:15.782 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #130580, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T20:52:15.786 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #130581, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T20:57:54.497 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T21:12:59.502 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T21:28:04.497 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T21:43:09.495 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T21:52:06.268 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #131767, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T21:52:06.271 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #131768, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T21:52:16.278 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #131777, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T21:52:16.282 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #131778, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T21:58:14.480 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T22:13:19.482 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T22:28:24.476 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T22:34:10.593 Bm signature throttled:0x0000fab3228bcd4d

2025-11-21T22:42:20.316 ProcessImageName: ffmpeg.exe, Pid: 17932, TotalTime: 65990, Count: 8156, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\libx265_main12.dll, EstimatedImpact: 35%

2025-11-21T22:42:20.316 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 7847, Count: 870, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\ffprobe.exe, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: SrTasks.exe, Pid: 6496, TotalTime: 3431, Count: 1080, MaxTime: 296, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 7%

2025-11-21T22:42:20.316 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 3348, Count: 345, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9812c55a-673b-491d-98b5-c196d695cfe6.tmp, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 2656, Count: 213, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\97f14c1b-571e-4b38-9c29-806fd1a9c80e.tmp, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: ffmpeg.exe, Pid: 25108, TotalTime: 1620, Count: 256, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\transcoding-temp\C41826\C41826_s3.m3u8.tmp, EstimatedImpact: 23%

2025-11-21T22:42:20.316 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1422, Count: 84, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\bfs.sys, EstimatedImpact: 81%

2025-11-21T22:42:20.316 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1216, Count: 195, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\e60c1a038e1886e936e51bf063c60be29b6aa7c194f787331aac46e2f567edff\Ontology64.dll, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: taskhostw.exe, Pid: 6908, TotalTime: 405, Count: 83, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 25%

2025-11-21T22:42:20.316 ProcessImageName: RuntimeBroker.exe, Pid: 15500, TotalTime: 384, Count: 22, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 24%

2025-11-21T22:42:20.316 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 270, Count: 47, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: WmiPrvSE.exe, Pid: 22596, TotalTime: 258, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\smbdirect.sys, EstimatedImpact: 64%

2025-11-21T22:42:20.316 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 180, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: WmiPrvSE.exe, Pid: 17848, TotalTime: 153, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 100%

2025-11-21T22:42:20.316 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 150, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: ngentask.exe, Pid: 6392, TotalTime: 150, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 16%

2025-11-21T22:42:20.316 ProcessImageName: ngentask.exe, Pid: 15700, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 18%

2025-11-21T22:42:20.316 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 135, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\9f092fb8-1005-4904-a69b-a17ce648851b.tmp, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 16004, TotalTime: 105, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: backgroundTaskHost.exe, Pid: 22688, TotalTime: 90, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1763509465, EstimatedImpact: 17%

2025-11-21T22:42:20.316 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 17868, TotalTime: 90, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 90, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: ngentask.exe, Pid: 6476, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 22%

2025-11-21T22:42:20.316 ProcessImageName: taskhostw.exe, Pid: 24420, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\BTHUSB.SYS, EstimatedImpact: 3%

2025-11-21T22:42:20.316 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 7840, TotalTime: 75, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 1%

2025-11-21T22:42:20.316 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: ngentask.exe, Pid: 22832, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-21T22:42:20.316 ProcessImageName: taskhostw.exe, Pid: 24700, TotalTime: 45, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 4%

2025-11-21T22:42:20.316 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 1%

2025-11-21T22:42:20.316 ProcessImageName: ngentask.exe, Pid: 6496, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 34%

2025-11-21T22:42:20.316 ProcessImageName: taskhostw.exe, Pid: 24376, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 26%

2025-11-21T22:42:20.316 ProcessImageName: ngentask.exe, Pid: 19432, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 26%

2025-11-21T22:42:20.316 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context->(Base64), EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: NVIDIA Overlay.exe, Pid: 20964, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\c5419794-cbdf-4431-9bef-4a1659d2be14.tmp, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\oem20.PNF, EstimatedImpact: 5%

2025-11-21T22:42:20.316 ProcessImageName: svchost.exe, Pid: 3564, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT7569.tmp, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: StoreDesktopExtension.exe, Pid: 22088, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 25%

2025-11-21T22:42:20.316 ProcessImageName: taskhostw.exe, Pid: 24580, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 3%

2025-11-21T22:42:20.316 ProcessImageName: taskhostw.exe, Pid: 8936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 1%

2025-11-21T22:42:20.316 ProcessImageName: nvngx_update.exe, Pid: 9984, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 5%

2025-11-21T22:42:20.316 ProcessImageName: updater.exe, Pid: 3628, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: updater.exe, Pid: 6024, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9ab8cbd3-cf46-41e8-8dea-0918f07d3b85.tmp, EstimatedImpact: 0%

2025-11-21T22:42:20.316 ProcessImageName: backgroundTaskHost.exe, Pid: 18116, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\310091\1763146039, EstimatedImpact: 1%

2025-11-21T22:42:20.316 ProcessImageName: nvngx_update.exe, Pid: 18496, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-21T22:43:29.472 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T22:52:06.830 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #133250, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T22:52:06.833 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #133251, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T22:52:16.837 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #133447, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T22:52:16.842 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #133448, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T22:58:34.460 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T23:10:36.194 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg. Process: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\Display.NvContainer\NVDisplay.Container.exe, Status: 0xc0000001, State: 0, ScanRequest #134109, FileId: 0xd4000000008fc0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:10:36.201 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\ProgramData\NVIDIA\DisplaySessionContainer3.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #134112, FileId: 0x250000000002d9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:10:36.219 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg. Process: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\Display.NvContainer\NVDisplay.Container.exe, Status: 0xc0000001, State: 0, ScanRequest #134114, FileId: 0xd5000000008fc0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:10:36.263 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\NvContainer\NvContainerSession3.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #134120, FileId: 0x1ea000000007930, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:10:36.645 Engine:Process 880 will be fully monitored because of injection from C:\Windows\System32\dwm.exe

2025-11-21T23:10:38.010 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg. Process: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\Display.NvContainer\NVDisplay.Container.exe, Status: 0xc0000001, State: 0, ScanRequest #134259, FileId: 0xf0000000142b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:10:38.038 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg. Process: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\Display.NvContainer\NVDisplay.Container.exe, Status: 0xc0000001, State: 0, ScanRequest #134267, FileId: 0x1d0000000162f8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:10:39.100 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\ShadowPlay\CaptureCore.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #134406, FileId: 0x500000001ce2c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x0, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:10:40.164 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg. Process: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\Display.NvContainer\NVDisplay.Container.exe, Status: 0xc0000001, State: 0, ScanRequest #134579, FileId: 0xaf000000001940, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:10:48.490 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\ShadowPlay\CaptureCore.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #134860, FileId: 0x500000001ce2c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x0, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:11:00.950 Bm signature throttled:0x00002db31bed458f

2025-11-21T23:11:02.277 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Mozilla\Firefox\Profiles\vklme25l.default-release\datareporting\glean\events\pageload. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #135250, FileId: 0x1c00000000b939, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:11:17.665 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #135296, FileId: 0xe3000000015fd2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

Internal signature match:subtype=Lowfi, sigseq=0x00008AE758D247FB, sigsha=79cc60f8c8a572c0f0bac7e3da065959cd19bd97, cached=false, source=2, resourceid=0xb019c8db

2025-11-21T23:12:34.151 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-21T23:12:34.151 [Cloud] Start of cloud request. Passive mode: 0

2025-11-21T23:12:34.151 [Cloud] Queued cloud request.

2025-11-21T23:12:34.151 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-21T23:12:34.151 [Cloud] Dequeued cloud request.

2025-11-21T23:12:34.151 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-21T23:12:34.443 Dynamic signature received

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a56ce1accc5a5378c73e66a63c16dc1857da8ae6

Dynamic Signature Compilation Timestamp:11-21-2025 23:12:34

Persistence Type:Duration

Time remaining:50065408

2025-11-21T23:12:34.446 [Cloud] End of cloud request.

2025-11-21T23:12:34.447 RTSD:RTSD recieved, rescanning impacted resources

2025-11-21T23:12:34.989 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T23:13:39.455 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T23:14:57.851 Bm signature throttled:0x00002db31bed458f

2025-11-21T23:14:59.341 Bm signature throttled:0x00002db31bed458f

2025-11-21T23:15:34.805 Bm signature throttled:0x00002db31bed458f

2025-11-21T23:23:02.165 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Ookla.SpeedtestbyOokla_43tkc6nmykmb6\TempState\UnityPlayer.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #136824, FileId: 0x2e10000000079fc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=2, resourceid=0x7385b4e5

Internal signature match:subtype=Lowfi, sigseq=0x0000055508F3A39A, sigsha=adc296cf14a948811ec4fc94642d047458c25c9d, cached=false, source=2, resourceid=0xaab25df3

Internal signature match:subtype=Lowfi, sigseq=0x0000157E63AB3170, sigsha=e38cd0eab571423665adf9aa5888e28cacf8b14e, cached=false, source=2, resourceid=0x0e2f25c4

Internal signature match:subtype=Lowfi, sigseq=0x0000108090FCF4C4, sigsha=064f0536ffb97bb72d6c274c080aa4e2ffdf1b46, cached=false, source=2, resourceid=0xe9a0dc71

2025-11-21T23:27:25.859 Engine:Setting original file name "BM_IsPotentialSideLoad" for "c:\xampp\mercurymail\sqlite3.dll", hr=0x0

Internal signature match:subtype=Lowfi, sigseq=0x0006D3BDCFCEABEE, sigsha=c9c8b6b7c7b47b78581c804bcb01032bb84e2863, cached=false, source=2, resourceid=0x1605cb09

Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=2, resourceid=0xe2dca15a

Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=2, resourceid=0xf4aea03a

Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=2, resourceid=0x360f1922

Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=2, resourceid=0x7c00d887

Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=2, resourceid=0x813b6143

Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=2, resourceid=0x209998a4

Internal signature match:subtype=Lowfi, sigseq=0x00001A2985E55790, sigsha=88cbf2a3b3bf6b6a86b3ca3d8c024e1f4a6f32b9, cached=false, source=2, resourceid=0x5636c29d

Internal signature match:subtype=Lowfi, sigseq=0x0000157E5BFB8B84, sigsha=01d0db7a78767ad28dfc9cac69cd21960dc49ff8, cached=false, source=2, resourceid=0xd06b509f

2025-11-21T23:28:44.457 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=2, resourceid=0x7385b4e5

2025-11-21T23:30:57.738 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\xampp\apache\logs\error.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #172769, FileId: 0x23000000054431, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:32:48.236 Bm signature throttled:0x00002db31bed458f

2025-11-21T23:37:46.121 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\ProgramData\NVIDIA\DisplaySessionContainer3.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #173132, FileId: 0x1910000000086ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:37:46.129 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\NvContainer\NvContainerSession3.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #173134, FileId: 0x10000000014565, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:37:46.162 Bm signature throttled:0x00002db31bed458f

2025-11-21T23:37:46.819 Task(MpCmdRun.exe AdvertiseSso) launched under the given user session

2025-11-21T23:39:17.769 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Windows\SystemTemp\chrome_installer.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #173811, FileId: 0xed0000000248e9, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:39:18.710 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #173816, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:39:18.714 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #173819, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:39:32.910 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Windows\SystemTemp\chrome_installer.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #173845, FileId: 0xed0000000248e9, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:39:57.893 ReportLowfi(c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe, 0x83161cd9) from 0x0002c9bd4055ee43

2025-11-21T23:39:57.893 ReportLowfi(c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe , 0x83161cd9) from 0x0002c9bd4055ee43

2025-11-21T23:43:03.438 Bm signature throttled:0x00002db31bed458f

2025-11-21T23:43:49.455 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-21T23:46:30.798 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-21T23:46:30.811 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-21T23:46:32.158 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-21T23:46:32.158 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-21T23:46:34.162 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext)

2025-11-21T23:46:34.162 [Cloud] Start of cloud request. Passive mode: 0

2025-11-21T23:46:34.162 [Cloud] Queued cloud request.

2025-11-21T23:46:34.162 [Cloud] Dequeued cloud request.

2025-11-21T23:46:34.178 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-21T23:46:34.289 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-21T23:46:34.289 [Cloud] End of cloud request.

2025-11-21T23:46:34.798 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-21T23:46:37.583 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent_new.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #174990, FileId: 0xb400000002429f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:46:49.821 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent_new.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #175021, FileId: 0x16400000000206b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:48:42.792 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\xampp\apache\logs\error.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #175113, FileId: 0x23000000054431, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:52:08.223 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #175532, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:52:08.229 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #175533, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:52:12.481 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #175556, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:52:18.238 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #175563, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:52:18.238 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #175564, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:52:18.238 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #175566, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:53:09.428 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent_new.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #175676, FileId: 0x1010000000039b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:58:22.551 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent_new.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #176460, FileId: 0x4b000000042542, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-21T23:58:54.445 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-21T23:59:55.961 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent_new.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #176734, FileId: 0x25b000000024278, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T00:00:51.324 Engine:Process 14640 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.325 Engine:Process 3328 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.325 Engine:Process 23408 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.326 Engine:Process 23408 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.328 Engine:Process 12984 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.328 Engine:Process 24056 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.343 Engine:Process 3328 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.365 Engine:Process 14640 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.369 Engine:Process 3328 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.380 Engine:Process 3328 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.390 Engine:Process 3328 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.399 Engine:Process 24056 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.400 Engine:Process 14640 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.412 Engine:Process 14640 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.412 Engine:Process 24056 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.412 Engine:Process 24056 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.412 Engine:Process 23408 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.412 Engine:Process 3328 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.412 Engine:Process 23408 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.412 Engine:Process 14640 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.412 Engine:Process 23408 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.412 Engine:Process 14640 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.421 Engine:Process 23408 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.421 Engine:Process 3328 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.425 Engine:Process 12984 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.427 Engine:Process 24056 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.429 Engine:Process 12984 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.431 Engine:Process 12984 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.431 Engine:Process 12984 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.431 Engine:Process 24056 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:00:51.441 Engine:Process 24056 will be fully monitored because of injection from C:\Windows\System32\svchost.exe

2025-11-22T00:01:29.607 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #177253, FileId: 0x155000000024224, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T00:01:40.175 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #177280, FileId: 0xe4000000015fd2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T00:13:59.442 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T00:16:29.827 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #178884, FileId: 0x1200000001c7a3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T00:17:09.437 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3

2025-11-22T00:17:09.438 Job Notification: New process added to job (22736)

2025-11-22T00:17:09.441 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched

2025-11-22T00:17:09.442 Aggressive catchup quick scan threshold: 3455970407900 / 25920000000000

2025-11-22T00:17:09.445 Job Notification: New process added to job (25564)

2025-11-22T00:17:09.454 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:22736] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:25564]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-22T00:17:09.503 Job Notification: New process added to job (21888)

2025-11-22T00:17:09.506 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched

2025-11-22T00:17:09.507 Job Notification: New process added to job (18948)

2025-11-22T00:17:09.513 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:21888] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:18948]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-22T00:17:09.532 Job Notification: New process added to job (7316)

2025-11-22T00:17:09.535 Task(GetDeviceTicket -AccessKey CB1C2EF8-B6CB-D6C3-71E8-A77F76A78FA1 ) launched as network service

2025-11-22T00:17:09.961 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-22T00:17:09.961 [RTP] Duplicating the current plugin configuration object...

2025-11-22T00:17:09.961 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-22T00:17:09.961 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-22T00:17:09.962 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-22T00:17:09.962 [RTP] No config change detected. Not updating plugin configuration.

2025-11-22T00:17:09.962 [RTP] No config changes found. No configuration switch.

2025-11-22T00:17:09.962 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-22T00:17:09.967 Job Notification: Process exited from job (7316)

2025-11-22T00:17:10.156 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-22T00:17:10.156 [Cloud] Start of cloud request. Passive mode: 0

2025-11-22T00:17:10.156 [Cloud] Queued cloud request.

2025-11-22T00:17:10.156 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-22T00:17:10.156 [Cloud] Dequeued cloud request.

2025-11-22T00:17:10.157 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-22T00:17:10.157 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0

2025-11-22T00:17:10.157 [Cloud] Start of cloud request. Passive mode: 0

2025-11-22T00:17:10.157 [Cloud] Queued cloud request.

2025-11-22T00:17:10.157 [Cloud] Dequeued cloud request.

2025-11-22T00:17:10.158 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-22T00:17:10.275 [Cloud] End of cloud request.

2025-11-22T00:17:10.320 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-22T00:17:10.320 [Cloud] End of cloud request.

2025-11-22T00:17:10.675 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T00:17:23.390 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\2C84FA87-B217-4779-83C7-608C487427ED46f4.1dc5b455effc69e

2025-11-22T00:17:23.424 Verifying engine and signature files (source: 0) ...

2025-11-22T00:17:23.424 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{459570F3-4ADA-46DC-B885-78598EDC5934}\mpengine.dll] due to PPL.

2025-11-22T00:17:23.424 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{459570F3-4ADA-46DC-B885-78598EDC5934}\mpasbase.vdm] (file in cache)

2025-11-22T00:17:23.425 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{459570F3-4ADA-46DC-B885-78598EDC5934}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-22T00:17:23.434 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{459570F3-4ADA-46DC-B885-78598EDC5934}\mpasdlta.vdm]

2025-11-22T00:17:23.434 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{459570F3-4ADA-46DC-B885-78598EDC5934}\mpavbase.vdm] (file in cache)

2025-11-22T00:17:23.434 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{459570F3-4ADA-46DC-B885-78598EDC5934}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-22T00:17:23.444 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{459570F3-4ADA-46DC-B885-78598EDC5934}\mpavdlta.vdm]

2025-11-22T00:17:23.527 [Engine] IsHybridMode: 0

2025-11-22T00:17:23.529 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-22T00:17:23.538 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-03606451C43384F3678A56AF361845D8F8051DA0.bin): 0x00000002

2025-11-22T00:17:23.539 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-03606451C43384F3678A56AF361845D8F8051DA0.bin)

2025-11-22T00:17:23.539 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-22T00:17:23.539 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-22T00:17:23.539 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-22T00:17:23.539 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-22T00:17:29.254 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-22T00:17:29.254 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-22T00:17:29.263 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFEBC4FA660, lRefCount: 5, hr=0

2025-11-22T00:17:29.263 [Engine] New active engine 00007FFE7F1CA660 replacing engine 00007FFEBC4FA660. Number of active engines: 2

2025-11-22T00:17:29.270 EngineInit:Global ASOC is enabled

2025-11-22T00:17:29.270 EngineInit:ASOO is enabled for developer volumes

2025-11-22T00:17:29.304 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-22T00:17:29.304 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.304 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-22T00:17:29.304 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-22T00:17:29.304 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-22T00:17:29.304 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.304 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.304 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.304 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-22T00:17:29.304 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.304 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.304 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-22T00:17:29.305 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.305 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.305 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.305 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.305 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.305 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.305 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T00:17:29.305 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\12c27b036408e0bbb458262d54219f7edfefa6bc

Dynamic Signature Compilation Timestamp:11-11-2025 19:01:22

Persistence Type:Duration

Time remaining:50065408

2025-11-22T00:17:29.306 Dynamic signature dropped

2025-11-22T00:17:29.308 MpWriteUupSignatureVersion 1.441.396.0, hr = 0

2025-11-22T00:17:29.309 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-22T00:17:29.320 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-22T00:17:29.322 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-22T00:17:29.322 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-22T00:17:29.322 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-22T00:17:29.322 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-22T00:17:29.338 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-22T00:17:29.338 [Plugin] Initializing RTP plugin state...

2025-11-22T00:17:29.338 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-22T00:17:29.338 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 21 - 2025 15:42:20

Last Perf: 11 - 21 - 2025 15:42:20

First RTP Scan: 11 - 21 - 2025 15:42:21

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:4665

  Misses:32251

BM Queue:0,191,0

  Proc:0,130,0

  File:0,133,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:179011

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1084860682

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:17

  TotalStreamCon:29483

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:863398

   TotalHits:1426371

   InstanceCacheInserts:63137

   InstanceCacheUpdates:0

   InstanceCacheDeletes:40211

   InstanceCacheHits:2241

   InstanceCacheMisses:263088

   InstanceCacheOverflows:8633

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (3162/3359)

   Success: 3359, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-22T00:17:29.338 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{459570F3-4ADA-46DC-B885-78598EDC5934}

2025-11-22T00:17:29.339 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F201DCC8-58E9-4A40-A834-EFC3193FECC5}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F201DCC8-58E9-4A40-A834-EFC3193FECC5}\mpasbase.vdm in use, hr=0x80070020

2025-11-22T00:17:29.339 [SCC][CID=377344953_22456] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-22T00:17:29.339 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-22T00:17:29.340 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-22T00:17:29.340 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-22T00:17:29.340 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-22T00:17:29.340 MdCoreSvc is supported in this platform and OS

2025-11-22T00:17:29.340 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-22-2025 00:17:29

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-22-2025 00:17:29

2025-11-22T00:17:29.343 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-22T00:17:29.343 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-22T00:17:29.344 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-22T00:17:29.344 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-22-2025 00:17:29

END TDT(U) telemetry



2025-11-22T00:17:29.346 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T00:17:29.346 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-22T00:17:29.346 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-22T00:17:29.347 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-22T00:17:29.347 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-22T00:17:29.347 MdCoreSvc is supported in this platform and OS

Signature updated on 11-22-2025 00:17:29

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.396.0

AV Signature Version: 1.441.396.0

************************************************************

2025-11-22T00:17:29.348 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-22T00:17:29.348 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\2C84FA87-B217-4779-83C7-608C487427ED46f4.1dc5b455effc69e

2025-11-22T00:17:29.357 Process scan (postsignatureupdatescan) started.

2025-11-22T00:17:29.391 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-22T00:17:29.392 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

Signature updated via MicrosoftUpdateServer on 11-22-2025 00:17:29

************************************************************

2025-11-22T00:17:29.432 Job Notification: Process exited from job (21888)

2025-11-22T00:17:29.434 Job Notification: Process exited from job (18948)

2025-11-22T00:17:29.467 Job Notification: Process exited from job (22736)

2025-11-22T00:17:29.468 Job Notification: Process exited from job (25564)

2025-11-22T00:17:29.541 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-22T00:17:29.541 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-22T00:17:29.541 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-22T00:17:29.541 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-22T00:17:29.541 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-22T00:17:29.545 [Engine] Engine 00007FFEBC4FA660 no longer in use. Number of active engines: 1

2025-11-22T00:17:29.545 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-22T00:17:29.545 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-22T00:17:29.716 ProcessImageName: xampp-windows-x64-8.2.12-0-VS16-installer(1).exe, Pid: 25368, TotalTime: 147946, Count: 22457, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume4\xampp\sendmail\sendmail.exe, EstimatedImpact: 43%

2025-11-22T00:17:29.716 ProcessImageName: ffmpeg.exe, Pid: 17932, TotalTime: 65990, Count: 8156, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\libx265_main12.dll, EstimatedImpact: 35%

2025-11-22T00:17:29.716 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 18261, Count: 2419, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\Brooklyn Nine-Nine (2013) Season 1-8 S01-S08 (1080p AMZN WEB-DL x265 HEVC 10bit EAC3 5.1 Silence) REPACK\Season 4\Brooklyn Nine-Nine (2013) - S04E04 - The Night Shift (1) (1080p AMZN WEB-DL x265 Silence).mkv, EstimatedImpact: 0%

2025-11-22T00:17:29.716 ProcessImageName: EmbyServer.exe, Pid: 18312, TotalTime: 8793, Count: 1027, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\ffprobe.exe, EstimatedImpact: 0%

2025-11-22T00:17:29.716 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 6425, Count: 445, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\plugins\Emby.Dlna.dll, EstimatedImpact: 0%

2025-11-22T00:17:29.716 ProcessImageName: NVIDIA Overlay.exe, Pid: 10484, TotalTime: 3543, Count: 366, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9812c55a-673b-491d-98b5-c196d695cfe6.tmp, EstimatedImpact: 0%

2025-11-22T00:17:29.716 ProcessImageName: SrTasks.exe, Pid: 6496, TotalTime: 3431, Count: 1080, MaxTime: 296, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 7%

2025-11-22T00:17:29.716 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 3424, Count: 278, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\97f14c1b-571e-4b38-9c29-806fd1a9c80e.tmp, EstimatedImpact: 0%

2025-11-22T00:17:29.716 ProcessImageName: helper.exe, Pid: 11632, TotalTime: 2217, Count: 81, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 84%

2025-11-22T00:17:29.716 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 2178, Count: 228, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\osc\main.497d57969ef1c036.js, EstimatedImpact: 0%

2025-11-22T00:17:29.716 ProcessImageName: ffmpeg.exe, Pid: 25108, TotalTime: 1620, Count: 256, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\transcoding-temp\C41826\C41826_s3.m3u8.tmp, EstimatedImpact: 23%

2025-11-22T00:17:29.716 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1422, Count: 84, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\bfs.sys, EstimatedImpact: 81%

2025-11-22T00:17:29.716 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1231, Count: 196, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\e60c1a038e1886e936e51bf063c60be29b6aa7c194f787331aac46e2f567edff\Ontology64.dll, EstimatedImpact: 0%

2025-11-22T00:17:29.716 ProcessImageName: ffmpeg.exe, Pid: 7484, TotalTime: 1065, Count: 184, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\transcoding-temp\ECCD09\ECCD09_0.ts.tmp, EstimatedImpact: 24%

2025-11-22T00:17:29.716 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1061, Count: 102, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server.exe, EstimatedImpact: 0%

2025-11-22T00:17:29.716 ProcessImageName: filezilla-server-gui.exe, Pid: 8692, TotalTime: 1026, Count: 14, MaxTime: 484, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\wxmsw32u_core_gcc_custom.dll, EstimatedImpact: 100%

2025-11-22T00:17:29.736 [Engine] RSIG_UNLOADENGINE, 00007FFEBC4FA660, err=0x0

2025-11-22T00:17:29.761 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F201DCC8-58E9-4A40-A834-EFC3193FECC5} removed

2025-11-22T00:17:29.828 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-22T00:17:29.836 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-22T00:17:29.836 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-22T00:17:29.836 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-22T00:17:29.836 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-22T00:17:29.836 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-22T00:17:29.836 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-22T00:17:29.840 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-22T00:17:29.840 [RTP] Duplicating the current plugin configuration object...

2025-11-22T00:17:29.840 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-22T00:17:29.840 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-22T00:17:29.840 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-22T00:17:29.840 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-22T00:17:29.840 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-22T00:17:29.840 [RTP] No config change detected. Not updating plugin configuration.

2025-11-22T00:17:29.840 [RTP] No config changes found. No configuration switch.

2025-11-22T00:17:29.840 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-22T00:17:29.840 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-22T00:17:29.840 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-22T00:17:29.840 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-22T00:17:29.841 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-22T00:17:29.841 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-22T00:17:29.841 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-22T00:17:29.841 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-22T00:17:29.841 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-22T00:17:29.841 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-22T00:17:29.841 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-22T00:17:29.841 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-22T00:17:29.841 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-22T00:17:29.841 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-22T00:17:29.841 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-22T00:17:29.841 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-22T00:17:29.841 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T00:17:29.843 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T00:17:29.845 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T00:17:29.846 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T00:17:29.848 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T00:17:29.850 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 4285012(ms) from now at 02:28 (01:28 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-22T00:17:31.363 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-22T00:17:31.368 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-22T00:17:31.368 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-22T00:17:32.361 [RTP] Duplicating the current plugin configuration object...

2025-11-22T00:17:32.361 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-22T00:17:32.361 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-22T00:17:32.361 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-22T00:17:32.361 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-22T00:17:35.463 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-22T00:17:35.463 [Cloud] Start of cloud request. Passive mode: 0

2025-11-22T00:17:35.463 [Cloud] Queued cloud request.

2025-11-22T00:17:35.463 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-22T00:17:35.463 [Cloud] Dequeued cloud request.

2025-11-22T00:17:35.463 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-22T00:17:35.855 [Cloud] End of cloud request.

2025-11-22T00:17:36.374 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T00:17:45.559 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-22T00:17:45.559 Process scan (postsignatureupdatescan) completed.

2025-11-22T00:22:29.296 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-22T00:29:04.440 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T00:31:30.236 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #180083, FileId: 0x2b000000054726, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T00:44:09.437 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T00:46:30.921 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #180933, FileId: 0x46000000025034, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T00:52:06.100 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #181160, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T00:52:06.104 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #181161, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T00:52:16.115 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #181174, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T00:52:16.119 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #181175, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T00:59:14.431 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T01:01:31.455 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #181567, FileId: 0x1b000000054860, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T01:14:19.426 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T01:16:32.023 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #182484, FileId: 0x1b000000054725, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T01:29:24.420 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T01:31:33.335 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #182571, FileId: 0x1d7000000019570, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T01:34:13.455 Bm signature throttled:0x0000fab3228bcd4d

2025-11-22T01:39:44.350 [AutoPurge] Verification Routine tasks have started.

2025-11-22T01:39:44.350 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-22T01:39:44.352 [AutoPurge] Routine task for Cache Maintenance has started.

2025-11-22T01:39:44.353 [AutoPurge] Routine task for Cache Maintenance ...

2025-11-22T01:39:44.353 [AutoPurge] Routine task for MpSFCBuild ...

2025-11-22T01:39:44.353 [AutoPurge] MpCmIsBuildCompleted() - S_OK

2025-11-22T01:39:44.353 [AutoPurge] MpSignalMaintenanceMode ...

2025-11-22T01:39:44.357 [AutoPurge] Cleanup Routine tasks have started.

2025-11-22T01:39:44.362 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:1C4ADF66-9349-4630-BB25-5CF60B7E048E, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1)

2025-11-22T01:39:44.362 Scheduled scan with Id 1C4ADF66-9349-4630-BB25-5CF60B7E048E configured CPU priority: normal (LowCpuPriority: 0)

2025-11-22T01:39:44.362 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0)

2025-11-22T01:39:44.363 [AutoPurge] Purged 0 expired detection item(s) from a total of 0.

2025-11-22T01:39:44.363 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds)

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:65538

Start time:11-22-2025 01:39:44

2025-11-22T01:39:44.363 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build.

2025-11-22T01:39:44.363 [SFC] System file cache build is not needed (already completed)

2025-11-22T01:39:44.364 QuickScan:ScanID:1C4ADF66-9349-4630-BB25-5CF60B7E048E: Quick Scan skipped since it already ran during the past 7 days

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-22-2025 01:39:44

2025-11-22T01:39:44.364 QuickScan:ScanID:1C4ADF66-9349-4630-BB25-5CF60B7E048E: Quick scan finished with error 1223

2025-11-22T01:39:44.365 OnDemandScanWorker: Scan Cancelled! scanId:1C4ADF66-9349-4630-BB25-5CF60B7E048E, hr = 0x80508018

!ERROR

Begin Quick Scan

Scan ID:{1C4ADF66-9349-4630-BB25-5CF60B7E048E}

Scan Source:1

Start Time:11-22-2025 01:39:44

Unsuccessful Scan

Return Code:1223

************************************************************



2025-11-22T01:39:44.368 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ...

2025-11-22T01:39:44.368 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0 ...

2025-11-22T01:39:44.368 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0 ...

2025-11-22T01:39:44.370 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ...

2025-11-22T01:39:44.371 [AutoPurge] Cleanup Routine tasks have ended.

2025-11-22T01:39:44.424 EnsureProtectedFolderAcls(), hr = 0x0

2025-11-22T01:39:44.427 [AutoPurge] MpReinforceServiceAcls: 0

2025-11-22T01:39:44.438 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0

2025-11-22T01:39:44.440 Engine:Setting original file name "WIARPC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiarpc.dll.mui_0c913b87", hr=0x0

2025-11-22T01:39:44.442 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed.

2025-11-22T01:39:44.443 [AutoPurge] Verification Routine tasks have ended.

2025-11-22T01:39:44.477 Engine:Setting original file name "nlsbres.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..ocale-nls.resources_31bf3856ad364e35_10.0.26100.4484_nb-no_339b02f7f61c146e\winnlsres.dll.mui", hr=0x0

2025-11-22T01:39:44.770 Engine:Setting original file name "IEXPLORE.EXE" for "c:\program files (x86)\internet explorer\en-us\iexplore.exe.mui", hr=0x0

2025-11-22T01:39:44.803 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_en-us_1258b52c940aadb7_winload.efi.mui_35ee487d", hr=0x0

2025-11-22T01:39:45.365 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sr-..-rs_d1943ecc8317ab66_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-22T01:39:45.508 Engine:Setting original file name " " for "c:\program files (x86)\steam\bin\cef\cef.win7x64\dxcompiler.dll", hr=0x0

2025-11-22T01:39:45.555 Engine:Setting original file name "dual_engine_adapter.dll" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\dual_engine_adapter_x64.dll", hr=0x0

2025-11-22T01:39:45.718 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\winsxs\wow64_microsoft-windows-bcp47languages_31bf3856ad364e35_10.0.26100.7019_none_40ac55a9bb1ab239\bcp47langs.dll", hr=0x0

2025-11-22T01:39:45.733 Engine:Setting original file name "MAPI32.DLL.MUI" for "c:\windows\system32\nb-no\mapistub.dll.mui", hr=0x0

2025-11-22T01:39:45.913 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-22T01:39:45.957 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_ar-sa_af75f4ef024a79a1_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-22T01:39:46.037 Engine:Setting original file name "Apphelp" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a4bb088d5aa4193f97a4bdef0c1f8c71\apphelp.dll.mui", hr=0x0

2025-11-22T01:39:46.089 Engine:Setting original file name "F12Chooser.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-ie-iechooser.resources_31bf3856ad364e35_11.0.26100.1_nb-no_a7630c027f26ac69\iechooser.exe.mui", hr=0x0

2025-11-22T01:39:46.131 Engine:Setting original file name "THEMESERVICE.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-themeservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_5e5bf64d5b3ca824_themeservice.dll.mui_9e71f1ab", hr=0x0

2025-11-22T01:39:46.171 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_ad141a64b8fd6038_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:46.269 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\wow64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.26100.712_none_5cfec91758ee0662\windows.security.credentials.ui.credentialpicker.dll", hr=0x0

2025-11-22T01:39:46.342 Engine:Setting original file name "mavinject32.exe" for "c:\windows\winsxs\wow64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_592d553ad6e77100\mavinject.exe", hr=0x0

2025-11-22T01:39:46.374 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-22T01:39:46.377 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-22T01:39:46.378 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-22T01:39:46.476 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_bfcde09794ad7074_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-22T01:39:46.487 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\zh-cn\memtest.efi.mui", hr=0x0

2025-11-22T01:39:46.606 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_nb-no_022ea2e874b2cab6_winresume.efi.mui_f412814e", hr=0x0

2025-11-22T01:39:46.683 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lt-lt_11cd7cc1c62eb609_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:46.973 Engine:Setting original file name "WmiApSrv.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiapsrv.exe.mui_b1567840", hr=0x0

2025-11-22T01:39:47.042 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kk-kz_bb9a512b689c9b87_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:47.072 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_b5793645604cae79_memtest.efi.mui_71e15c22", hr=0x0

2025-11-22T01:39:47.091 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_he-il_3abd6f82e93c03e5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:47.100 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.26100.1_en-us_c3d82ef5c0380efa_wudfpf.sys.mui_f61e9e86", hr=0x0

2025-11-22T01:39:47.370 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaihdrx.dll", hr=0x0

2025-11-22T01:39:47.535 Engine:Setting original file name "l3codec.acm.mui" for "c:\windows\system32\nb-no\l3codeca.acm.mui", hr=0x0

2025-11-22T01:39:47.647 Engine:Setting original file name "w32topl.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_10.0.26100.1_none_cbd0eec659c2eb5c_w32topl.dll_1a0f388b", hr=0x0

2025-11-22T01:39:47.662 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ms-my_6f80e6fda2cebe8f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:47.949 Engine:Setting original file name "NVPTXJITCOMPILER32.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvptxjitcompiler64.dll", hr=0x0

2025-11-22T01:39:47.992 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5de87d4a39ffc584310f0b06dff9fcd0\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-22T01:39:48.075 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_38f499759ea365c4_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:48.133 Engine:Setting original file name "ddputils.lib.mui" for "c:\windows\system32\nb-no\ddputils.dll.mui", hr=0x0

2025-11-22T01:39:48.260 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kn-in_6e7a81f857a45cbe_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:48.297 Engine:Setting original file name "officeimm.odf" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\office.odf", hr=0x0

2025-11-22T01:39:48.384 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-22T01:39:48.387 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-22T01:39:48.388 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-22T01:39:48.521 Engine:Setting original file name ""AcGenral.dll"" for "c:\windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_10.0.26100.7019_none_a8119654a230db44\acgenral.dll", hr=0x0

2025-11-22T01:39:48.611 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sr-..-rs_7327597d7718c882_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:48.641 Engine:Setting original file name "Hyper-V Host Compute Service Diagnostics Tool" for "c:\windows\winsxs\amd64_hyperv-compute-cont..sticstool.resources_31bf3856ad364e35_10.0.26100.1_en-us_61074b8c7d2f38cf\hcsdiag.exe.mui", hr=0x0

2025-11-22T01:39:48.660 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.32530.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-22T01:39:48.703 Engine:Setting original file name "davsvc.dll.mui" for "c:\windows\system32\nb-no\webclnt.dll.mui", hr=0x0

2025-11-22T01:39:48.738 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\nb-no\wsepno.dll.mui", hr=0x0

2025-11-22T01:39:48.752 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x0

2025-11-22T01:39:48.792 Engine:Setting original file name "bootstr.exe.mui" for "c:\windows\system32\nb-no\bootstr.dll.mui", hr=0x0

2025-11-22T01:39:48.814 Engine:Setting original file name "msvcp140_2_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_2_app.dll", hr=0x0

2025-11-22T01:39:49.045 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-libraryloader-l1-1-0.dll", hr=0x0

2025-11-22T01:39:49.051 Engine:Setting original file name "dvsvc.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..rationsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_5c873aff49ea76e6\dcsvc.dll.mui", hr=0x0

2025-11-22T01:39:49.085 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_qps-ploc_5c9773f9ea1ce396_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:49.087 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_cs-cz_7086b4650c9e547c_memtest.efi.mui_71e15c22", hr=0x0

2025-11-22T01:39:49.197 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa78d0db4729269ff4beb393d45ca94a\dnsapi.dll.mui", hr=0x0

2025-11-22T01:39:49.214 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hr-hr_86baa9ad7eed6d52_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:49.260 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ja-jp_ed01f249e53f7235_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-22T01:39:49.267 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-file-l1-1-0.dll", hr=0x0

2025-11-22T01:39:49.299 Engine:Setting original file name "D3DX10.dll" for "c:\windows\system32\d3dx10_43.dll", hr=0x0

2025-11-22T01:39:49.389 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_da-dk_f5abc0a0339bc397_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:49.487 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-conio-l1-1-0.dll", hr=0x0

2025-11-22T01:39:49.644 Engine:Setting original file name "Auto Enrollment DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..utoenroll.resources_31bf3856ad364e35_10.0.26100.1_en-us_b82b35a9c2228d6b\pautoenr.dll.mui", hr=0x0

2025-11-22T01:39:49.748 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\windows\winsxs\amd64_microsoft-textinput-helpers.resources_31bf3856ad364e35_10.0.26100.1_nb-no_2c9a52bac4b766e3\ime_textinputhelpers.dll.mui", hr=0x0

2025-11-22T01:39:49.763 Engine:Setting original file name "Ribbons" for "c:\windows\winsxs\amd64_microsoft-windows-ribbons.resources_31bf3856ad364e35_10.0.26100.1_en-us_f85e1124efc279b5\ribbons.scr.mui", hr=0x0

2025-11-22T01:39:49.811 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_18153ede37451276\memtest.exe.mui", hr=0x0

2025-11-22T01:39:49.863 Engine:Setting original file name "scecli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\978b70ff94ed14c641fe52c5237facec\scecli.dll.mui", hr=0x0

2025-11-22T01:39:49.889 Engine:Setting original file name "mpsdrv.sys.mui" for "c:\windows\winsxs\backup\amd64_networking-mpssvc-drv.resources_31bf3856ad364e35_10.0.26100.1_nb-no_05849dc2762f9d2d_mpsdrv.sys.mui_b2aea3b6", hr=0x0

2025-11-22T01:39:49.913 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-tw_21b451d70c8c2957_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-22T01:39:50.093 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_2b309b875a6f3e1e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:50.170 Engine:Setting original file name "Vulkan Runtime" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\vulkan-1.dll", hr=0x0

2025-11-22T01:39:50.215 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-p..i-ntprint.resources_31bf3856ad364e35_10.0.26100.1_en-us_6ff199c21e8ad886\ntprint.dll.mui", hr=0x0

2025-11-22T01:39:50.287 Engine:Setting original file name "bootstr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..environment-strings_31bf3856ad364e35_10.0.26100.1_none_f575b80d757af501\bootstr.dll", hr=0x0

2025-11-22T01:39:50.315 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_zh-cn_fd81e6b68df3d1a9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:50.500 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-22T01:39:50.608 Engine:Setting original file name "liblzma.dll" for "c:\program files\windowsapps\microsoft.6365217ce6eb4_102.2509.19002.0_x64__8wekyb3d8bbwe\lzma.dll", hr=0x0

2025-11-22T01:39:50.723 Engine:Setting original file name "wuapi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\uus\x86\nb-no\c120e79170c204b0e5f1ece795e86e83\wuapicore.dll.mui", hr=0x0

2025-11-22T01:39:50.798 Engine:Setting original file name "Ontology.dll" for "c:\users\serverpc\appdata\local\nvidia corporation\nvidia app\nvbackend\applicationontology\ontology64.dll", hr=0x0

2025-11-22T01:39:50.953 Engine:Setting original file name "VpnSohDesktop.dll" for "c:\windows\system32\windows.perception.stub.dll", hr=0x0

2025-11-22T01:39:51.046 Engine:Setting original file name "kernel32" for "c:\windows\syswow64\kernel32.dll", hr=0x0

2025-11-22T01:39:51.082 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.549981c3f5f10_4.2308.1005.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-22T01:39:51.265 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_b38289243d899c4c_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:51.337 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_82eb3d34cd19fa50_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:51.479 Engine:Setting original file name "Steamclient.dll" for "c:\program files (x86)\steam\steamclient64.dll", hr=0x0

2025-11-22T01:39:51.556 Engine:Setting original file name "VrdUmde.dll" for "c:\windows\winsxs\amd64_gpuvirtualizationumed_31bf3856ad364e35_10.0.26100.1150_none_17421023ba072774\vrdumed.dll", hr=0x0

2025-11-22T01:39:51.577 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.efi.mui", hr=0x0

2025-11-22T01:39:51.729 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.winmd", hr=0x0

2025-11-22T01:39:52.079 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_lt-lt_ba1ae95b692b9594_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-22T01:39:52.226 Engine:Setting original file name "windows.ui.xaml.resources.win81.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ctui-resourceswin81_31bf3856ad364e35_10.0.26100.1301_none_b7b52abe3d381205_windows.ui.xaml.resources.win81.dll_d426e245", hr=0x0

2025-11-22T01:39:52.368 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-timezone-l1-1-0.dll", hr=0x0

2025-11-22T01:39:52.417 Engine:Setting original file name "jscript9.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\c3275836e276aea69afa458336037853\jscript9legacy.dll.mui", hr=0x0

2025-11-22T01:39:52.788 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x0

2025-11-22T01:39:52.848 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-profile-l1-1-0.dll", hr=0x0

2025-11-22T01:39:53.088 Engine:Setting original file name "Windows.FileExplorer.Common.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\84c8a2171c12d91e854ffb6a27b39453\windows.fileexplorer.common.dll.mui", hr=0x0

2025-11-22T01:39:53.307 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.26100.1_en-us_99a73e6649d69102\ndisimplatcim.dll.mui", hr=0x0

2025-11-22T01:39:53.359 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-22T01:39:53.438 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-localization-l1-2-0.dll", hr=0x0

2025-11-22T01:39:53.509 Engine:Setting original file name "Placeholder.dll" for "c:\windows\winsxs\x86_netfx4-penimc_v0400_b03f5f7f11d50a3a_4.0.15920.102_none_21046749883d249b\penimc_v0400.dll", hr=0x0

2025-11-22T01:39:53.533 Engine:Setting original file name "NvCamera.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\nvcameraallowlisting32.dll", hr=0x0

2025-11-22T01:39:53.818 Engine:Setting original file name ".NET Host Policy -" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\hostpolicy.dll", hr=0x0

2025-11-22T01:39:54.230 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sv-se_cac4b549037c269f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:54.235 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-22T01:39:54.271 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-22T01:39:54.291 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\winsxs\amd64_microsoft-windows-appx-deployment-server_31bf3856ad364e35_10.0.26100.7171_none_fd3893d466902045\applytrustoffline.exe", hr=0x0

2025-11-22T01:39:54.451 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\wow64_microsoft-windows-a..on-logger.resources_31bf3856ad364e35_10.0.26100.1_en-us_a0e09b8ec526451d\aeevts.dll.mui", hr=0x0

2025-11-22T01:39:54.555 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-22T01:39:54.754 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\4f8d3bb436c7\apex_particleschecked_x86.dll", hr=0x0

2025-11-22T01:39:54.839 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_it-it_72537c4985790e22_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:54.973 Engine:Setting original file name "EsclWiaDriver.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_esclwiadriver.dll.mui_d4a5b959", hr=0x0

2025-11-22T01:39:55.102 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_da-dk_be356ba870c91e76\msprivs.dll.mui", hr=0x0

2025-11-22T01:39:55.105 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-22T01:39:55.120 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_es-es_bdfd06f72820647a_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-22T01:39:55.240 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pl-pl\msprivs.dll.mui", hr=0x0

2025-11-22T01:39:55.258 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-22T01:39:55.281 Engine:Setting original file name "rmactivate.exe.mui" for "c:\windows\syswow64\en-us\rmactivate_isv.exe.mui", hr=0x0

2025-11-22T01:39:55.535 Engine:Setting original file name "apex.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\73be2921551d\apex_turbulencefschecked_x86.dll", hr=0x0

2025-11-22T01:39:55.563 Engine:Setting original file name "ScrCons" for "c:\windows\winsxs\amd64_microsoft-windows-w..consumers.resources_31bf3856ad364e35_10.0.26100.1_en-us_5d0e2df387a86d5d\scrcons.exe.mui", hr=0x0

2025-11-22T01:39:55.572 Engine:Setting original file name "PtpProv" for "c:\windows\winsxs\amd64_microsoft-windows-t..-provider.resources_31bf3856ad364e35_10.0.26100.1_en-us_eec70481b215edf0\ptpprov.dll.mui", hr=0x0

2025-11-22T01:39:55.579 Engine:Setting original file name "GbrtClient.dll" for "c:\program files\windowsapps\spotifyab.spotifymusic_1.276.298.0_x64__zpdnekdrzrea0\microsoft.gaming.xboxgamebar.dll", hr=0x0

2025-11-22T01:39:55.627 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\resources\themes\aero\nb-no\aerolite.msstyles.mui", hr=0x0

2025-11-22T01:39:55.923 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_cd255b4d1be69fe9_winload.efi.mui_35ee487d", hr=0x0

2025-11-22T01:39:55.958 Engine:Setting original file name "pegi.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_en-us_58f534214187451c\pegi.rs.mui", hr=0x0

2025-11-22T01:39:55.965 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-iexpress.resources_31bf3856ad364e35_11.0.26100.1_en-us_f84c0d683fdc407b\wextract.exe.mui", hr=0x0

2025-11-22T01:39:56.467 Engine:Setting original file name "updater.exe" for "c:\program files (x86)\google\update\googleupdate.exe", hr=0x0

2025-11-22T01:39:56.637 Engine:Setting original file name "ServicingBase.dll" for "c:\windows\system32\servicingcommon.dll", hr=0x0

2025-11-22T01:39:56.662 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.exe.mui", hr=0x0

2025-11-22T01:39:56.858 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\vulkan-1.dll", hr=0x0

2025-11-22T01:39:56.914 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_c77eb7b609c47f12\diagpackage.dll.mui", hr=0x0

2025-11-22T01:39:57.062 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\system32\wbem\en-us\netadaptercim.dll.mui", hr=0x0

2025-11-22T01:39:57.091 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\syswow64\nb-no\wextract.exe.mui", hr=0x0

2025-11-22T01:39:57.210 Engine:Setting original file name "NvTelemetry.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvinstallerutil.dll", hr=0x0

2025-11-22T01:39:57.259 Engine:Setting original file name "NvMessageBusBroadcast.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\localsystem\_nvmsgbusbroadcast.dll", hr=0x0

2025-11-22T01:39:57.470 Engine:Setting original file name "NVOPENCL.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvopencl64.dll", hr=0x0

2025-11-22T01:39:57.478 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x0

2025-11-22T01:39:57.552 Engine:Setting original file name "Ribbons" for "c:\windows\system32\nb-no\ribbons.scr.mui", hr=0x0

2025-11-22T01:39:57.727 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_de-de_bb6100e4729f7310\msprivs.dll.mui", hr=0x0

2025-11-22T01:39:57.881 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_en-gb_943f70b729277031_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:57.915 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570\dnsapi.dll.mui", hr=0x0

2025-11-22T01:39:57.919 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x0

2025-11-22T01:39:58.015 Engine:Setting original file name "expediteupdater" for "c:\program files\microsoft update health tools\expediteupdater.exe", hr=0x0

2025-11-22T01:39:58.068 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5fc58c6fab06ca1651cc2f24f6b3294e\dnsapi.dll.mui", hr=0x0

2025-11-22T01:39:58.127 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25101.25.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1025.47515.dll", hr=0x0

2025-11-22T01:39:58.199 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-22T01:39:58.242 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-22T01:39:58.313 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pt-br\msprivs.dll.mui", hr=0x0

2025-11-22T01:39:58.351 Engine:Setting original file name "vcomp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-22T01:39:58.411 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_pt-br_45b1cef334010120_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-22T01:39:58.461 Engine:Setting original file name "DismProvPS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..ing-management-core_31bf3856ad364e35_10.0.26100.7019_none_c721839bdaa557fd\dismcoreps.dll", hr=0x0

2025-11-22T01:39:58.574 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x0

2025-11-22T01:39:58.611 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.efi", hr=0x0

2025-11-22T01:39:58.615 Engine:Setting original file name "ProfSvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-profsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_63afbc426d007f3f_profsvc.dll.mui_32482e9e", hr=0x0

2025-11-22T01:39:58.723 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25101.25.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x0

2025-11-22T01:39:58.728 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2cfe4c864d785675f415b7e6aa962e4\msinfo32.exe.mui", hr=0x0

2025-11-22T01:39:58.958 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\6dfad87d7e49db84e1a96c1c1b32fef6\msidntld.dll.mui", hr=0x0

2025-11-22T01:39:58.977 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7\memtest.exe.mui", hr=0x0

2025-11-22T01:39:59.088 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pa-in_9c6b14ad918eaffd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:59.108 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ar-sa_51090f9ff64b96bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:39:59.159 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.26100.1_en-us_c94c280205b42295\bubbles.scr.mui", hr=0x0

2025-11-22T01:39:59.439 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\nb-no\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x0

2025-11-22T01:39:59.466 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-console-l1-2-0.dll", hr=0x0

2025-11-22T01:39:59.482 Engine:Setting original file name "SETUP.EXE.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-wow64-legacy.resources_31bf3856ad364e35_10.0.26100.1_nb-no_735ab890ce560efa\setup16.exe.mui", hr=0x0

2025-11-22T01:39:59.646 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x0

2025-11-22T01:39:59.682 Engine:Setting original file name "RarExt.dll" for "c:\program files\winrar\rarext32.dll", hr=0x0

2025-11-22T01:39:59.728 Engine:Setting original file name "pcw.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-pcw_31bf3856ad364e35_10.0.26100.1150_none_4bf8e6d5066a4f9f_pcw.sys_dbeb0bbd", hr=0x0

2025-11-22T01:39:59.823 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\syswow64\nb-no\ieadvpack.dll.mui", hr=0x0

2025-11-22T01:39:59.861 Engine:Setting original file name "EmbyServer.dll" for "c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe", hr=0x0

2025-11-22T01:39:59.970 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-environment-l1-1-0.dll", hr=0x0

2025-11-22T01:40:00.135 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2535f07be6867822893c0bd7f299affd\dwmcore.dll.mui", hr=0x0

2025-11-22T01:40:00.149 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_am-et_12002fbedc3ad139_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:00.193 Engine:Setting original file name "mavinject64.exe" for "c:\windows\winsxs\amd64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_4ed8aae8a286af05\mavinject.exe", hr=0x0

2025-11-22T01:40:00.366 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_b1cb38b404e84204\seclogon.dll.mui", hr=0x0

2025-11-22T01:40:00.414 Engine:Setting original file name "AuditPolicyGP.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\1e37baae98dce76981781b53776e70b9\auditpolicygpinterop.dll.mui", hr=0x0

2025-11-22T01:40:00.499 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9c4e95300400790b8d8a05d9bf7e1f5c\winnlsres.dll.mui", hr=0x0

2025-11-22T01:40:00.513 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e981bfd75ae177a858ec5c78a5cfda25\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-22T01:40:00.575 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-22T01:40:00.793 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ru-ru_e71c93fcf7d6f33e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:00.854 Engine:Setting original file name "qualityupdateassistant" for "c:\windows\system32\qualityupdateassistant.dll", hr=0x0

2025-11-22T01:40:00.867 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ro-ro_2c617f480dd85974_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:01.005 Engine:Setting original file name "wersvc" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2f884580919ab799dbe1ecd0f275799\wersvc.dll.mui", hr=0x0

2025-11-22T01:40:01.099 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_fa-ir_f7555235024374d9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:01.129 Engine:Setting original file name "ClrCompression" for "c:\program files\windowsapps\microsoft.net.native.runtime.1.7_1.7.25531.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-22T01:40:01.168 Engine:Setting original file name "WIASERVC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiaservc.dll.mui_54051b53", hr=0x0

2025-11-22T01:40:01.172 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-22T01:40:01.207 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ru-ru_0752c1c778fe6e7c_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-22T01:40:01.320 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-22T01:40:01.711 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_id-id_6be80829898706a2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:01.716 Engine:Setting original file name "STI.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_en-us_d64b3cbf22b2a8d1_sti.dll.mui_00a4f15b", hr=0x0

2025-11-22T01:40:01.726 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9035fe481934c33719e75dea902d1698\bcastdvruserservice.dll.mui", hr=0x0

2025-11-22T01:40:01.755 Engine:Setting original file name "NVIDIA Debug Dump" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvdebugdump.exe", hr=0x0

2025-11-22T01:40:01.775 Engine:Setting original file name "acpiex.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-acpiex_31bf3856ad364e35_10.0.26100.1150_none_d0b1f61a88e2f0e9_acpiex.sys_6a8b9aed", hr=0x0

2025-11-22T01:40:01.797 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_60b47cf61af27adc_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-22T01:40:01.813 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x0

2025-11-22T01:40:02.028 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sv-se_29319a980f7b0983_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-22T01:40:02.133 Engine:Setting original file name "pshed.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-pshed_31bf3856ad364e35_10.0.26100.1_none_633b3602ca01eb94_pshed.dll_f6ac239e", hr=0x0

2025-11-22T01:40:02.234 Engine:Setting original file name "ClipSVC.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-client-li..m-service.resources_31bf3856ad364e35_10.0.26100.1_en-us_3f436cbd520195fd_clipsvc.dll.mui_18823613", hr=0x0

2025-11-22T01:40:02.259 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_cy-gb_976c80cbdb5c65c1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:02.489 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_uk-ua_c5d15aec526b5235_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:02.561 Engine:Setting original file name "msfltr32.acm" for "c:\windows\winsxs\wow64_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_10.0.26100.1_none_e82ddbd17df6cb5b\msacm32.dll", hr=0x0

2025-11-22T01:40:02.622 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-22T01:40:02.640 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-22T01:40:02.695 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_6dcfa7c5391fe7a2_dnsapi.dll.mui_97465f8a", hr=0x0

2025-11-22T01:40:02.834 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_3cda2262e7ef70ab_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:02.948 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_10.0.26100.7171_none_f70fffd91c8f0404\winload.exe", hr=0x0

2025-11-22T01:40:03.112 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_et-ee_9786a4bcaafec5cb_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:03.396 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files\mozilla firefox\dxcompiler.dll", hr=0x0

2025-11-22T01:40:03.465 Engine:Setting original file name "Device_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\device\nb-no\edb83efa185c0a23d97fafe6a71cd608\diagpackage.dll.mui", hr=0x0

2025-11-22T01:40:03.490 Engine:Setting original file name "rtutils.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasrtutils_31bf3856ad364e35_10.0.26100.3037_none_a90518339a5ed736_rtutils.dll_243724ab", hr=0x0

2025-11-22T01:40:03.610 Engine:Setting original file name "udiapi.dll" for "c:\windows\system32\udiapiclient.dll", hr=0x0

2025-11-22T01:40:03.634 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-22T01:40:03.697 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaidvc.dll", hr=0x0

2025-11-22T01:40:03.703 Engine:Setting original file name "DWrite" for "c:\windows\winsxs\amd64_microsoft-windows-directwrite.resources_31bf3856ad364e35_10.0.26100.1_en-us_8e75f00536c95f8c\dwrite.dll.mui", hr=0x0

2025-11-22T01:40:03.713 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\windows\syswow64\nb-no\mfc40u.dll.mui", hr=0x0

2025-11-22T01:40:03.829 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.26100.1_en-us_12a038f1fa40c367_wlrmdr.exe.mui_ee563c83", hr=0x0

2025-11-22T01:40:03.930 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.xaml.winmd", hr=0x0

2025-11-22T01:40:04.011 Engine:Setting original file name "raspptp.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasbase-raspptp_31bf3856ad364e35_10.0.26100.1882_none_358d932997f7087d_raspptp.sys_25e89db1", hr=0x0

2025-11-22T01:40:04.105 Engine:Setting original file name "l3codec.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\17e7113a56f3171dc40844c9d3ee9e47\l3codeca.acm.mui", hr=0x0

2025-11-22T01:40:04.143 Engine:Setting original file name "bridgeres.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-networkbridge_31bf3856ad364e35_10.0.26100.2454_none_a3b07853b6183928_bridgeres.dll_55e40455", hr=0x0

2025-11-22T01:40:04.393 Engine:Setting original file name "mf.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..oundation.resources_31bf3856ad364e35_10.0.26100.1_en-us_8b9cc1ab2476fea1\mfpmp.exe.mui", hr=0x0

2025-11-22T01:40:04.492 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-processthreads-l1-1-1.dll", hr=0x0

2025-11-22T01:40:04.564 Engine:Setting original file name "FreeImage.dll" for "c:\program files (x86)\steam\steamapps\common\wallpaper_engine\bin\freeimage64.dll", hr=0x0

2025-11-22T01:40:04.570 Engine:Setting original file name "tier0_s.dll" for "c:\program files (x86)\steam\tier0_s64.dll", hr=0x0

2025-11-22T01:40:04.586 Engine:Setting original file name "nvaudcap.dll" for "c:\windows\syswow64\nvaudcap32v.dll", hr=0x0

2025-11-22T01:40:04.629 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mi-nz_b80bad72b6b0ee53_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:04.659 Engine:Setting original file name "CertCli" for "c:\windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_10.0.26100.1_en-us_61b2ff4b086153b8\certcli.dll.mui", hr=0x0

2025-11-22T01:40:04.664 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\en-us\wsepno.dll.mui", hr=0x0

2025-11-22T01:40:04.692 Engine:Setting original file name "ConfigurationRemotingServer.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\configurationremotingserver.exe", hr=0x0

2025-11-22T01:40:04.704 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_sr-..-rs_e67ffd847af5d250_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:04.707 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\power\en-us\diagpackage.dll.mui", hr=0x0

2025-11-22T01:40:04.734 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay8-payload_31bf3856ad364e35_1.0.26100.4202_none_bb7ce817a226517c\dpnaddr.dll", hr=0x0

2025-11-22T01:40:04.997 Engine:Setting original file name "msfltr32.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8836c193640d589410b5cc3dbe67e146\msacm32.dll.mui", hr=0x0

2025-11-22T01:40:05.099 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_6a24110114ad15ad_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-22T01:40:05.124 Engine:Setting original file name "usk.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\7c8e526d244ad657f882f8bbba0149ec\usk.rs.mui", hr=0x0

2025-11-22T01:40:05.137 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-22T01:40:05.158 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay4-payload_31bf3856ad364e35_1.0.26100.4202_none_186a372066698d60\dpmodemx.dll", hr=0x0

2025-11-22T01:40:05.354 Engine:Setting original file name "Register-CimProvider2.exe.mui" for "c:\windows\syswow64\en-us\register-cimprovider.exe.mui", hr=0x0

2025-11-22T01:40:05.459 Engine:Setting original file name "metabase.dll.mui" for "c:\windows\winsxs\wow64_microsoft-windows-iis-metabase.resources_31bf3856ad364e35_10.0.26100.1_en-us_8ff50fedc8451a7b\metadata.dll.mui", hr=0x0

2025-11-22T01:40:05.463 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x0

2025-11-22T01:40:05.548 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_de-de_ab2a1f0520f5ef2b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:05.619 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_6fced6fbf4c0e3e0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:05.760 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\en-us\diagpackage.dll.mui", hr=0x0

2025-11-22T01:40:05.786 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_7478bb53490dd7a8_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-22T01:40:05.842 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\windows\system32\nb-no\msidntld.dll.mui", hr=0x0

2025-11-22T01:40:05.847 Engine:Setting original file name "glu32" for "c:\windows\winsxs\amd64_microsoft-windows-opengl.resources_31bf3856ad364e35_10.0.26100.1_en-us_9c3b296d3d668ac3\glu32.dll.mui", hr=0x0

2025-11-22T01:40:05.871 Engine:Setting original file name "mf.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mediafoundation_31bf3856ad364e35_10.0.26100.7171_none_384874e2bca9ce3f\mfpmp.exe", hr=0x0

2025-11-22T01:40:05.897 Engine:Setting original file name "msedgeupdate.dll" for "c:\program files (x86)\microsoft\edgeupdate\1.3.207.5\microsoftedgeupdateondemand.exe", hr=0x0

2025-11-22T01:40:05.913 Engine:Setting original file name "scesrv" for "c:\windows\system32\nb-no\scesrv.dll.mui", hr=0x0

2025-11-22T01:40:05.927 Engine:Setting original file name "DWWIN" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ae2b7dc24859d1fa2a509d5b642451b4\dwwin.exe.mui", hr=0x0

2025-11-22T01:40:06.077 Engine:Setting original file name "nvcuvid.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcuvid64.dll", hr=0x0

2025-11-22T01:40:06.114 Engine:Setting original file name "AppHostNameRegistrationVerifier.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\baf91a75f57ca8730dd9a6f926a58dd0\apphostregistrationverifier.exe.mui", hr=0x0

2025-11-22T01:40:06.125 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_en-gb_9672c12aaba943d2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:06.279 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-rtlsupport-l1-1-0.dll", hr=0x0

2025-11-22T01:40:06.300 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-22T01:40:06.330 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_gu-in_97d53b15f69aaeca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:06.379 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_84875939fc6b99b1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:06.399 Engine:Setting original file name "ServDeps.exe.mui" for "c:\windows\syswow64\wbem\nb-no\servdeps.dll.mui", hr=0x0

2025-11-22T01:40:06.434 Engine:Setting original file name "schtasks.exe" for "c:\windows\winsxs\amd64_microsoft-windows-sctasks_31bf3856ad364e35_10.0.26100.6725_none_25e27f3a6574108c\schtasks.exe", hr=0x0

2025-11-22T01:40:06.445 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_e38364b045f31518_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:06.501 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_el-gr_b382575af3d00da3_memtest.efi.mui_71e15c22", hr=0x0

2025-11-22T01:40:06.670 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.26100.1_en-us_0e875971ea5fda56\ieadvpack.dll.mui", hr=0x0

2025-11-22T01:40:06.716 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-datetime-l1-1-0.dll", hr=0x0

2025-11-22T01:40:06.742 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-22T01:40:06.774 Engine:Setting original file name "user32" for "c:\windows\system32\user32.dll", hr=0x0

2025-11-22T01:40:06.854 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.642.119.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-22T01:40:06.866 Engine:Setting original file name "shutdownui" for "c:\windows\winsxs\amd64_microsoft-windows-shutdownext.resources_31bf3856ad364e35_10.0.26100.1_en-us_9bd0f22e3578c871\shutdownext.dll.mui", hr=0x0

2025-11-22T01:40:07.038 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4\memtest.exe.mui", hr=0x0

2025-11-22T01:40:07.081 Engine:Setting original file name ".NET Host Resolver - 8.0.20" for "c:\users\serverpc\appdata\local\temp\emby-server-updater\hostfxr.dll", hr=0x0

2025-11-22T01:40:07.101 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_bs-..-ba_3017f7e2648d7e73_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:07.186 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_quz-pe_0266e81632046792_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:07.303 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lb-lu_cb546bb0b0d79a98_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:07.342 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\amd64_microsoft-windows-a..perience-ait-static_31bf3856ad364e35_10.0.26100.7019_none_ccd1f49f5e2b3b28\aitstatic.exe", hr=0x0

2025-11-22T01:40:07.445 Engine:Setting original file name "UNPShared.dll" for "c:\windows\winsxs\amd64_microsoft-windows-update-upshared_31bf3856ad364e35_10.0.26100.5074_none_29764f36135e6d4c\upshared.dll", hr=0x0

2025-11-22T01:40:07.526 Engine:Setting original file name "messagin.dll" for "c:\program files\bitdefender agent\27.1.1.23\messaging.dll", hr=0x0

2025-11-22T01:40:07.609 Engine:Setting original file name "WindowsCodecs" for "c:\windows\syswow64\windowscodecs.dll", hr=0x0

2025-11-22T01:40:07.649 Engine:Setting original file name "WerMgr" for "c:\windows\system32\wermgr.exe", hr=0x0

2025-11-22T01:40:07.703 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d\memtest.exe.mui", hr=0x0

2025-11-22T01:40:07.707 Engine:Setting original file name "imapi.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bd7c223153b9576fe4c4e66ebf1c6ece\imapi.dll.mui", hr=0x0

2025-11-22T01:40:07.846 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hi-in_8555c5797fc8795e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:07.924 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\esrb.rs.mui", hr=0x0

2025-11-22T01:40:08.020 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-22T01:40:08.043 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_zh-tw_ff4ad39908e2da78_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:08.048 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-22T01:40:08.100 Engine:Setting original file name "microsoftedgedevtools.exe" for "c:\windows\system32\microsoftedgecp.exe", hr=0x0

2025-11-22T01:40:08.125 Engine:Setting original file name "la57setup.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ec428185df2994f7d7954c1efe1b2738\la57setup.exe.mui", hr=0x0

2025-11-22T01:40:08.133 Engine:Setting original file name "wuapi.dll" for "c:\windows\uus\x86\wuapicore.dll", hr=0x0

2025-11-22T01:40:08.196 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\system32\en-us\dsprop.dll.mui", hr=0x0

2025-11-22T01:40:08.323 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-22T01:40:08.348 Engine:Setting original file name "etweseproviderresources.dll" for "c:\windows\winsxs\backup\amd64_microsoft-etw-ese_31bf3856ad364e35_10.0.26100.1_none_cc4e7afeeee8d3b1_etweseproviderresources.dll_f21e8ea7", hr=0x0

2025-11-22T01:40:08.422 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_2821a024e044bada_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:08.424 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-22T01:40:08.465 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bf8ce2a53903d9e6d302aee07de95dd9\mfc40u.dll.mui", hr=0x0

2025-11-22T01:40:08.480 Engine:Setting original file name "TAPISRV.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-tapiservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_83c985f74a352be9\tapisrv.dll.mui", hr=0x0

2025-11-22T01:40:08.694 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lo-la_099683f3cb70d44f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:08.698 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x0

2025-11-22T01:40:08.797 Engine:Setting original file name "wininet.dll" for "c:\windows\systemresources\wininet.dll.mun", hr=0x0

2025-11-22T01:40:08.833 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\nb-no\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x0

2025-11-22T01:40:08.852 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_hu-hu_9dd052ebcaf187fd_memtest.efi.mui_71e15c22", hr=0x0

2025-11-22T01:40:08.855 Engine:Setting original file name "PrintBrmEng.exe.mui" for "c:\windows\system32\spool\tools\en-us\printbrmengine.exe.mui", hr=0x0

2025-11-22T01:40:08.857 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_it-it_4087c8eabdc39e5f_memtest.efi.mui_71e15c22", hr=0x0

2025-11-22T01:40:08.894 Engine:Setting original file name "audioadg.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f411807b0749e7d602e77baf3c1c4e60\audiodg.exe.mui", hr=0x0

2025-11-22T01:40:08.971 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x0

2025-11-22T01:40:09.051 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-t..iprovider.resources_31bf3856ad364e35_10.0.26100.1_en-us_41b711b4f2db4fe7\rdpsign.exe.mui", hr=0x0

2025-11-22T01:40:09.191 Engine:Setting original file name "Video_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\video\nb-no\2ca5a0690699da595bd35a22420a1c04\diagpackage.dll.mui", hr=0x0

2025-11-22T01:40:09.199 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-22T01:40:09.222 Engine:Setting original file name "FvSDKTestClientPublic" for "c:\program files\nvidia corporation\frameviewsdk\sdk\fvsdktestclient_public.exe", hr=0x0

2025-11-22T01:40:09.270 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\qps-ploc\msprivs.dll.mui", hr=0x0

2025-11-22T01:40:09.272 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-22T01:40:09.425 Engine:Setting original file name "mini_installer.exe" for "c:\program files (x86)\microsoft\edgeupdate\download\{56eb18f8-b008-4cbd-b6d2-8c97fe7e9062}\142.0.3595.90\microsoftedge_x64_142.0.3595.90_142.0.3595.80.exe", hr=0x0

2025-11-22T01:40:09.464 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\windows\system32\nb-no\pnpclean.dll.mui", hr=0x0

2025-11-22T01:40:09.477 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_or-in_f89501f89f876dc5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:09.513 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.26100.7171_none_4ad020869b677502\taskmgr.exe.mun", hr=0x0

2025-11-22T01:40:09.567 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_ca98740be1962356_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:09.629 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x0

2025-11-22T01:40:09.683 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_it-it_f0fca0072ba86c5a\msprivs.dll.mui", hr=0x0

2025-11-22T01:40:09.726 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps-ploc_7ccda1c46b445ed4\memtest.exe.mui", hr=0x0

2025-11-22T01:40:09.746 Engine:Setting original file name "NETBIOS.SYS" for "c:\windows\winsxs\backup\amd64_microsoft-windows-netbios_31bf3856ad364e35_10.0.26100.1_none_56d5608ad3abe945_netbios.sys_6f23c4df", hr=0x0

2025-11-22T01:40:09.811 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-process-l1-1-0.dll", hr=0x0

2025-11-22T01:40:09.948 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\systemresources\etwcoreuicomponentsresources.dll.mun", hr=0x0

2025-11-22T01:40:09.960 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pt-br_55b72b827c87f88f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:10.085 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_0dc0948c02e4507b_memtest.efi.mui_71e15c22", hr=0x0

2025-11-22T01:40:10.098 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mt-mt_b4ebaa02b8bfece3_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:10.133 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.devices.winmd", hr=0x0

2025-11-22T01:40:10.175 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_576ce8a1070e9744_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:10.188 Engine:Setting original file name "FileInfo.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-fileinfominifilter_31bf3856ad364e35_10.0.26100.1150_none_729c4b9be137bb96_fileinfo.sys_9be2dfcd", hr=0x0

2025-11-22T01:40:10.278 Engine:Setting original file name "aclui.dll" for "c:\windows\winsxs\amd64_microsoft-windows-aclui_31bf3856ad364e35_10.0.26100.7019_none_f0f7bbb4638cf785\aclui.dll.mun", hr=0x0

2025-11-22T01:40:10.282 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\73be2921551d\apex_fieldsamplerchecked_x86.dll", hr=0x0

2025-11-22T01:40:10.342 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.777.2143.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-22T01:40:10.409 Engine:Setting original file name "qualityupdateassistant" for "c:\program files\microsoft update health tools\qualityupdateassistant.dll", hr=0x0

2025-11-22T01:40:10.439 Engine:Setting original file name "NVPPE.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvppex.dll", hr=0x0

2025-11-22T01:40:10.524 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_en-us_4761fcc7ecd6d884_winresume.efi.mui_f412814e", hr=0x0

2025-11-22T01:40:10.723 Engine:Setting original file name "NVPrxy.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvprxy32.dll", hr=0x0

2025-11-22T01:40:10.834 Engine:Setting original file name "Mystify" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\589bec7339e102473dc7566c3b9b0f45\mystify.scr.mui", hr=0x0

2025-11-22T01:40:10.860 Engine:Setting original file name "volmgrx.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..memanager.resources_31bf3856ad364e35_10.0.26100.1_en-us_a18734abf077f9b4_volmgrx.sys.mui_b0c205d7", hr=0x0

2025-11-22T01:40:10.899 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-22T01:40:10.990 Engine:Setting original file name "libcrypto" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\libcrypto-3-x64.dll", hr=0x0

2025-11-22T01:40:11.016 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-string-l1-1-0.dll", hr=0x0

2025-11-22T01:40:11.048 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hi-in_83227505fd46a5bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:11.094 Engine:Setting original file name "CertCa" for "c:\windows\winsxs\amd64_microsoft-windows-c..ertca-dll.resources_31bf3856ad364e35_10.0.26100.1_nb-no_25e015431023bb9b\certca.dll.mui", hr=0x0

2025-11-22T01:40:11.210 Engine:Setting original file name "PCW_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_ddc581f4a364804b\diagpackage.dll.mui", hr=0x0

2025-11-22T01:40:11.310 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..subsystem.resources_31bf3856ad364e35_10.0.26100.1_nb-no_ab8620bc0ed41a36\scardsvr.dll.mui", hr=0x0

2025-11-22T01:40:11.330 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_6.0.3624.51421.dll", hr=0x0

2025-11-22T01:40:11.410 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-22T01:40:11.450 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_06d4a9c0547686dc\msprivs.dll.mui", hr=0x0

2025-11-22T01:40:11.613 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mapi_31bf3856ad364e35_10.0.26100.7019_none_473a9ee5c9a5ebee\mapistub.dll", hr=0x0

2025-11-22T01:40:11.739 Engine:Setting original file name "mofcomp.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_nb-no_8c87dcbbb8114be3_mofcomp.exe.mui_35badf56", hr=0x0

2025-11-22T01:40:11.745 Engine:Setting original file name "MspsProv.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..oning-wmi.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd6de3cbb42de1cb\mspsprov.dll.mui", hr=0x0

2025-11-22T01:40:11.795 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x0

2025-11-22T01:40:11.898 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.26100.7019_none_4a484d6501b73a17\wwanapi.dll", hr=0x0

2025-11-22T01:40:11.972 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ne-np_591939d32e7d4223_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:12.050 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.xboxidentityprovider_12.130.16001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-22T01:40:12.221 Engine:Setting original file name "Operativsystemet Microsoft� Windows�" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e2a170892be5347a116ae0806fb5309d\pcalua.exe.mui", hr=0x0

2025-11-22T01:40:12.306 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x0

2025-11-22T01:40:12.323 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x0

2025-11-22T01:40:12.617 Engine:Setting original file name "imageres.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-imageres_31bf3856ad364e35_10.0.26100.1_none_d9b14b936072a0bc\imageres.dll.mun", hr=0x0

2025-11-22T01:40:12.837 Engine:Setting original file name "vcruntime140.dll" for "c:\config.msi\1c742.rbf", hr=0x0

2025-11-22T01:40:12.885 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-22T01:40:12.927 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_kk-kz_71b9c9e0d19e9ee0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:13.135 Engine:Setting original file name "Apps_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\apps\nb-no\d2a92c7cfed83dc547a21508b5b0ea0f\diagpackage.dll.mui", hr=0x0

2025-11-22T01:40:13.155 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32.dll", hr=0x0

2025-11-22T01:40:13.210 Engine:Setting original file name "CertPKICmdlet" for "c:\windows\system32\en-us\certpkicmdlet.dll.mui", hr=0x0

2025-11-22T01:40:13.285 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ed4232cecc06e9efb72d2a7c142b63b4\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x0

2025-11-22T01:40:13.296 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.424.1611.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-22T01:40:13.378 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_0cb2119581e88ce0\diagpackage.dll.mui", hr=0x0

2025-11-22T01:40:13.548 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\system32\bcp47langs.dll", hr=0x0

2025-11-22T01:40:13.631 Engine:Setting original file name "gpapi.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-g..licy-base.resources_31bf3856ad364e35_10.0.26100.1_en-us_be2843fbd972ca37_gpapi.dll.mui_ef0a9748", hr=0x0

2025-11-22T01:40:13.634 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-math-l1-1-0.dll", hr=0x0

2025-11-22T01:40:13.695 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x0

2025-11-22T01:40:13.705 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\winsxs\amd64_microsoft-windows-aerolite.resources_31bf3856ad364e35_10.0.26100.1_en-us_bc993ceae8fc48bf\aerolite.msstyles.mui", hr=0x0

2025-11-22T01:40:14.009 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\en-us\utilman.exe.mui", hr=0x0

2025-11-22T01:40:14.161 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x0

2025-11-22T01:40:14.238 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-22T01:40:14.247 Engine:Setting original file name "sqlite3" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\sqlite3.dll", hr=0x0

2025-11-22T01:40:14.316 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x0

2025-11-22T01:40:14.368 Engine:Setting original file name "w32time.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-time-tool.resources_31bf3856ad364e35_10.0.26100.1_en-us_7b897a2738f484fc\w32tm.exe.mui", hr=0x0

2025-11-22T01:40:14.372 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd473133072db5bb\diagpackage.dll.mui", hr=0x0

2025-11-22T01:40:14.398 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_80a1d04cb31f8eca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:14.404 Engine:Setting original file name "ERC" for "c:\windows\system32\nb-no\wercplsupport.dll.mui", hr=0x0

2025-11-22T01:40:14.439 Engine:Setting original file name "vdsutil.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-v..skservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_59d12af3dce743c1_vdsutil.dll.mui_0caf9b0e", hr=0x0

2025-11-22T01:40:14.527 Engine:Setting original file name "AppLockerCSP.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appidcore.resources_31bf3856ad364e35_10.0.26100.1_en-us_564c6ad9b132641f_applockercsp.dll.mui_d2a0df70", hr=0x0

2025-11-22T01:40:14.592 Engine:Setting original file name "dnsrslvr.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570_dnsrslvr.dll.mui_1e1a1ed1", hr=0x0

2025-11-22T01:40:14.663 Engine:Setting original file name "PSAPI" for "c:\windows\winsxs\backup\wow64_microsoft-windows-basedependencies_31bf3856ad364e35_10.0.26100.1_none_09ea4476c5bcc4c0_psapi.dll_e8b5b4d1", hr=0x0

2025-11-22T01:40:14.692 Engine:Setting original file name "AcPlugin.dll" for "c:\program files\windowsapps\microsoft.applicationcompatibilityenhancements_1.2511.9.0_x64__8wekyb3d8bbwe\amd64\acplugin_test.dll", hr=0x0

2025-11-22T01:40:14.704 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\426c2b1101abec586136a4bbd67a716e\narrator.exe.mui", hr=0x0

2025-11-22T01:40:14.720 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..tiator_ui.resources_31bf3856ad364e35_10.0.26100.1_en-us_7967a83a130d426e\iscsicpl.dll.mui", hr=0x0

2025-11-22T01:40:14.820 Engine:Setting original file name "WindowsMediaPlayerPlayDVD_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_587c1f8aa98a4a71\diagpackage.dll.mui", hr=0x0

2025-11-22T01:40:15.004 Engine:Setting original file name "scecli" for "c:\windows\system32\nb-no\scecli.dll.mui", hr=0x0

2025-11-22T01:40:15.025 Engine:Setting original file name "scesrv" for "c:\windows\winsxs\amd64_microsoft-windows-s..ionengine.resources_31bf3856ad364e35_10.0.26100.1_en-us_e63bd45b831a32e3\scesrv.dll.mui", hr=0x0

2025-11-22T01:40:15.061 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_bg-bg_af9bba51d24fbf0e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:15.127 Engine:Setting original file name "nvhda.sys" for "c:\windows\system32\driverstore\filerepository\nvhda.inf_amd64_c32d8360d192a82e\nvhda64v.sys", hr=0x0

2025-11-22T01:40:15.142 Engine:Setting original file name "wmiutils.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiutils.dll.mui_42583eaf", hr=0x0

2025-11-22T01:40:15.160 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_te-in_e10bae4a47776b9f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:15.191 Engine:Setting original file name "BdncProxy.dll" for "c:\program files\bitdefender agent\27.1.1.23\crash_handler\bdnc.dll", hr=0x0

2025-11-22T01:40:15.274 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.26100.1_nb-no_e175a2f7bf27ee8d_ws2ifsl.sys.mui_b672c7b4", hr=0x0

2025-11-22T01:40:15.343 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_eu-es_e55e702bbb854a24_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:15.383 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-msinfo32-exe.resources_31bf3856ad364e35_10.0.26100.1_en-us_53ae64398a08feba\msinfo32.exe.mui", hr=0x0

2025-11-22T01:40:15.439 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-22T01:40:15.682 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x86__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-22T01:40:15.709 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x0

2025-11-22T01:40:15.815 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x0

2025-11-22T01:40:15.825 Engine:Setting original file name "NxCooking.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\v2.7.6\physxcooking.dll", hr=0x0

2025-11-22T01:40:15.858 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-22T01:40:15.999 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x0

2025-11-22T01:40:16.083 Engine:Setting original file name "filterLib.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\4fffc8576907b0b5da815790887fb244\fltlib.dll.mui", hr=0x0

2025-11-22T01:40:16.115 Engine:Setting original file name "srpuxgp.dll" for "c:\windows\systemresources\srpuxnativesnapin.dll.mun", hr=0x0

2025-11-22T01:40:16.118 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-22T01:40:16.326 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_nl-nl_0d26e65c98dbf6f7_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:16.336 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sl-si_8549ba61ed8af84b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:16.341 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x0

2025-11-22T01:40:16.531 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_pl-pl_9d43c82914fc6152_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:16.554 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.web.winmd", hr=0x0

2025-11-22T01:40:16.626 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-22T01:40:16.752 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ca-es_584cefb2c144b7d8_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:16.761 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\winsxs\amd64_microsoft-windows-qedwipes_31bf3856ad364e35_10.0.26100.1_none_5473011012d79dc1\qedwipes.dll.mun", hr=0x0

2025-11-22T01:40:16.943 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_et-ee_4da61d721400c924_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:16.990 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_fb2fbffb5205c552_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:17.224 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..xe-common.resources_31bf3856ad364e35_10.0.26100.1_en-us_58b62bf54b9ae38a\msinfo32.exe.mui", hr=0x0

2025-11-22T01:40:17.359 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.70.1338.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-22T01:40:17.364 Engine:Setting original file name "netcfgx.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-tcpip.resources_31bf3856ad364e35_10.0.26100.1_en-us_c93621b935b09922_tcpipcfg.dll.mui_a5479fc1", hr=0x0

2025-11-22T01:40:17.415 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_f4c1513bcd79893e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:17.462 Engine:Setting original file name "nvxdsync.exe" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\session\nvxdsyncplugin.dll", hr=0x0

2025-11-22T01:40:17.625 Engine:Setting original file name "ReShade" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\reshadefxc64.exe", hr=0x0

2025-11-22T01:40:17.672 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-22T01:40:17.722 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_0fbfb1c9f2926e3e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:17.754 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\power\nb-no\2803551e72f3605cc0b181750700647e\diagpackage.dll.mui", hr=0x0

2025-11-22T01:40:17.817 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_th-th_25ee4fb15dc2e739_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:17.823 Engine:Setting original file name "Umpo.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-u..erservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_a887c532823d0a08_umpo.dll.mui_cac12e54", hr=0x0

2025-11-22T01:40:17.827 Engine:Setting original file name "bootres" for "c:\windows\boot\resources\nb-no\bootres.dll.mui", hr=0x0

2025-11-22T01:40:17.854 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\b74f41bc269d13282681d018820fb031\ddores.dll.mui", hr=0x0

2025-11-22T01:40:17.884 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x0

2025-11-22T01:40:17.893 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\mscordaccore_amd64_amd64_8.0.2125.47513.dll", hr=0x0

2025-11-22T01:40:17.920 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-namedpipe-l1-1-0.dll", hr=0x0

2025-11-22T01:40:18.028 Engine:Setting original file name "dxmasf.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_10.0.26100.7019_none_b1abcb083360b859\msdxm.ocx", hr=0x0

2025-11-22T01:40:18.170 Engine:Setting original file name "Bubbles" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ee15dd2b573766654f76694ac2f468d4\bubbles.scr.mui", hr=0x0

2025-11-22T01:40:18.215 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_tr-tr_2c24c8b8ddbbff8a_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:18.241 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_es-mx_9dca765f230af946_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-22T01:40:18.267 Engine:Setting original file name "CUDART64_65_19.DLL" for "c:\program files (x86)\nvidia corporation\physx\common\cudart64_65.dll", hr=0x0

2025-11-22T01:40:18.286 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-errorhandling-l1-1-0.dll", hr=0x0

2025-11-22T01:40:18.426 Engine:Setting original file name "wcp.dll" for "c:\windows\system32\ssshim.dll", hr=0x0

2025-11-22T01:40:18.531 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.exe", hr=0x0

2025-11-22T01:40:18.581 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-time-l1-1-0.dll", hr=0x0

2025-11-22T01:40:18.581 OriginalFileName Maintenance::11269 files in Moac, 0 skipped (cached), 433 filename set

2025-11-22T01:40:18.581 [AutoPurge] Routine task for Cache Maintenance has ended.

2025-11-22T01:44:29.413 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T01:46:34.252 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #182834, FileId: 0x2800000001ccb8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T01:52:08.066 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #182942, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T01:52:08.070 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #182943, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T01:52:18.078 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #182950, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T01:52:18.082 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #182951, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T01:58:11.862 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #183176, FileId: 0xe2000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T01:59:34.403 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T02:01:34.545 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #183235, FileId: 0x21e000000007806, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T02:07:09.932 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

2025-11-22T02:07:09.943 [DLP] DlpEngineConfigStorage::OnConfigChange DlpDwordSettingsMap:

2025-11-22T02:07:09.943 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-22T02:07:09.943 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-22T02:07:09.943 [RTP] Duplicating the current plugin configuration object...

2025-11-22T02:07:09.943 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-22T02:07:09.943 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-22T02:07:09.943 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-22T02:07:09.943 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-22T02:07:09.943 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-22T02:07:09.943 [RTP] No config change detected. Not updating plugin configuration.

2025-11-22T02:07:09.944 [RTP] No config changes found. No configuration switch.

2025-11-22T02:07:09.944 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-22T02:07:09.944 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-22T02:07:09.944 [RTP] [RtpConfig] Config change detected, type: 16

2025-11-22T02:07:09.944 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-22T02:07:09.944 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-22T02:07:09.944 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-22T02:07:09.944 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-22T02:07:09.944 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-22T02:07:09.944 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:07:09.945 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-22T02:07:09.945 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-22T02:07:09.945 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-22T02:07:09.945 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-22T02:07:09.945 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-22T02:07:09.945 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-22T02:07:09.946 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-22T02:07:09.946 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-22T02:07:09.946 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-22T02:07:09.946 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:07:09.947 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:07:09.949 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:07:09.951 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:07:09.953 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 83633502(ms) from now at 02:21 (01:21 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-22T02:07:12.485 [RTP] Duplicating the current plugin configuration object...

2025-11-22T02:07:12.485 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-22T02:07:12.485 [RTP] Updating plugin configuration due to recent config changes (0x41e) ...

2025-11-22T02:07:12.485 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-22T02:07:12.485 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x218

2025-11-22T02:14:39.403 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T02:16:35.630 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #183897, FileId: 0xc1000000030671, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T02:17:29.231 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 13911, Count: 2144, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\Brooklyn Nine-Nine (2013) Season 1-8 S01-S08 (1080p AMZN WEB-DL x265 HEVC 10bit EAC3 5.1 Silence) REPACK\Season 2\Brooklyn Nine-Nine (2013) - S02E16 - The Wednesday Incident (1080p AMZN WEB-DL x265 Silence).mkv, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 992, Count: 89, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\01ab15d2-6cd5-42b0-9535-967eb3875b67.tmp, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 709, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\96bf74e4-a6d0-45a3-ac95-ab7597c65218.tmp, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: RuntimeBroker.exe, Pid: 27292, TotalTime: 559, Count: 23, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-22T02:17:29.231 ProcessImageName: RuntimeBroker.exe, Pid: 25704, TotalTime: 483, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 26%

2025-11-22T02:17:29.231 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 255, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: taskhostw.exe, Pid: 23244, TotalTime: 210, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\config.json, EstimatedImpact: 9%

2025-11-22T02:17:29.231 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 120, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\metadata\library\1d\1d854ce617f51aa73da05b267e88901d\poster.jpg, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0D1686C3FBB7F7352C5A7B6BA00CB0A6, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\dashboard\index.html, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: taskhostw.exe, Pid: 8492, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-22T02:17:29.231 ProcessImageName: taskhostw.exe, Pid: 16452, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 8%

2025-11-22T02:17:29.231 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: updater.exe, Pid: 21708, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-22T02:17:29.231 ProcessImageName: Spotify.exe, Pid: 17104, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-22T02:29:44.403 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T02:31:36.737 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #183988, FileId: 0x25000000054886, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T02:44:49.398 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T02:46:37.642 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #184268, FileId: 0x14c0000000544eb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T02:52:06.738 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #184344, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T02:52:16.719 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #184351, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T02:52:16.723 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #184352, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T02:57:45.229 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\CC4D062F-F3A4-453D-A6C5-A81F2D45C8CA4220.1dc5b5bc6152a77

2025-11-22T02:57:45.259 Verifying engine and signature files (source: 0) ...

2025-11-22T02:57:45.259 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79F10480-F9E1-482C-A8EF-EE11B9C367B8}\mpengine.dll] due to PPL.

2025-11-22T02:57:45.259 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79F10480-F9E1-482C-A8EF-EE11B9C367B8}\mpasbase.vdm] (file in cache)

2025-11-22T02:57:45.259 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79F10480-F9E1-482C-A8EF-EE11B9C367B8}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-22T02:57:45.268 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79F10480-F9E1-482C-A8EF-EE11B9C367B8}\mpasdlta.vdm]

2025-11-22T02:57:45.268 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79F10480-F9E1-482C-A8EF-EE11B9C367B8}\mpavbase.vdm] (file in cache)

2025-11-22T02:57:45.268 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79F10480-F9E1-482C-A8EF-EE11B9C367B8}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-22T02:57:45.276 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79F10480-F9E1-482C-A8EF-EE11B9C367B8}\mpavdlta.vdm]

2025-11-22T02:57:45.355 [Engine] IsHybridMode: 0

2025-11-22T02:57:45.355 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-22T02:57:45.366 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-AA47A9CE3B3755306C14E2E1C7EFAA60802AD97D.bin): 0x00000002

2025-11-22T02:57:45.367 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-AA47A9CE3B3755306C14E2E1C7EFAA60802AD97D.bin)

2025-11-22T02:57:45.367 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-22T02:57:45.367 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-22T02:57:45.367 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-22T02:57:45.367 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-22T02:57:50.844 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-22T02:57:50.845 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-22T02:57:50.851 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7F1CA660, lRefCount: 5, hr=0

2025-11-22T02:57:50.851 [Engine] New active engine 00007FFE7A9CA660 replacing engine 00007FFE7F1CA660. Number of active engines: 2

2025-11-22T02:57:50.856 EngineInit:Global ASOC is enabled

2025-11-22T02:57:50.856 EngineInit:ASOO is enabled for developer volumes

2025-11-22T02:57:50.888 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-22T02:57:50.888 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.888 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-22T02:57:50.889 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-22T02:57:50.889 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-22T02:57:50.889 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.889 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.890 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.890 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-22T02:57:50.890 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.891 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.891 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-22T02:57:50.891 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.892 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.892 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.892 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.893 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.893 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.893 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T02:57:50.893 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7a5e098e1e89efe54b2df4caab51f54aaf9aebdd

Dynamic Signature Compilation Timestamp:11-21-2025 01:09:47

Persistence Type:Duration

Time remaining:864000000

2025-11-22T02:57:50.894 Dynamic signature dropped

2025-11-22T02:57:50.895 MpWriteUupSignatureVersion 1.441.399.0, hr = 0

2025-11-22T02:57:50.897 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-22T02:57:50.908 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-22T02:57:50.909 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-22T02:57:50.909 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-22T02:57:50.909 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-22T02:57:50.909 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-22T02:57:50.912 Bm signature throttled:0x000263b33f08cde7

2025-11-22T02:57:50.923 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-22T02:57:50.923 [Plugin] Initializing RTP plugin state...

2025-11-22T02:57:50.923 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-22T02:57:50.923 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 22 - 2025 01:17:29

Last Perf: 11 - 22 - 2025 01:17:29

First RTP Scan: 11 - 22 - 2025 01:17:30

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:976

  Misses:4001

BM Queue:0,29,0

  Proc:0,28,0

  File:0,9,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:185122

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1094661446

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:17

  TotalStreamCon:27309

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:878965

   TotalHits:1445719

   InstanceCacheInserts:64601

   InstanceCacheUpdates:0

   InstanceCacheDeletes:48953

   InstanceCacheHits:3010

   InstanceCacheMisses:264959

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (228/261)

   Success: 261, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-22T02:57:50.923 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79F10480-F9E1-482C-A8EF-EE11B9C367B8}

2025-11-22T02:57:50.923 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{459570F3-4ADA-46DC-B885-78598EDC5934}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{459570F3-4ADA-46DC-B885-78598EDC5934}\mpasbase.vdm in use, hr=0x80070020

2025-11-22T02:57:50.923 [SCC][CID=465498765_26264] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-22T02:57:50.924 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-22T02:57:50.924 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-22T02:57:50.924 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-22T02:57:50.924 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-22T02:57:50.925 MdCoreSvc is supported in this platform and OS

2025-11-22T02:57:50.925 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-22-2025 02:57:50

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-22-2025 02:57:50

2025-11-22T02:57:50.928 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-22T02:57:50.928 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-22T02:57:50.928 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-22T02:57:50.928 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-22-2025 02:57:50

END TDT(U) telemetry



2025-11-22T02:57:50.930 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:57:50.931 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-22T02:57:50.931 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-22T02:57:50.931 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-22T02:57:50.931 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-22T02:57:50.931 MdCoreSvc is supported in this platform and OS

Signature updated on 11-22-2025 02:57:50

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.399.0

AV Signature Version: 1.441.399.0

************************************************************

2025-11-22T02:57:50.932 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-22T02:57:50.933 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\CC4D062F-F3A4-453D-A6C5-A81F2D45C8CA4220.1dc5b5bc6152a77

2025-11-22T02:57:50.940 Process scan (postsignatureupdatescan) started.

2025-11-22T02:57:50.977 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-22T02:57:50.978 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-22T02:57:51.113 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-22T02:57:51.113 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-22T02:57:51.113 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-22T02:57:51.113 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-22T02:57:51.113 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-22T02:57:51.115 [Engine] Engine 00007FFE7F1CA660 no longer in use. Number of active engines: 1

2025-11-22T02:57:51.116 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-22T02:57:51.116 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-22T02:57:51.286 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 14122, Count: 2167, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\Brooklyn Nine-Nine (2013) Season 1-8 S01-S08 (1080p AMZN WEB-DL x265 HEVC 10bit EAC3 5.1 Silence) REPACK\Season 2\Brooklyn Nine-Nine (2013) - S02E16 - The Wednesday Incident (1080p AMZN WEB-DL x265 Silence).mkv, EstimatedImpact: 0%

2025-11-22T02:57:51.286 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 1355, Count: 118, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\01ab15d2-6cd5-42b0-9535-967eb3875b67.tmp, EstimatedImpact: 0%

2025-11-22T02:57:51.286 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 1011, Count: 71, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\96bf74e4-a6d0-45a3-ac95-ab7597c65218.tmp, EstimatedImpact: 0%

2025-11-22T02:57:51.286 ProcessImageName: RuntimeBroker.exe, Pid: 27292, TotalTime: 559, Count: 23, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-22T02:57:51.286 ProcessImageName: RuntimeBroker.exe, Pid: 25704, TotalTime: 483, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 26%

2025-11-22T02:57:51.286 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 405, Count: 90, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-22T02:57:51.286 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 232, Count: 5, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-22T02:57:51.286 ProcessImageName: taskhostw.exe, Pid: 23244, TotalTime: 210, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\config.json, EstimatedImpact: 9%

2025-11-22T02:57:51.286 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 150, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-22T02:57:51.286 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 120, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\metadata\library\1d\1d854ce617f51aa73da05b267e88901d\poster.jpg, EstimatedImpact: 0%

2025-11-22T02:57:51.286 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-22T02:57:51.286 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0D1686C3FBB7F7352C5A7B6BA00CB0A6, EstimatedImpact: 0%

2025-11-22T02:57:51.286 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\dashboard\index.html, EstimatedImpact: 0%

2025-11-22T02:57:51.286 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-22T02:57:51.286 ProcessImageName: taskhostw.exe, Pid: 25468, TotalTime: 45, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 3%

2025-11-22T02:57:51.306 [Engine] RSIG_UNLOADENGINE, 00007FFE7F1CA660, err=0x0

2025-11-22T02:57:51.326 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{459570F3-4ADA-46DC-B885-78598EDC5934} removed

2025-11-22T02:57:51.411 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-22T02:57:51.419 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-22T02:57:51.419 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-22T02:57:51.419 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-22T02:57:51.419 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-22T02:57:51.419 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-22T02:57:51.419 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-22T02:57:51.422 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-22T02:57:51.423 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-22T02:57:51.423 [RTP] Duplicating the current plugin configuration object...

2025-11-22T02:57:51.423 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-22T02:57:51.423 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-22T02:57:51.423 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-22T02:57:51.423 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-22T02:57:51.423 [RTP] No config change detected. Not updating plugin configuration.

2025-11-22T02:57:51.423 [RTP] No config changes found. No configuration switch.

2025-11-22T02:57:51.423 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-22T02:57:51.423 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-22T02:57:51.423 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-22T02:57:51.423 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-22T02:57:51.423 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-22T02:57:51.423 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-22T02:57:51.423 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-22T02:57:51.423 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-22T02:57:51.423 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-22T02:57:51.423 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-22T02:57:51.423 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-22T02:57:51.423 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-22T02:57:51.423 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-22T02:57:51.423 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-22T02:57:51.423 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-22T02:57:51.423 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-22T02:57:51.424 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:57:51.425 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:57:51.427 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:57:51.429 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:57:51.431 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:57:51.432 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 3572243(ms) from now at 04:57 (03:57 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-22T02:57:52.943 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-22T02:57:52.947 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-22T02:57:52.947 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-22T02:57:53.973 [RTP] Duplicating the current plugin configuration object...

2025-11-22T02:57:53.973 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-22T02:57:53.973 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-22T02:57:53.973 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-22T02:57:53.973 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157ED7C270CE, sigsha=5eded354160aa060b3f2a16db0725661264de9cd, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EC4695FB0, sigsha=52047109963df3b68264cf6c70eb58a332f0e384, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EE3E9E96F, sigsha=bb73eddcceeb861170c0e1ea3e27e4478d601280, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157E24ECD9EE, sigsha=b8666aeb5330bc151c524a8796313de114549911, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF9518016, sigsha=8fa60ffaf004b3696b5767c35f78f1425d04eb09, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0xa85b3f00

2025-11-22T02:57:56.487 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-22T02:57:56.487 [Cloud] Start of cloud request. Passive mode: 0

2025-11-22T02:57:56.487 [Cloud] Queued cloud request.

2025-11-22T02:57:56.487 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-22T02:57:56.487 [Cloud] Dequeued cloud request.

2025-11-22T02:57:56.487 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ef19a1e7d03ed68772afd197dc302c12174e05da

Dynamic Signature Compilation Timestamp:11-22-2025 02:57:56

Persistence Type:Duration

Time remaining:864000000

2025-11-22T02:57:56.791 Dynamic signature received

2025-11-22T02:57:56.792 [Cloud] End of cloud request.

2025-11-22T02:57:56.793 RTSD:RTSD recieved, rescanning impacted resources

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-22T02:57:57.298 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:57:58.131 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-22T02:57:58.131 [Cloud] Start of cloud request. Passive mode: 0

2025-11-22T02:57:58.131 [Cloud] Queued cloud request.

2025-11-22T02:57:58.131 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-22T02:57:58.131 [Cloud] Dequeued cloud request.

2025-11-22T02:57:58.131 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-22T02:57:58.448 [Cloud] End of cloud request.

2025-11-22T02:57:58.969 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T02:58:07.499 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-22T02:58:07.499 Process scan (postsignatureupdatescan) completed.

2025-11-22T02:59:54.395 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T03:01:38.501 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #186193, FileId: 0x26000000012e21, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T03:02:50.880 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-22T03:14:59.389 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T03:16:39.578 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #186944, FileId: 0x50000000034718, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T03:30:04.377 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T03:31:40.770 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #187548, FileId: 0x22000000054637, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T03:45:09.370 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T03:46:41.378 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #187907, FileId: 0x280000000232cb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T03:52:06.956 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #188023, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T03:52:06.959 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #188024, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T03:52:16.973 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #188031, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T03:52:16.977 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #188032, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T04:00:14.368 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T04:01:42.686 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #188159, FileId: 0x1ab00000000ceef, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T04:15:19.362 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T04:16:43.613 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #188512, FileId: 0x380000000547ea, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T04:30:24.366 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T04:31:44.904 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #188686, FileId: 0x460000000547ea, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T04:34:16.537 Bm signature throttled:0x0000fab3228bcd4d

2025-11-22T04:45:29.348 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T04:46:45.994 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #188881, FileId: 0x8700000003ae1e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T04:52:06.056 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #188939, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T04:52:06.060 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #188940, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T04:52:16.073 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #188947, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T04:52:16.077 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #188948, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T04:52:16.085 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #188949, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T04:52:16.090 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #188950, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T04:57:50.823 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1645, Count: 84, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-22T04:57:50.823 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 1367, Count: 163, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\Brooklyn Nine-Nine (2013) Season 1-8 S01-S08 (1080p AMZN WEB-DL x265 HEVC 10bit EAC3 5.1 Silence) REPACK\Season 7\Brooklyn Nine-Nine (2013) - S07E04 - The Jimmy Jab Games II (1080p AMZN WEB-DL x265 Silence).mkv, EstimatedImpact: 0%

2025-11-22T04:57:50.823 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 1149, Count: 85, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9ba0a96c-ab24-4414-ab1e-6ca99c909c59.tmp, EstimatedImpact: 0%

2025-11-22T04:57:50.823 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 846, Count: 53, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\eca2aab1-825c-4009-9e4b-e6acb9685c7d.tmp, EstimatedImpact: 0%

2025-11-22T04:57:50.823 ProcessImageName: RuntimeBroker.exe, Pid: 25704, TotalTime: 618, Count: 21, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-22T04:57:50.823 ProcessImageName: DeviceCensus.exe, Pid: 26292, TotalTime: 326, Count: 13, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-22T04:57:50.823 ProcessImageName: taskhostw.exe, Pid: 23720, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-22T04:57:50.823 ProcessImageName: taskhostw.exe, Pid: 25424, TotalTime: 165, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 73%

2025-11-22T04:57:50.823 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 76, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-22T04:57:50.823 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-22T04:57:50.823 ProcessImageName: taskhostw.exe, Pid: 14732, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-22T04:57:50.823 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-22T04:57:50.823 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\index.php->(SCRIPT0000), EstimatedImpact: 0%

2025-11-22T04:57:50.823 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 30, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\221e69c75d2ebd901f43b49f837382c045686b79ba68ba6ace4a7e0a20cd9177, EstimatedImpact: 0%

2025-11-22T04:57:50.823 ProcessImageName: updater.exe, Pid: 8992, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9d615a41-4fdf-4edb-93b2-e05360d17bd6.tmp, EstimatedImpact: 0%

2025-11-22T04:57:50.823 ProcessImageName: StoreDesktopExtension.exe, Pid: 23428, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-22T04:57:50.823 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-22T04:57:50.823 ProcessImageName: crashhelper.exe, Pid: 19520, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log, EstimatedImpact: 2%

2025-11-22T04:57:50.823 ProcessImageName: updater.exe, Pid: 8080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\c18523e2-3cbe-48cc-8232-f433087744a0.tmp, EstimatedImpact: 0%

2025-11-22T05:00:34.353 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T05:01:46.768 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #189055, FileId: 0x6f00000003e29a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T05:15:39.339 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T05:16:47.573 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #189423, FileId: 0x7900000003e2a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T05:30:44.340 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T05:31:48.361 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #189535, FileId: 0x1c000000054904, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T05:45:49.336 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T05:46:49.263 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #189754, FileId: 0x111000000015212, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T05:52:06.544 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #189825, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T05:52:06.554 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #189826, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T05:52:16.545 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #189833, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T05:52:16.550 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #189834, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T06:00:54.329 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T06:01:50.212 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #190145, FileId: 0x640000000144c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T06:15:59.324 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T06:16:51.291 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #190415, FileId: 0x12f000000013a82, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T06:31:04.322 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T06:31:52.264 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #190592, FileId: 0x890000000195e9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T06:34:18.642 Bm signature throttled:0x0000fab3228bcd4d

2025-11-22T06:46:09.310 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T06:46:52.957 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #190790, FileId: 0x33000000054915, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T06:52:06.812 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #190861, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T06:52:06.819 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #190862, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T06:52:16.819 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #190867, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T06:52:16.823 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #190868, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T06:57:50.787 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 2175, Count: 171, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9ba0a96c-ab24-4414-ab1e-6ca99c909c59.tmp, EstimatedImpact: 0%

2025-11-22T06:57:50.787 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1645, Count: 84, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-22T06:57:50.787 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 1599, Count: 106, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\eca2aab1-825c-4009-9e4b-e6acb9685c7d.tmp, EstimatedImpact: 0%

2025-11-22T06:57:50.787 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 1472, Count: 173, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\Brooklyn Nine-Nine (2013) Season 1-8 S01-S08 (1080p AMZN WEB-DL x265 HEVC 10bit EAC3 5.1 Silence) REPACK\Season 7\Brooklyn Nine-Nine (2013) - S07E04 - The Jimmy Jab Games II (1080p AMZN WEB-DL x265 Silence).mkv, EstimatedImpact: 0%

2025-11-22T06:57:50.787 ProcessImageName: RuntimeBroker.exe, Pid: 25704, TotalTime: 618, Count: 21, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-22T06:57:50.787 ProcessImageName: DeviceCensus.exe, Pid: 26292, TotalTime: 326, Count: 13, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-22T06:57:50.787 ProcessImageName: taskhostw.exe, Pid: 23720, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-22T06:57:50.787 ProcessImageName: taskhostw.exe, Pid: 25424, TotalTime: 165, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 73%

2025-11-22T06:57:50.787 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 152, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-22T06:57:50.787 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 135, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-22T06:57:50.787 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\index.php->(SCRIPT0000), EstimatedImpact: 0%

2025-11-22T06:57:50.787 ProcessImageName: taskhostw.exe, Pid: 14732, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-22T06:57:50.787 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 45, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-22T06:57:50.788 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-22T06:57:50.788 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 30, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\221e69c75d2ebd901f43b49f837382c045686b79ba68ba6ace4a7e0a20cd9177, EstimatedImpact: 0%

2025-11-22T06:57:50.789 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-22T06:57:50.789 ProcessImageName: updater.exe, Pid: 8992, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9d615a41-4fdf-4edb-93b2-e05360d17bd6.tmp, EstimatedImpact: 0%

2025-11-22T06:57:50.789 ProcessImageName: StoreDesktopExtension.exe, Pid: 23428, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-22T06:57:50.789 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-22T06:57:50.789 ProcessImageName: crashhelper.exe, Pid: 19520, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log, EstimatedImpact: 2%

2025-11-22T06:57:50.789 ProcessImageName: updater.exe, Pid: 8080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\c18523e2-3cbe-48cc-8232-f433087744a0.tmp, EstimatedImpact: 0%

2025-11-22T07:01:14.314 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T07:01:54.285 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #190965, FileId: 0x5e00000003e6e8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T07:16:19.312 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T07:16:55.477 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #191230, FileId: 0x2e000000054911, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T07:31:24.301 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T07:31:56.154 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #191385, FileId: 0x7200000003e6e9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T07:46:29.296 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T07:46:57.089 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #191551, FileId: 0x5100000005490d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T07:52:06.367 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #191624, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T07:52:06.370 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #191625, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T07:52:16.370 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #191632, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T07:52:16.374 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #191633, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T08:01:16.692 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #191895, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T08:01:34.286 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T08:01:58.170 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #191906, FileId: 0x14d000000004346, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T08:16:39.297 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T08:16:59.262 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #192476, FileId: 0x39000000054905, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T08:31:44.286 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T08:32:00.338 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #192635, FileId: 0x23a000000007df2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T08:34:20.443 Bm signature throttled:0x0000fab3228bcd4d

2025-11-22T08:46:49.273 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T08:47:01.210 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #192863, FileId: 0x5b00000005490d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T08:52:06.217 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #192920, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T08:52:06.223 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #192921, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T08:52:16.212 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #192926, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T08:52:16.217 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #192927, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T08:57:50.754 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 3757, Count: 257, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9ba0a96c-ab24-4414-ab1e-6ca99c909c59.tmp, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 2556, Count: 160, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\eca2aab1-825c-4009-9e4b-e6acb9685c7d.tmp, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1645, Count: 84, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-22T08:57:50.754 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 1607, Count: 183, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\Brooklyn Nine-Nine (2013) Season 1-8 S01-S08 (1080p AMZN WEB-DL x265 HEVC 10bit EAC3 5.1 Silence) REPACK\Season 7\Brooklyn Nine-Nine (2013) - S07E04 - The Jimmy Jab Games II (1080p AMZN WEB-DL x265 Silence).mkv, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: RuntimeBroker.exe, Pid: 25704, TotalTime: 618, Count: 21, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-22T08:57:50.754 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 336, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: DeviceCensus.exe, Pid: 26292, TotalTime: 326, Count: 13, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-22T08:57:50.754 ProcessImageName: taskhostw.exe, Pid: 23720, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-22T08:57:50.754 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 195, Count: 36, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: taskhostw.exe, Pid: 25424, TotalTime: 165, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 73%

2025-11-22T08:57:50.754 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 105, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\221e69c75d2ebd901f43b49f837382c045686b79ba68ba6ace4a7e0a20cd9177, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 75, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\index.php->(SCRIPT0000), EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: taskhostw.exe, Pid: 14732, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-22T08:57:50.754 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: taskhostw.exe, Pid: 26868, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-22T08:57:50.754 ProcessImageName: updater.exe, Pid: 8992, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9d615a41-4fdf-4edb-93b2-e05360d17bd6.tmp, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: StoreDesktopExtension.exe, Pid: 23428, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: updater.exe, Pid: 8080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\c18523e2-3cbe-48cc-8232-f433087744a0.tmp, EstimatedImpact: 0%

2025-11-22T08:57:50.754 ProcessImageName: crashhelper.exe, Pid: 19520, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log, EstimatedImpact: 2%

2025-11-22T09:01:54.275 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T09:02:02.362 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #193066, FileId: 0xc9000000008e69, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T09:09:54.045 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #193530, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T09:16:59.277 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T09:17:03.685 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #193599, FileId: 0x26000000054a13, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T09:32:04.264 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T09:32:04.860 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #193730, FileId: 0x4a000000054a30, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T09:46:53.759 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #193953, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T09:47:05.963 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #193957, FileId: 0x4b0000000546d4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T09:47:09.255 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T09:52:05.779 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #194030, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T09:52:05.790 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #194031, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T09:52:15.776 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #194038, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T09:52:15.777 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #194039, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T09:52:15.780 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #194040, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T09:52:15.781 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #194041, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T10:02:06.895 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #194292, FileId: 0x2a00000004c241, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T10:02:14.252 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T10:17:07.800 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #194576, FileId: 0xa80000000549c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T10:17:19.249 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T10:32:08.884 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #194736, FileId: 0xbb0000000549c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T10:32:24.242 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T10:34:22.577 Bm signature throttled:0x0000fab3228bcd4d

2025-11-22T10:47:09.444 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #194911, FileId: 0x3600000001c987, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T10:47:29.248 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T10:52:07.040 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #194935, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T10:52:07.045 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #194936, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T10:52:17.048 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #194941, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T10:57:50.724 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 5188, Count: 345, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9ba0a96c-ab24-4414-ab1e-6ca99c909c59.tmp, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 3388, Count: 214, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\eca2aab1-825c-4009-9e4b-e6acb9685c7d.tmp, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 1682, Count: 193, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\Brooklyn Nine-Nine (2013) Season 1-8 S01-S08 (1080p AMZN WEB-DL x265 HEVC 10bit EAC3 5.1 Silence) REPACK\Season 7\Brooklyn Nine-Nine (2013) - S07E04 - The Jimmy Jab Games II (1080p AMZN WEB-DL x265 Silence).mkv, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1645, Count: 84, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-22T10:57:50.724 ProcessImageName: RuntimeBroker.exe, Pid: 25704, TotalTime: 618, Count: 21, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-22T10:57:50.724 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 468, Count: 2, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\ffprobe.exe, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 442, Count: 34, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: DeviceCensus.exe, Pid: 26292, TotalTime: 326, Count: 13, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-22T10:57:50.724 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 270, Count: 44, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: taskhostw.exe, Pid: 23720, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-22T10:57:50.724 ProcessImageName: taskhostw.exe, Pid: 25424, TotalTime: 165, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 73%

2025-11-22T10:57:50.724 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 150, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\221e69c75d2ebd901f43b49f837382c045686b79ba68ba6ace4a7e0a20cd9177, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 105, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: RuntimeBroker.exe, Pid: 23892, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 13%

2025-11-22T10:57:50.724 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\index.php->(SCRIPT0000), EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: taskhostw.exe, Pid: 14732, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-22T10:57:50.724 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\28a2f016-ffa1-40a0-ae80-8ec409beb086.tmp, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: taskhostw.exe, Pid: 26868, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-22T10:57:50.724 ProcessImageName: updater.exe, Pid: 8992, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9d615a41-4fdf-4edb-93b2-e05360d17bd6.tmp, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: StoreDesktopExtension.exe, Pid: 23428, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: updater.exe, Pid: 12700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\c8d085e8-fa71-439e-85fd-247165b7ffb1.tmp, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: updater.exe, Pid: 8080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\c18523e2-3cbe-48cc-8232-f433087744a0.tmp, EstimatedImpact: 0%

2025-11-22T10:57:50.724 ProcessImageName: crashhelper.exe, Pid: 19520, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log, EstimatedImpact: 2%

2025-11-22T11:02:10.337 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #195112, FileId: 0x310000000545db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T11:02:34.238 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T11:17:11.273 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #195358, FileId: 0x9d000000054a3d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T11:17:39.234 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T11:32:12.359 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #195469, FileId: 0x430000000545db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T11:32:44.222 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T11:47:13.474 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #195644, FileId: 0x8300000003e8fd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T11:47:49.221 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T11:52:06.469 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #195679, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T11:52:06.472 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #195680, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T11:52:16.484 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #195687, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T11:52:16.491 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #195688, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T12:02:14.478 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #195872, FileId: 0x8500000000439c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T12:02:54.219 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T12:17:15.528 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #196451, FileId: 0x86000000054a45, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T12:17:59.214 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T12:32:16.571 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #196577, FileId: 0x9c00000000439c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T12:33:04.210 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T12:34:24.632 Bm signature throttled:0x0000fab3228bcd4d

2025-11-22T12:47:17.136 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #196809, FileId: 0x3a000000054a1b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T12:48:09.211 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T12:52:07.419 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #196848, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T12:52:07.423 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #196849, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T12:52:17.419 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #196854, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T12:52:17.425 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #196855, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T12:52:17.433 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #196856, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T12:52:17.439 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #196857, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T12:57:50.699 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 6465, Count: 431, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9ba0a96c-ab24-4414-ab1e-6ca99c909c59.tmp, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 4313, Count: 268, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\eca2aab1-825c-4009-9e4b-e6acb9685c7d.tmp, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 1803, Count: 203, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\Brooklyn Nine-Nine (2013) Season 1-8 S01-S08 (1080p AMZN WEB-DL x265 HEVC 10bit EAC3 5.1 Silence) REPACK\Season 7\Brooklyn Nine-Nine (2013) - S07E04 - The Jimmy Jab Games II (1080p AMZN WEB-DL x265 Silence).mkv, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1645, Count: 84, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-22T12:57:50.699 ProcessImageName: RuntimeBroker.exe, Pid: 25704, TotalTime: 618, Count: 21, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-22T12:57:50.699 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 548, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 468, Count: 2, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\ffprobe.exe, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 360, Count: 57, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: DeviceCensus.exe, Pid: 26292, TotalTime: 326, Count: 13, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-22T12:57:50.699 ProcessImageName: taskhostw.exe, Pid: 23720, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-22T12:57:50.699 ProcessImageName: taskhostw.exe, Pid: 25424, TotalTime: 165, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 73%

2025-11-22T12:57:50.699 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 150, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\221e69c75d2ebd901f43b49f837382c045686b79ba68ba6ace4a7e0a20cd9177, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 135, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: RuntimeBroker.exe, Pid: 23892, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 13%

2025-11-22T12:57:50.699 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\index.php->(SCRIPT0000), EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: taskhostw.exe, Pid: 14732, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-22T12:57:50.699 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\28a2f016-ffa1-40a0-ae80-8ec409beb086.tmp, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: taskhostw.exe, Pid: 26868, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-22T12:57:50.699 ProcessImageName: updater.exe, Pid: 8992, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9d615a41-4fdf-4edb-93b2-e05360d17bd6.tmp, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: StoreDesktopExtension.exe, Pid: 23428, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: updater.exe, Pid: 12700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\c8d085e8-fa71-439e-85fd-247165b7ffb1.tmp, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: updater.exe, Pid: 8080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\c18523e2-3cbe-48cc-8232-f433087744a0.tmp, EstimatedImpact: 0%

2025-11-22T12:57:50.699 ProcessImageName: crashhelper.exe, Pid: 19520, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log, EstimatedImpact: 2%

2025-11-22T13:02:18.183 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #196990, FileId: 0x52000000054a44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T13:03:14.215 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T13:17:19.285 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #197320, FileId: 0xb600000000439c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T13:18:19.199 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T13:32:20.208 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #197478, FileId: 0x26000000054a56, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T13:33:24.197 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T13:47:21.148 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #197712, FileId: 0xd900000001957b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T13:48:29.198 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T13:52:05.996 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #197755, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T13:52:06.000 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #197756, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T13:52:15.997 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #197763, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T13:52:16.001 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #197764, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T13:56:44.661 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #198037, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T14:01:20.628 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume4\ProgramData\NVIDIA\DisplaySessionContainer3.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #198397, FileId: 0x260000000002d9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T14:01:20.642 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\NvContainer\NvContainerSession3.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #198402, FileId: 0x1eb000000007930, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T14:01:56.822 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #198947, FileId: 0xe7000000015fd2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T14:03:34.199 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T14:18:39.185 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T14:33:44.184 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T14:34:26.534 Bm signature throttled:0x0000fab3228bcd4d

2025-11-22T14:48:49.181 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T14:51:14.696 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume4\Windows\SystemTemp\msedge_installer.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #201725, FileId: 0x12600000000eadd, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T14:57:50.668 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 7769, Count: 519, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9ba0a96c-ab24-4414-ab1e-6ca99c909c59.tmp, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 5270, Count: 320, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\874f51da-1606-4e96-bd36-fd43bfea825a.tmp, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 2913, Count: 280, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\ffprobe.exe, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: setup.exe, Pid: 24712, TotalTime: 2170, Count: 215, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeCore\142.0.3595.94\dxcompiler.dll, EstimatedImpact: 15%

2025-11-22T14:57:50.668 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 1985, Count: 217, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\Brooklyn Nine-Nine (2013) Season 1-8 S01-S08 (1080p AMZN WEB-DL x265 HEVC 10bit EAC3 5.1 Silence) REPACK\Season 7\Brooklyn Nine-Nine (2013) - S07E04 - The Jimmy Jab Games II (1080p AMZN WEB-DL x265 Silence).mkv, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1645, Count: 84, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-22T14:57:50.668 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 984, Count: 56, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\xampp-windows-x64-7.4.33-0-VC15-installer.exe, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 639, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: RuntimeBroker.exe, Pid: 25704, TotalTime: 618, Count: 21, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-22T14:57:50.668 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 600, Count: 101, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: setup.exe, Pid: 24656, TotalTime: 555, Count: 152, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeCore\142.0.3595.94\Installer\msedge_7z.data, EstimatedImpact: 43%

2025-11-22T14:57:50.668 ProcessImageName: DeviceCensus.exe, Pid: 26292, TotalTime: 326, Count: 13, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-22T14:57:50.668 ProcessImageName: powershell.exe, Pid: 3820, TotalTime: 290, Count: 45, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\4acfdbda9fe7d2c227cd2d57ea292ba9\System.Management.Automation.ni.dll, EstimatedImpact: 25%

2025-11-22T14:57:50.668 ProcessImageName: taskhostw.exe, Pid: 23720, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-22T14:57:50.668 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 196, Count: 30, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\14e110f4-263a-490b-938d-4cb77b4deccf.tmp, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 196, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 1864, TotalTime: 171, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeUpdate\Install\{76D7C8DE-684C-4A5B-BF52-3DE09E1CDB8D}\MicrosoftEdge_X64_142.0.3595.94_142.0.3595.90.exe, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: taskhostw.exe, Pid: 25424, TotalTime: 165, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 73%

2025-11-22T14:57:50.668 ProcessImageName: WmiPrvSE.exe, Pid: 23316, TotalTime: 154, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 100%

2025-11-22T14:57:50.668 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 152, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\dashboard\javascripts\modernizr.js, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 135, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 121, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 109, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\http.sys, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: MicrosoftEdge_X64_142.0.3595.94_142.0.3595.90.exe, Pid: 27144, TotalTime: 108, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeUpdate\Install\{76D7C8DE-684C-4A5B-BF52-3DE09E1CDB8D}\EDGEMITMP_1136D.tmp\setup.exe, EstimatedImpact: 77%

2025-11-22T14:57:50.668 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 106, Count: 8, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\Temp\DO25D1.tmp, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: nvcontainer.exe, Pid: 23544, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\MessageBus\messagebus.conf, EstimatedImpact: 9%

2025-11-22T14:57:50.668 ProcessImageName: MicrosoftEdge_X64_142.0.3595.94_142.0.3595.90.exe, Pid: 24900, TotalTime: 77, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeUpdate\Install\{E57F8CBA-C2A5-47AF-A9E0-B3B725DD47EA}\EDGEMITMP_0874C.tmp\setup.exe, EstimatedImpact: 72%

2025-11-22T14:57:50.668 ProcessImageName: RuntimeBroker.exe, Pid: 23892, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 13%

2025-11-22T14:57:50.668 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\28a2f016-ffa1-40a0-ae80-8ec409beb086.tmp, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: taskhostw.exe, Pid: 14732, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-22T14:57:50.668 ProcessImageName: updater.exe, Pid: 5864, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\c24af6cb-7bce-4023-b652-b77a0fba7eff.tmp, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: PhoneExperienceHost.exe, Pid: 13604, TotalTime: 30, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\Public\desktop.ini, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: wallpaper32.exe, Pid: 4144, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\DirectXApps.sdb, EstimatedImpact: 9%

2025-11-22T14:57:50.668 ProcessImageName: taskhostw.exe, Pid: 26868, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-22T14:57:50.668 ProcessImageName: updater.exe, Pid: 8992, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9d615a41-4fdf-4edb-93b2-e05360d17bd6.tmp, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: ffdetect.exe, Pid: 524, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 2%

2025-11-22T14:57:50.668 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: StoreDesktopExtension.exe, Pid: 23428, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: taskhostw.exe, Pid: 24956, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 3%

2025-11-22T14:57:50.668 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: NVDisplay.Container.exe, Pid: 2660, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 10%

2025-11-22T14:57:50.668 ProcessImageName: dllhost.exe, Pid: 404, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: crashhelper.exe, Pid: 19520, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log, EstimatedImpact: 2%

2025-11-22T14:57:50.668 ProcessImageName: updater.exe, Pid: 8080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\c18523e2-3cbe-48cc-8232-f433087744a0.tmp, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: updater.exe, Pid: 12700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\c8d085e8-fa71-439e-85fd-247165b7ffb1.tmp, EstimatedImpact: 0%

2025-11-22T14:57:50.668 ProcessImageName: powershell.exe, Pid: 23028, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\__PSScriptPolicyTest_hvklggry.2qz.psm1, EstimatedImpact: 0%

2025-11-22T15:03:54.171 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T15:18:07.953 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\08CA9191-2797-4267-A32A-63917E09D96F31a8.1dc5bc33410de06

2025-11-22T15:18:07.982 Verifying engine and signature files (source: 0) ...

2025-11-22T15:18:07.982 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AA6FF0EE-8FD6-46EF-A4B3-32FBBB4CEE4A}\mpengine.dll] due to PPL.

2025-11-22T15:18:07.982 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AA6FF0EE-8FD6-46EF-A4B3-32FBBB4CEE4A}\mpasbase.vdm] (file in cache)

2025-11-22T15:18:07.982 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AA6FF0EE-8FD6-46EF-A4B3-32FBBB4CEE4A}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-22T15:18:07.991 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AA6FF0EE-8FD6-46EF-A4B3-32FBBB4CEE4A}\mpasdlta.vdm]

2025-11-22T15:18:07.991 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AA6FF0EE-8FD6-46EF-A4B3-32FBBB4CEE4A}\mpavbase.vdm] (file in cache)

2025-11-22T15:18:07.991 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AA6FF0EE-8FD6-46EF-A4B3-32FBBB4CEE4A}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-22T15:18:08.000 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AA6FF0EE-8FD6-46EF-A4B3-32FBBB4CEE4A}\mpavdlta.vdm]

2025-11-22T15:18:08.071 [Engine] IsHybridMode: 0

2025-11-22T15:18:08.072 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-22T15:18:08.082 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-F97444A51361D03F174AD5A530C577877F6297A8.bin): 0x00000002

2025-11-22T15:18:08.084 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-F97444A51361D03F174AD5A530C577877F6297A8.bin)

2025-11-22T15:18:08.084 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-22T15:18:08.084 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-22T15:18:08.084 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-22T15:18:08.084 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-22T15:18:13.250 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-22T15:18:13.250 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-22T15:18:13.258 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7A9CA660, lRefCount: 5, hr=0

2025-11-22T15:18:13.258 [Engine] New active engine 00007FFE7F1CA660 replacing engine 00007FFE7A9CA660. Number of active engines: 2

2025-11-22T15:18:13.260 EngineInit:Global ASOC is enabled

2025-11-22T15:18:13.260 EngineInit:ASOO is enabled for developer volumes

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.289 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-22T15:18:13.290 MpWriteUupSignatureVersion 1.441.411.0, hr = 0

2025-11-22T15:18:13.291 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-22T15:18:13.303 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-22T15:18:13.304 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-22T15:18:13.304 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-22T15:18:13.304 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-22T15:18:13.304 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-22T15:18:13.318 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-22T15:18:13.318 [Plugin] Initializing RTP plugin state...

2025-11-22T15:18:13.318 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-22T15:18:13.318 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 22 - 2025 03:57:51

Last Perf: 11 - 22 - 2025 03:57:50

First RTP Scan: 11 - 22 - 2025 03:57:51

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1264

  Misses:12231

BM Queue:0,39,0

  Proc:0,30,0

  File:0,24,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:202377

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1146723836

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:17

  TotalStreamCon:28837

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:924490

   TotalHits:1559660

   InstanceCacheInserts:69697

   InstanceCacheUpdates:0

   InstanceCacheDeletes:49177

   InstanceCacheHits:4610

   InstanceCacheMisses:274370

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (1542/1632)

   Success: 1632, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-22T15:18:13.318 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AA6FF0EE-8FD6-46EF-A4B3-32FBBB4CEE4A}

2025-11-22T15:18:13.318 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79F10480-F9E1-482C-A8EF-EE11B9C367B8}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79F10480-F9E1-482C-A8EF-EE11B9C367B8}\mpasbase.vdm in use, hr=0x80070020

2025-11-22T15:18:13.318 [SCC][CID=421368093_17872] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-22T15:18:13.319 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-22T15:18:13.319 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-22T15:18:13.319 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-22T15:18:13.319 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-22T15:18:13.319 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-22T15:18:13.320 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-22-2025 15:18:13

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-22-2025 15:18:13

2025-11-22T15:18:13.322 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-22T15:18:13.322 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-22T15:18:13.323 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-22-2025 15:18:13

END TDT(U) telemetry



2025-11-22T15:18:13.323 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0

2025-11-22T15:18:13.325 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T15:18:13.325 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-22T15:18:13.325 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-22T15:18:13.325 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-22T15:18:13.325 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-22T15:18:13.325 MdCoreSvc is supported in this platform and OS

Signature updated on 11-22-2025 15:18:13

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.411.0

AV Signature Version: 1.441.411.0

************************************************************

2025-11-22T15:18:13.327 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-22T15:18:13.327 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\08CA9191-2797-4267-A32A-63917E09D96F31a8.1dc5bc33410de06

2025-11-22T15:18:13.338 Process scan (postsignatureupdatescan) started.

2025-11-22T15:18:13.363 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-22T15:18:13.365 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-22T15:18:13.494 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-22T15:18:13.494 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-22T15:18:13.494 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-22T15:18:13.494 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-22T15:18:13.494 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-22T15:18:13.496 [Engine] Engine 00007FFE7A9CA660 no longer in use. Number of active engines: 1

2025-11-22T15:18:13.496 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-22T15:18:13.496 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-22T15:18:13.650 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 7981, Count: 534, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9ba0a96c-ab24-4414-ab1e-6ca99c909c59.tmp, EstimatedImpact: 0%

2025-11-22T15:18:13.650 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 5421, Count: 330, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\874f51da-1606-4e96-bd36-fd43bfea825a.tmp, EstimatedImpact: 0%

2025-11-22T15:18:13.650 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 2913, Count: 280, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\ffprobe.exe, EstimatedImpact: 0%

2025-11-22T15:18:13.650 ProcessImageName: setup.exe, Pid: 24712, TotalTime: 2170, Count: 215, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeCore\142.0.3595.94\dxcompiler.dll, EstimatedImpact: 15%

2025-11-22T15:18:13.650 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 2015, Count: 219, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\Brooklyn Nine-Nine (2013) Season 1-8 S01-S08 (1080p AMZN WEB-DL x265 HEVC 10bit EAC3 5.1 Silence) REPACK\Season 7\Brooklyn Nine-Nine (2013) - S07E04 - The Jimmy Jab Games II (1080p AMZN WEB-DL x265 Silence).mkv, EstimatedImpact: 0%

2025-11-22T15:18:13.650 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1645, Count: 84, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-22T15:18:13.650 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 984, Count: 56, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\xampp-windows-x64-7.4.33-0-VC15-installer.exe, EstimatedImpact: 0%

2025-11-22T15:18:13.650 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 654, Count: 54, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-22T15:18:13.650 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 630, Count: 107, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-22T15:18:13.650 ProcessImageName: RuntimeBroker.exe, Pid: 25704, TotalTime: 618, Count: 21, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-22T15:18:13.650 ProcessImageName: setup.exe, Pid: 24656, TotalTime: 555, Count: 152, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Microsoft\EdgeCore\142.0.3595.94\Installer\msedge_7z.data, EstimatedImpact: 43%

2025-11-22T15:18:13.650 ProcessImageName: DeviceCensus.exe, Pid: 26292, TotalTime: 326, Count: 13, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-22T15:18:13.650 ProcessImageName: powershell.exe, Pid: 3820, TotalTime: 290, Count: 45, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\4acfdbda9fe7d2c227cd2d57ea292ba9\System.Management.Automation.ni.dll, EstimatedImpact: 25%

2025-11-22T15:18:13.650 ProcessImageName: taskhostw.exe, Pid: 23720, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-22T15:18:13.650 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 196, Count: 30, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\14e110f4-263a-490b-938d-4cb77b4deccf.tmp, EstimatedImpact: 0%

2025-11-22T15:18:13.650 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 196, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-22T15:18:13.667 [Engine] RSIG_UNLOADENGINE, 00007FFE7A9CA660, err=0x0

2025-11-22T15:18:13.685 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79F10480-F9E1-482C-A8EF-EE11B9C367B8} removed

2025-11-22T15:18:13.812 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-22T15:18:13.818 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-22T15:18:13.818 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-22T15:18:13.818 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-22T15:18:13.818 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-22T15:18:13.818 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-22T15:18:13.818 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-22T15:18:13.821 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-22T15:18:13.821 [RTP] Duplicating the current plugin configuration object...

2025-11-22T15:18:13.821 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-22T15:18:13.821 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-22T15:18:13.821 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-22T15:18:13.821 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-22T15:18:13.821 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-22T15:18:13.821 [RTP] No config change detected. Not updating plugin configuration.

2025-11-22T15:18:13.821 [RTP] No config changes found. No configuration switch.

2025-11-22T15:18:13.821 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-22T15:18:13.821 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-22T15:18:13.822 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-22T15:18:13.822 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-22T15:18:13.822 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-22T15:18:13.822 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-22T15:18:13.822 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-22T15:18:13.822 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-22T15:18:13.822 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-22T15:18:13.822 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-22T15:18:13.822 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-22T15:18:13.822 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-22T15:18:13.822 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-22T15:18:13.822 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-22T15:18:13.822 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-22T15:18:13.822 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-22T15:18:13.822 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T15:18:13.824 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T15:18:13.826 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T15:18:13.827 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T15:18:13.829 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T15:18:13.831 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 44619318(ms) from now at 04:41 (03:41 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-22T15:18:15.348 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-22T15:18:15.352 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-22T15:18:15.352 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-22T15:18:16.356 [RTP] Duplicating the current plugin configuration object...

2025-11-22T15:18:16.356 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-22T15:18:16.356 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-22T15:18:16.356 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-22T15:18:16.356 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-22T15:18:18.805 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-22T15:18:18.805 [Cloud] Start of cloud request. Passive mode: 0

2025-11-22T15:18:18.805 [Cloud] Queued cloud request.

2025-11-22T15:18:18.805 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-22T15:18:18.806 [Cloud] Dequeued cloud request.

2025-11-22T15:18:18.806 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-22T15:18:19.095 [Cloud] End of cloud request.

2025-11-22T15:18:19.612 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-22T15:18:27.485 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-22T15:18:27.486 Process scan (postsignatureupdatescan) completed.

2025-11-22T15:18:59.171 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T15:23:13.277 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-22T15:32:28.099 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #202535, FileId: 0x15b000000010639, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T15:34:04.160 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T15:41:08.518 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume4\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #203348, FileId: 0x107000000001e55, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T15:47:29.365 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #203405, FileId: 0x1ed000000002310, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T15:49:09.154 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T15:52:07.016 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #203459, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T15:52:07.027 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #203460, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T15:52:17.018 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #203473, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T16:02:29.549 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #203622, FileId: 0x1ca000000003a46, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T16:04:14.158 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T16:17:30.038 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #204118, FileId: 0x2540000000160fa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T16:19:19.149 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T16:32:31.355 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #204174, FileId: 0x3700000000ce9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T16:34:24.143 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T16:34:28.528 Bm signature throttled:0x0000fab3228bcd4d

2025-11-22T16:47:31.528 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #204332, FileId: 0x2e000000008b9a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T16:49:29.136 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T16:52:07.517 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #204344, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T16:52:07.519 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #204345, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T16:52:17.526 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #204350, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T16:52:17.526 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #204351, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T16:52:17.531 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #204352, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T17:02:31.613 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #204910, FileId: 0x38a000000008aff, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T17:04:34.142 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T17:17:33.095 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #205164, FileId: 0x20600000000397e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T17:18:13.225 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1472, Count: 80, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 88%

2025-11-22T17:18:13.225 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 1153, Count: 85, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\116bef63-32b0-46e8-8b86-d26e971582a2.tmp, EstimatedImpact: 0%

2025-11-22T17:18:13.225 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 693, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ce9f5b62-9186-43c4-b6db-c2bbda23c257.tmp, EstimatedImpact: 0%

2025-11-22T17:18:13.225 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 617, Count: 125, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 23%

2025-11-22T17:18:13.225 ProcessImageName: RuntimeBroker.exe, Pid: 20672, TotalTime: 481, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 32%

2025-11-22T17:18:13.225 ProcessImageName: taskhostw.exe, Pid: 21192, TotalTime: 373, Count: 6, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 3%

2025-11-22T17:18:13.225 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 240, Count: 52, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-22T17:18:13.225 ProcessImageName: taskhostw.exe, Pid: 5356, TotalTime: 196, Count: 40, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\SmartOptOut.json, EstimatedImpact: 9%

2025-11-22T17:18:13.225 ProcessImageName: ngentask.exe, Pid: 19412, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 17%

2025-11-22T17:18:13.225 ProcessImageName: WmiPrvSE.exe, Pid: 9880, TotalTime: 136, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 91%

2025-11-22T17:18:13.225 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 121, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-22T17:18:13.225 ProcessImageName: ngentask.exe, Pid: 21056, TotalTime: 120, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 12%

2025-11-22T17:18:13.225 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 92, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-22T17:18:13.225 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 90, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-22T17:18:13.225 ProcessImageName: ngentask.exe, Pid: 22544, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 53%

2025-11-22T17:18:13.225 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 76, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-22T17:18:13.225 ProcessImageName: ngentask.exe, Pid: 26416, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 37%

2025-11-22T17:18:13.225 ProcessImageName: ngentask.exe, Pid: 26252, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-22T17:18:13.225 ProcessImageName: ngentask.exe, Pid: 24684, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 8%

2025-11-22T17:18:13.225 ProcessImageName: StoreDesktopExtension.exe, Pid: 15104, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-22T17:18:13.225 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-22T17:18:13.225 ProcessImageName: updater.exe, Pid: 24448, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\3dd8e96a-a84c-44d7-80fe-dc5449d206d1.tmp, EstimatedImpact: 0%

2025-11-22T17:19:39.127 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T17:32:34.451 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #205305, FileId: 0x21300000000397e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T17:34:44.121 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T17:39:54.228 Bm signature throttled:0x00002db31bed458f

2025-11-22T17:47:34.503 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #206200, FileId: 0x1f2000000014dca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T17:49:49.119 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T17:52:05.404 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #206257, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T17:52:05.410 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #206258, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T17:52:15.407 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #206265, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T17:52:15.411 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #206266, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T18:01:37.992 Bm signature throttled:0x00002db31bed458f

2025-11-22T18:02:35.965 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #206550, FileId: 0x1cb000000023d86, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T18:04:54.115 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T18:17:37.375 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #206788, FileId: 0x22000000000397e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T18:19:59.115 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T18:32:38.804 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #207251, FileId: 0x373000000023eba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T18:34:30.527 Bm signature throttled:0x0000fab3228bcd4d

2025-11-22T18:35:04.115 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T18:47:38.975 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #207465, FileId: 0x1cf00000000b706, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T18:50:09.097 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T18:52:05.717 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #207491, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T18:52:05.721 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #207492, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T18:52:15.729 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #207497, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T18:52:15.733 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #207499, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T19:02:39.108 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #207612, FileId: 0x27f000000023f41, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T19:05:14.104 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T19:17:40.611 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #207768, FileId: 0xeb000000014373, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T19:18:13.199 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 2383, Count: 173, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\116bef63-32b0-46e8-8b86-d26e971582a2.tmp, EstimatedImpact: 0%

2025-11-22T19:18:13.199 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1692, Count: 153, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\Microsoft.IdentityModel.Tokens.dll, EstimatedImpact: 1%

2025-11-22T19:18:13.200 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 1541, Count: 105, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ce9f5b62-9186-43c4-b6db-c2bbda23c257.tmp, EstimatedImpact: 0%

2025-11-22T19:18:13.200 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1472, Count: 80, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 88%

2025-11-22T19:18:13.200 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1339, Count: 204, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-22T19:18:13.200 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 617, Count: 125, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 23%

2025-11-22T19:18:13.200 ProcessImageName: RuntimeBroker.exe, Pid: 20672, TotalTime: 481, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 32%

2025-11-22T19:18:13.200 ProcessImageName: taskhostw.exe, Pid: 21192, TotalTime: 373, Count: 6, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 3%

2025-11-22T19:18:13.200 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 255, Count: 58, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-22T19:18:13.201 ProcessImageName: WmiPrvSE.exe, Pid: 21148, TotalTime: 242, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 65%

2025-11-22T19:18:13.201 ProcessImageName: taskhostw.exe, Pid: 5356, TotalTime: 196, Count: 40, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\SmartOptOut.json, EstimatedImpact: 9%

2025-11-22T19:18:13.201 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 196, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-22T19:18:13.201 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 150, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-22T19:18:13.201 ProcessImageName: ngentask.exe, Pid: 19412, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 17%

2025-11-22T19:18:13.201 ProcessImageName: WmiPrvSE.exe, Pid: 9880, TotalTime: 136, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 91%

2025-11-22T19:18:13.201 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 121, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-22T19:18:13.201 ProcessImageName: ngentask.exe, Pid: 21056, TotalTime: 120, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 12%

2025-11-22T19:18:13.201 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 92, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-22T19:18:13.201 ProcessImageName: ngentask.exe, Pid: 22544, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 53%

2025-11-22T19:18:13.201 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 60, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 0%

2025-11-22T19:18:13.201 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 1%

2025-11-22T19:18:13.201 ProcessImageName: ngentask.exe, Pid: 26416, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 37%

2025-11-22T19:18:13.201 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\f14c81de-9ccc-483a-b3cd-a50a4eb921ab.tmp, EstimatedImpact: 0%

2025-11-22T19:18:13.201 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-22T19:18:13.201 ProcessImageName: ngentask.exe, Pid: 26252, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-22T19:18:13.201 ProcessImageName: ngentask.exe, Pid: 24684, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 8%

2025-11-22T19:18:13.201 ProcessImageName: taskhostw.exe, Pid: 12484, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 27%

2025-11-22T19:18:13.201 ProcessImageName: taskhostw.exe, Pid: 7284, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 3%

2025-11-22T19:18:13.201 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 30, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-22T19:18:13.201 ProcessImageName: StoreDesktopExtension.exe, Pid: 15104, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-22T19:18:13.201 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\cb7930ce-3f47-49e2-9d4c-cce8e9717eb9.tmp, EstimatedImpact: 0%

2025-11-22T19:18:13.201 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 3%

2025-11-22T19:18:13.201 ProcessImageName: nvngx_update.exe, Pid: 18152, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\nvngx_config.txt, EstimatedImpact: 2%

2025-11-22T19:18:13.201 ProcessImageName: updater.exe, Pid: 24448, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\3dd8e96a-a84c-44d7-80fe-dc5449d206d1.tmp, EstimatedImpact: 0%

2025-11-22T19:18:13.201 ProcessImageName: nvngx_update.exe, Pid: 3528, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-22T19:20:19.091 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T19:32:40.782 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #207942, FileId: 0x7e000000023fd9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T19:35:24.092 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T19:47:42.111 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #208193, FileId: 0x5e000000024e36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T19:50:29.093 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T19:52:05.745 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #208294, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T19:52:05.749 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #208295, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T19:52:15.753 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #208302, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T19:52:15.754 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #208303, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T19:52:15.757 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #208304, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T19:52:15.758 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #208305, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T20:01:19.800 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #208483, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T20:02:43.512 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #208498, FileId: 0x2f00000002711a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T20:05:34.074 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T20:17:43.560 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #208750, FileId: 0x3800000000baf4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T20:20:39.077 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T20:28:08.865 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\Nucleus-2025-11-22.1634.5876.3.aodl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #208922, FileId: 0x3b00000000ce9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T20:28:08.934 Bm signature throttled:0x0000fab3228bcd4d

2025-11-22T20:32:44.906 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #209035, FileId: 0x35000000028f20, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T20:35:44.072 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T20:47:45.205 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #209178, FileId: 0x2600000002a414, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T20:50:49.059 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T20:52:06.508 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #209205, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T20:52:06.512 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #209206, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T20:52:16.515 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #209211, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T20:52:16.516 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #209212, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T20:52:16.519 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #209213, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T21:02:45.658 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #209406, FileId: 0x2e8000000016530, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T21:05:54.059 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T21:17:46.963 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #209958, FileId: 0x345000000023f65, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T21:18:13.173 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 3905, Count: 262, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\116bef63-32b0-46e8-8b86-d26e971582a2.tmp, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 2991, Count: 185, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\6e781e88-2aeb-4d98-828e-dc917b85d328.tmp, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1692, Count: 153, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\Microsoft.IdentityModel.Tokens.dll, EstimatedImpact: 1%

2025-11-22T21:18:13.173 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1472, Count: 80, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 88%

2025-11-22T21:18:13.173 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1354, Count: 205, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 617, Count: 125, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 23%

2025-11-22T21:18:13.173 ProcessImageName: RuntimeBroker.exe, Pid: 20672, TotalTime: 481, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 32%

2025-11-22T21:18:13.173 ProcessImageName: taskhostw.exe, Pid: 21192, TotalTime: 373, Count: 6, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 3%

2025-11-22T21:18:13.173 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 286, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 270, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: WmiPrvSE.exe, Pid: 21148, TotalTime: 242, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 65%

2025-11-22T21:18:13.173 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 240, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: taskhostw.exe, Pid: 5356, TotalTime: 196, Count: 40, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\SmartOptOut.json, EstimatedImpact: 9%

2025-11-22T21:18:13.173 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 182, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: ngentask.exe, Pid: 19412, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 17%

2025-11-22T21:18:13.173 ProcessImageName: WmiPrvSE.exe, Pid: 9880, TotalTime: 136, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 91%

2025-11-22T21:18:13.173 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 135, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 1%

2025-11-22T21:18:13.173 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 3820, TotalTime: 120, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 2%

2025-11-22T21:18:13.173 ProcessImageName: ngentask.exe, Pid: 21056, TotalTime: 120, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 12%

2025-11-22T21:18:13.173 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\f14c81de-9ccc-483a-b3cd-a50a4eb921ab.tmp, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 92, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 90, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: ngentask.exe, Pid: 22544, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 53%

2025-11-22T21:18:13.173 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 1%

2025-11-22T21:18:13.173 ProcessImageName: ngentask.exe, Pid: 26416, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 37%

2025-11-22T21:18:13.173 ProcessImageName: svchost.exe, Pid: 24772, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT840D.tmp, EstimatedImpact: 1%

2025-11-22T21:18:13.173 ProcessImageName: ngentask.exe, Pid: 26252, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-22T21:18:13.173 ProcessImageName: ngentask.exe, Pid: 24684, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 8%

2025-11-22T21:18:13.173 ProcessImageName: taskhostw.exe, Pid: 12484, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 27%

2025-11-22T21:18:13.173 ProcessImageName: taskhostw.exe, Pid: 7284, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 3%

2025-11-22T21:18:13.173 ProcessImageName: taskhostw.exe, Pid: 13292, TotalTime: 30, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 3%

2025-11-22T21:18:13.173 ProcessImageName: StoreDesktopExtension.exe, Pid: 15104, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\cb7930ce-3f47-49e2-9d4c-cce8e9717eb9.tmp, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 3%

2025-11-22T21:18:13.173 ProcessImageName: updater.exe, Pid: 22316, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\d67566dc-0834-4df7-8fe7-0d476a3bc18a.tmp, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: taskhostw.exe, Pid: 17820, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-22T21:18:13.173 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: nvngx_update.exe, Pid: 18152, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\nvngx_config.txt, EstimatedImpact: 2%

2025-11-22T21:18:13.173 ProcessImageName: updater.exe, Pid: 24448, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\3dd8e96a-a84c-44d7-80fe-dc5449d206d1.tmp, EstimatedImpact: 0%

2025-11-22T21:18:13.173 ProcessImageName: nvngx_update.exe, Pid: 3528, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-22T21:20:59.061 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T21:28:22.590 Bm signature throttled:0x0000fab3228bcd4d

2025-11-22T21:32:48.402 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #210102, FileId: 0x55300000000ced2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T21:36:04.048 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T21:47:49.635 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #210301, FileId: 0xf4000000027409, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T21:51:09.056 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T21:52:06.488 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #210357, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T21:52:06.495 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #210358, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T21:52:16.491 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #210367, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T21:52:16.501 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #210369, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T22:02:50.890 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #210771, FileId: 0x8c00000003e29a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T22:06:14.041 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T22:17:52.367 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #211024, FileId: 0x84000000001ffe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T22:21:19.048 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T22:32:53.544 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #211351, FileId: 0x7b00000003f57c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T22:36:24.043 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T22:47:53.573 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #211530, FileId: 0x5100000003f1c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T22:51:29.041 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T22:52:06.542 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #211610, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T22:52:06.544 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #211611, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T22:52:16.555 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #211618, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T22:52:16.555 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #211617, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T22:52:16.559 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #211619, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T23:02:53.724 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #211770, FileId: 0x101000000014373, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T23:06:34.026 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T23:17:53.980 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #212105, FileId: 0x54000000030f39, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T23:18:13.148 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 5288, Count: 349, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\116bef63-32b0-46e8-8b86-d26e971582a2.tmp, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 4456, Count: 270, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\6e781e88-2aeb-4d98-828e-dc917b85d328.tmp, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1753, Count: 158, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\Microsoft.IdentityModel.Tokens.dll, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1472, Count: 80, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 88%

2025-11-22T23:18:13.148 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1354, Count: 205, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 617, Count: 125, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 23%

2025-11-22T23:18:13.148 ProcessImageName: RuntimeBroker.exe, Pid: 20672, TotalTime: 481, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 32%

2025-11-22T23:18:13.148 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 438, Count: 33, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: taskhostw.exe, Pid: 21192, TotalTime: 373, Count: 6, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 3%

2025-11-22T23:18:13.148 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 315, Count: 50, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 315, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\f14c81de-9ccc-483a-b3cd-a50a4eb921ab.tmp, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 270, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: WmiPrvSE.exe, Pid: 21148, TotalTime: 242, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 65%

2025-11-22T23:18:13.148 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 212, Count: 34, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: taskhostw.exe, Pid: 5356, TotalTime: 196, Count: 40, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\SmartOptOut.json, EstimatedImpact: 9%

2025-11-22T23:18:13.148 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 180, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 165, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 150, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: ngentask.exe, Pid: 19412, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 17%

2025-11-22T23:18:13.148 ProcessImageName: WmiPrvSE.exe, Pid: 9880, TotalTime: 136, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 91%

2025-11-22T23:18:13.148 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 3820, TotalTime: 120, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 2%

2025-11-22T23:18:13.148 ProcessImageName: backgroundTaskHost.exe, Pid: 7192, TotalTime: 120, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446, EstimatedImpact: 26%

2025-11-22T23:18:13.148 ProcessImageName: ngentask.exe, Pid: 21056, TotalTime: 120, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 12%

2025-11-22T23:18:13.148 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 92, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: ngentask.exe, Pid: 22544, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 53%

2025-11-22T23:18:13.148 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 60, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 1%

2025-11-22T23:18:13.148 ProcessImageName: ngentask.exe, Pid: 26416, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 37%

2025-11-22T23:18:13.148 ProcessImageName: svchost.exe, Pid: 24772, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT840D.tmp, EstimatedImpact: 1%

2025-11-22T23:18:13.148 ProcessImageName: ngentask.exe, Pid: 26252, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-22T23:18:13.148 ProcessImageName: ngentask.exe, Pid: 24684, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 8%

2025-11-22T23:18:13.148 ProcessImageName: taskhostw.exe, Pid: 26612, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 27%

2025-11-22T23:18:13.148 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\cb7930ce-3f47-49e2-9d4c-cce8e9717eb9.tmp, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: taskhostw.exe, Pid: 12484, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 27%

2025-11-22T23:18:13.148 ProcessImageName: taskhostw.exe, Pid: 7284, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 3%

2025-11-22T23:18:13.148 ProcessImageName: taskhostw.exe, Pid: 13292, TotalTime: 30, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 3%

2025-11-22T23:18:13.148 ProcessImageName: StoreDesktopExtension.exe, Pid: 15104, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 3%

2025-11-22T23:18:13.148 ProcessImageName: taskhostw.exe, Pid: 8080, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 9%

2025-11-22T23:18:13.148 ProcessImageName: updater.exe, Pid: 22316, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\d67566dc-0834-4df7-8fe7-0d476a3bc18a.tmp, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: taskhostw.exe, Pid: 17820, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-22T23:18:13.148 ProcessImageName: nvngx_update.exe, Pid: 18152, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\nvngx_config.txt, EstimatedImpact: 2%

2025-11-22T23:18:13.148 ProcessImageName: updater.exe, Pid: 24448, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\3dd8e96a-a84c-44d7-80fe-dc5449d206d1.tmp, EstimatedImpact: 0%

2025-11-22T23:18:13.148 ProcessImageName: nvngx_update.exe, Pid: 3528, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-22T23:21:39.022 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T23:28:24.572 Bm signature throttled:0x0000fab3228bcd4d

2025-11-22T23:32:54.248 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #212294, FileId: 0x76000000029346, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T23:36:44.026 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T23:47:55.513 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #212518, FileId: 0xd4000000003dc1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T23:51:49.023 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-22T23:52:06.408 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #212564, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T23:52:06.417 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #212565, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T23:52:16.413 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #212572, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-22T23:52:16.422 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #212574, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T00:02:55.837 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #212696, FileId: 0x69000000028da4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T00:06:54.009 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T00:17:09.009 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3

2025-11-23T00:17:09.009 Job Notification: New process added to job (1708)

2025-11-23T00:17:09.012 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched

2025-11-23T00:17:09.013 Aggressive catchup quick scan threshold: 4319966121209 / 25920000000000

2025-11-23T00:17:09.016 Job Notification: New process added to job (19584)

2025-11-23T00:17:09.024 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:1708] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:19584]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-23T00:17:09.070 Job Notification: New process added to job (19056)

2025-11-23T00:17:09.073 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched

2025-11-23T00:17:09.074 Job Notification: New process added to job (20564)

2025-11-23T00:17:09.081 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:19056] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:20564]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-23T00:17:09.124 Job Notification: New process added to job (5456)

2025-11-23T00:17:09.127 Task(GetDeviceTicket -AccessKey 6858448F-6D87-1201-8A1F-5A64AD064FEE ) launched as network service

2025-11-23T00:17:09.526 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-23T00:17:09.526 [RTP] Duplicating the current plugin configuration object...

2025-11-23T00:17:09.526 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-23T00:17:09.526 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-23T00:17:09.527 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-23T00:17:09.527 [RTP] No config change detected. Not updating plugin configuration.

2025-11-23T00:17:09.527 [RTP] No config changes found. No configuration switch.

2025-11-23T00:17:09.527 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-23T00:17:09.541 Job Notification: Process exited from job (5456)

2025-11-23T00:17:09.725 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-23T00:17:09.725 [Cloud] Start of cloud request. Passive mode: 0

2025-11-23T00:17:09.725 [Cloud] Queued cloud request.

2025-11-23T00:17:09.725 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-23T00:17:09.726 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0

2025-11-23T00:17:09.726 [Cloud] Start of cloud request. Passive mode: 0

2025-11-23T00:17:09.726 [Cloud] Queued cloud request.

2025-11-23T00:17:09.726 [Cloud] Dequeued cloud request.

2025-11-23T00:17:09.726 [Cloud] Dequeued cloud request.

2025-11-23T00:17:09.726 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-23T00:17:09.727 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-23T00:17:09.850 [Cloud] End of cloud request.

2025-11-23T00:17:09.898 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-23T00:17:09.900 [Cloud] End of cloud request.

2025-11-23T00:17:10.239 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T00:17:17.666 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\68AF8D30-80A2-4DAD-AF1F-9A18D135ECEC4e4c.1dc5c0e8603b44c

2025-11-23T00:17:17.704 Verifying engine and signature files (source: 0) ...

2025-11-23T00:17:17.704 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CF1F707-13B8-41E9-901F-730F383A4FD4}\mpengine.dll] due to PPL.

2025-11-23T00:17:17.704 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CF1F707-13B8-41E9-901F-730F383A4FD4}\mpasbase.vdm] (file in cache)

2025-11-23T00:17:17.704 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CF1F707-13B8-41E9-901F-730F383A4FD4}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-23T00:17:17.714 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CF1F707-13B8-41E9-901F-730F383A4FD4}\mpasdlta.vdm]

2025-11-23T00:17:17.714 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CF1F707-13B8-41E9-901F-730F383A4FD4}\mpavbase.vdm] (file in cache)

2025-11-23T00:17:17.714 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CF1F707-13B8-41E9-901F-730F383A4FD4}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-23T00:17:17.722 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CF1F707-13B8-41E9-901F-730F383A4FD4}\mpavdlta.vdm]

2025-11-23T00:17:17.797 [Engine] IsHybridMode: 0

2025-11-23T00:17:17.798 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-23T00:17:17.807 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-51F6B9C9742AD690CC7FAD98DC663A3B4DD8C082.bin): 0x00000002

2025-11-23T00:17:17.809 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-51F6B9C9742AD690CC7FAD98DC663A3B4DD8C082.bin)

2025-11-23T00:17:17.809 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-23T00:17:17.809 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-23T00:17:17.809 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-23T00:17:17.809 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-23T00:17:23.357 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-23T00:17:23.357 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-23T00:17:23.363 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7F1CA660, lRefCount: 5, hr=0

2025-11-23T00:17:23.363 [Engine] New active engine 00007FFE7A9CA660 replacing engine 00007FFE7F1CA660. Number of active engines: 2

2025-11-23T00:17:23.370 EngineInit:Global ASOC is enabled

2025-11-23T00:17:23.370 EngineInit:ASOO is enabled for developer volumes

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.401 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T00:17:23.403 MpWriteUupSignatureVersion 1.441.420.0, hr = 0

2025-11-23T00:17:23.404 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-23T00:17:23.417 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-23T00:17:23.418 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-23T00:17:23.418 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-23T00:17:23.418 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-23T00:17:23.418 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-23T00:17:23.432 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-23T00:17:23.432 [Plugin] Initializing RTP plugin state...

2025-11-23T00:17:23.432 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-23T00:17:23.432 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 22 - 2025 16:18:13

Last Perf: 11 - 22 - 2025 16:18:13

First RTP Scan: 11 - 22 - 2025 16:18:14

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1018

  Misses:6621

BM Queue:0,44,0

  Proc:0,44,0

  File:0,15,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:213155

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1178591438

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:17

  TotalStreamCon:30265

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:960603

   TotalHits:1625768

   InstanceCacheInserts:72401

   InstanceCacheUpdates:0

   InstanceCacheDeletes:52673

   InstanceCacheHits:4612

   InstanceCacheMisses:281765

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (802/910)

   Success: 910, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-23T00:17:23.432 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CF1F707-13B8-41E9-901F-730F383A4FD4}

2025-11-23T00:17:23.433 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AA6FF0EE-8FD6-46EF-A4B3-32FBBB4CEE4A}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AA6FF0EE-8FD6-46EF-A4B3-32FBBB4CEE4A}\mpasbase.vdm in use, hr=0x80070020

2025-11-23T00:17:23.433 [SCC][CID=542271656_22220] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-23T00:17:23.434 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-23T00:17:23.434 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-23T00:17:23.434 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-23T00:17:23.434 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-23T00:17:23.434 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-23-2025 00:17:23

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-23-2025 00:17:23

2025-11-23T00:17:23.435 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-23T00:17:23.438 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-23T00:17:23.438 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-23T00:17:23.438 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-23T00:17:23.438 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-23-2025 00:17:23

END TDT(U) telemetry



2025-11-23T00:17:23.441 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T00:17:23.441 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-23T00:17:23.441 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-23T00:17:23.441 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-23T00:17:23.441 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-23T00:17:23.442 MdCoreSvc is supported in this platform and OS

Signature updated on 11-23-2025 00:17:23

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.420.0

AV Signature Version: 1.441.420.0

************************************************************

2025-11-23T00:17:23.443 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-23T00:17:23.443 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\68AF8D30-80A2-4DAD-AF1F-9A18D135ECEC4e4c.1dc5c0e8603b44c

2025-11-23T00:17:23.456 Process scan (postsignatureupdatescan) started.

2025-11-23T00:17:23.481 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-23T00:17:23.482 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

Signature updated via MicrosoftUpdateServer on 11-23-2025 00:17:23

************************************************************

2025-11-23T00:17:23.523 Job Notification: Process exited from job (19056)

2025-11-23T00:17:23.524 Job Notification: Process exited from job (20564)

2025-11-23T00:17:23.558 Job Notification: Process exited from job (1708)

2025-11-23T00:17:23.559 Job Notification: Process exited from job (19584)

2025-11-23T00:17:23.620 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-23T00:17:23.620 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-23T00:17:23.621 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-23T00:17:23.621 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-23T00:17:23.621 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-23T00:17:23.623 [Engine] Engine 00007FFE7F1CA660 no longer in use. Number of active engines: 1

2025-11-23T00:17:23.623 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-23T00:17:23.623 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-23T00:17:23.784 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 5940, Count: 391, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\116bef63-32b0-46e8-8b86-d26e971582a2.tmp, EstimatedImpact: 0%

2025-11-23T00:17:23.784 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 5249, Count: 314, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\6e781e88-2aeb-4d98-828e-dc917b85d328.tmp, EstimatedImpact: 0%

2025-11-23T00:17:23.784 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1784, Count: 159, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\Microsoft.IdentityModel.Tokens.dll, EstimatedImpact: 0%

2025-11-23T00:17:23.784 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1472, Count: 80, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 88%

2025-11-23T00:17:23.784 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1354, Count: 205, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-23T00:17:23.784 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 617, Count: 125, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 23%

2025-11-23T00:17:23.784 ProcessImageName: RuntimeBroker.exe, Pid: 20672, TotalTime: 481, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 32%

2025-11-23T00:17:23.784 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 468, Count: 36, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T00:17:23.784 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 450, Count: 55, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\f14c81de-9ccc-483a-b3cd-a50a4eb921ab.tmp, EstimatedImpact: 0%

2025-11-23T00:17:23.784 ProcessImageName: taskhostw.exe, Pid: 21192, TotalTime: 373, Count: 6, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 3%

2025-11-23T00:17:23.784 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 345, Count: 57, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-23T00:17:23.784 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 273, Count: 39, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-23T00:17:23.784 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5876, TotalTime: 270, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-23T00:17:23.784 ProcessImageName: WmiPrvSE.exe, Pid: 21148, TotalTime: 242, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 65%

2025-11-23T00:17:23.784 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 225, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-11-23T00:17:23.784 ProcessImageName: taskhostw.exe, Pid: 5356, TotalTime: 196, Count: 40, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\SmartOptOut.json, EstimatedImpact: 9%

2025-11-23T00:17:23.800 [Engine] RSIG_UNLOADENGINE, 00007FFE7F1CA660, err=0x0

2025-11-23T00:17:23.817 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AA6FF0EE-8FD6-46EF-A4B3-32FBBB4CEE4A} removed

2025-11-23T00:17:23.918 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-23T00:17:23.925 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-23T00:17:23.925 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-23T00:17:23.925 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-23T00:17:23.927 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-23T00:17:23.927 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-23T00:17:23.927 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-23T00:17:23.930 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-23T00:17:23.930 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-23T00:17:23.930 [RTP] Duplicating the current plugin configuration object...

2025-11-23T00:17:23.930 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-23T00:17:23.930 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-23T00:17:23.930 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-23T00:17:23.930 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-23T00:17:23.930 [RTP] No config change detected. Not updating plugin configuration.

2025-11-23T00:17:23.930 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-23T00:17:23.930 [RTP] No config changes found. No configuration switch.

2025-11-23T00:17:23.930 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-23T00:17:23.930 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-23T00:17:23.930 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-23T00:17:23.930 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-23T00:17:23.930 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-23T00:17:23.930 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-23T00:17:23.930 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-23T00:17:23.930 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-23T00:17:23.930 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-23T00:17:23.930 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-23T00:17:23.930 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-23T00:17:23.930 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-23T00:17:23.930 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-23T00:17:23.930 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-23T00:17:23.930 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-23T00:17:23.931 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T00:17:23.932 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T00:17:23.934 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T00:17:23.935 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T00:17:23.937 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T00:17:23.939 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 13481298(ms) from now at 05:02 (04:02 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-23T00:17:25.463 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-23T00:17:25.466 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-23T00:17:25.467 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-23T00:17:26.468 [RTP] Duplicating the current plugin configuration object...

2025-11-23T00:17:26.468 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-23T00:17:26.468 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-23T00:17:26.468 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-23T00:17:26.468 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-23T00:17:29.119 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-23T00:17:29.119 [Cloud] Start of cloud request. Passive mode: 0

2025-11-23T00:17:29.119 [Cloud] Queued cloud request.

2025-11-23T00:17:29.119 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-23T00:17:29.119 [Cloud] Dequeued cloud request.

2025-11-23T00:17:29.119 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-23T00:17:29.408 [Cloud] End of cloud request.

2025-11-23T00:17:29.921 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T00:17:38.022 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-23T00:17:38.022 Process scan (postsignatureupdatescan) completed.

2025-11-23T00:17:57.234 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #213186, FileId: 0x1af000000023c87, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T00:21:59.006 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T00:22:23.384 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-23T00:32:58.721 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #213526, FileId: 0x5600000003f71a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T00:37:04.007 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T00:48:00.076 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #213903, FileId: 0x570000000130e2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T00:52:07.281 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #213959, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T00:52:07.286 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #213960, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T00:52:08.991 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T00:52:17.282 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #213965, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T00:52:17.283 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #213966, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T00:52:17.285 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #213967, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T00:52:17.287 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #213968, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T01:03:00.169 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #214367, FileId: 0x5100000003f79a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T01:07:14.001 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T01:18:01.577 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #215272, FileId: 0x2f000000054af0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T01:22:18.988 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T01:28:26.594 Bm signature throttled:0x0000fab3228bcd4d

2025-11-23T01:33:02.787 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #215419, FileId: 0x2c000000054b0c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T01:37:23.977 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T01:39:44.707 [AutoPurge] Verification Routine tasks have started.

2025-11-23T01:39:44.707 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-23T01:39:44.714 [AutoPurge] Routine task for Cache Maintenance has started.

2025-11-23T01:39:44.714 [AutoPurge] Routine task for Cache Maintenance ...

2025-11-23T01:39:44.714 [AutoPurge] Routine task for MpSFCBuild ...

2025-11-23T01:39:44.714 [AutoPurge] MpCmIsBuildCompleted() - S_OK

2025-11-23T01:39:44.714 [AutoPurge] MpSignalMaintenanceMode ...

2025-11-23T01:39:44.715 [AutoPurge] Cleanup Routine tasks have started.

2025-11-23T01:39:44.717 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0)

2025-11-23T01:39:44.717 [AutoPurge] Purged 0 expired detection item(s) from a total of 0.

2025-11-23T01:39:44.718 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds)

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:65538

Start time:11-23-2025 01:39:44

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-23-2025 01:39:44

2025-11-23T01:39:44.720 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ...

2025-11-23T01:39:44.720 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0 ...

2025-11-23T01:39:44.720 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0 ...

2025-11-23T01:39:44.720 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ...

2025-11-23T01:39:44.720 [AutoPurge] Cleanup Routine tasks have ended.

2025-11-23T01:39:44.722 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:5EF057ED-F248-4C02-ADCB-A69536965504, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1)

2025-11-23T01:39:44.722 Scheduled scan with Id 5EF057ED-F248-4C02-ADCB-A69536965504 configured CPU priority: normal (LowCpuPriority: 0)

2025-11-23T01:39:44.722 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build.

2025-11-23T01:39:44.722 [SFC] System file cache build is not needed (already completed)

2025-11-23T01:39:44.723 QuickScan:ScanID:5EF057ED-F248-4C02-ADCB-A69536965504: Quick Scan skipped since it already ran during the past 7 days

2025-11-23T01:39:44.723 QuickScan:ScanID:5EF057ED-F248-4C02-ADCB-A69536965504: Quick scan finished with error 1223

2025-11-23T01:39:44.723 OnDemandScanWorker: Scan Cancelled! scanId:5EF057ED-F248-4C02-ADCB-A69536965504, hr = 0x80508018

!ERROR

Begin Quick Scan

Scan ID:{5EF057ED-F248-4C02-ADCB-A69536965504}

Scan Source:1

Start Time:11-23-2025 01:39:44

Unsuccessful Scan

Return Code:1223

************************************************************



2025-11-23T01:39:44.772 EnsureProtectedFolderAcls(), hr = 0x0

2025-11-23T01:39:44.776 [AutoPurge] MpReinforceServiceAcls: 0

2025-11-23T01:39:44.780 Engine:Setting original file name "WIARPC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiarpc.dll.mui_0c913b87", hr=0x0

2025-11-23T01:39:44.787 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0

2025-11-23T01:39:44.789 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed.

2025-11-23T01:39:44.790 [AutoPurge] Verification Routine tasks have ended.

2025-11-23T01:39:44.802 Engine:Setting original file name "nlsbres.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..ocale-nls.resources_31bf3856ad364e35_10.0.26100.4484_nb-no_339b02f7f61c146e\winnlsres.dll.mui", hr=0x0

2025-11-23T01:39:45.051 Engine:Setting original file name "IEXPLORE.EXE" for "c:\program files (x86)\internet explorer\en-us\iexplore.exe.mui", hr=0x0

2025-11-23T01:39:45.080 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_en-us_1258b52c940aadb7_winload.efi.mui_35ee487d", hr=0x0

2025-11-23T01:39:45.515 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sr-..-rs_d1943ecc8317ab66_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-23T01:39:45.650 Engine:Setting original file name " " for "c:\program files (x86)\steam\bin\cef\cef.win7x64\dxcompiler.dll", hr=0x0

2025-11-23T01:39:45.693 Engine:Setting original file name "dual_engine_adapter.dll" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\dual_engine_adapter_x64.dll", hr=0x0

2025-11-23T01:39:45.826 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\winsxs\wow64_microsoft-windows-bcp47languages_31bf3856ad364e35_10.0.26100.7019_none_40ac55a9bb1ab239\bcp47langs.dll", hr=0x0

2025-11-23T01:39:45.837 Engine:Setting original file name "MAPI32.DLL.MUI" for "c:\windows\system32\nb-no\mapistub.dll.mui", hr=0x0

2025-11-23T01:39:45.979 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-23T01:39:46.021 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_ar-sa_af75f4ef024a79a1_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-23T01:39:46.082 Engine:Setting original file name "Apphelp" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a4bb088d5aa4193f97a4bdef0c1f8c71\apphelp.dll.mui", hr=0x0

2025-11-23T01:39:46.127 Engine:Setting original file name "F12Chooser.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-ie-iechooser.resources_31bf3856ad364e35_11.0.26100.1_nb-no_a7630c027f26ac69\iechooser.exe.mui", hr=0x0

2025-11-23T01:39:46.158 Engine:Setting original file name "THEMESERVICE.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-themeservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_5e5bf64d5b3ca824_themeservice.dll.mui_9e71f1ab", hr=0x0

2025-11-23T01:39:46.186 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_ad141a64b8fd6038_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:46.282 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\wow64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.26100.712_none_5cfec91758ee0662\windows.security.credentials.ui.credentialpicker.dll", hr=0x0

2025-11-23T01:39:46.338 Engine:Setting original file name "mavinject32.exe" for "c:\windows\winsxs\wow64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_592d553ad6e77100\mavinject.exe", hr=0x0

2025-11-23T01:39:46.458 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_bfcde09794ad7074_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-23T01:39:46.464 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\zh-cn\memtest.efi.mui", hr=0x0

2025-11-23T01:39:46.563 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_nb-no_022ea2e874b2cab6_winresume.efi.mui_f412814e", hr=0x0

2025-11-23T01:39:46.641 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lt-lt_11cd7cc1c62eb609_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:46.739 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-23T01:39:46.742 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-23T01:39:46.743 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-23T01:39:46.896 Engine:Setting original file name "WmiApSrv.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiapsrv.exe.mui_b1567840", hr=0x0

2025-11-23T01:39:46.947 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kk-kz_bb9a512b689c9b87_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:46.972 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_b5793645604cae79_memtest.efi.mui_71e15c22", hr=0x0

2025-11-23T01:39:46.987 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_he-il_3abd6f82e93c03e5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:46.994 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.26100.1_en-us_c3d82ef5c0380efa_wudfpf.sys.mui_f61e9e86", hr=0x0

2025-11-23T01:39:47.248 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaihdrx.dll", hr=0x0

2025-11-23T01:39:47.378 Engine:Setting original file name "l3codec.acm.mui" for "c:\windows\system32\nb-no\l3codeca.acm.mui", hr=0x0

2025-11-23T01:39:47.483 Engine:Setting original file name "w32topl.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_10.0.26100.1_none_cbd0eec659c2eb5c_w32topl.dll_1a0f388b", hr=0x0

2025-11-23T01:39:47.496 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ms-my_6f80e6fda2cebe8f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:47.758 Engine:Setting original file name "NVPTXJITCOMPILER32.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvptxjitcompiler64.dll", hr=0x0

2025-11-23T01:39:47.794 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5de87d4a39ffc584310f0b06dff9fcd0\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-23T01:39:47.864 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_38f499759ea365c4_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:47.912 Engine:Setting original file name "ddputils.lib.mui" for "c:\windows\system32\nb-no\ddputils.dll.mui", hr=0x0

2025-11-23T01:39:48.014 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kn-in_6e7a81f857a45cbe_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:48.042 Engine:Setting original file name "officeimm.odf" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\office.odf", hr=0x0

2025-11-23T01:39:48.227 Engine:Setting original file name ""AcGenral.dll"" for "c:\windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_10.0.26100.7019_none_a8119654a230db44\acgenral.dll", hr=0x0

2025-11-23T01:39:48.301 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sr-..-rs_7327597d7718c882_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:48.329 Engine:Setting original file name "Hyper-V Host Compute Service Diagnostics Tool" for "c:\windows\winsxs\amd64_hyperv-compute-cont..sticstool.resources_31bf3856ad364e35_10.0.26100.1_en-us_61074b8c7d2f38cf\hcsdiag.exe.mui", hr=0x0

2025-11-23T01:39:48.343 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.32530.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-23T01:39:48.377 Engine:Setting original file name "davsvc.dll.mui" for "c:\windows\system32\nb-no\webclnt.dll.mui", hr=0x0

2025-11-23T01:39:48.404 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\nb-no\wsepno.dll.mui", hr=0x0

2025-11-23T01:39:48.416 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x0

2025-11-23T01:39:48.449 Engine:Setting original file name "bootstr.exe.mui" for "c:\windows\system32\nb-no\bootstr.dll.mui", hr=0x0

2025-11-23T01:39:48.468 Engine:Setting original file name "msvcp140_2_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_2_app.dll", hr=0x0

2025-11-23T01:39:48.681 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-libraryloader-l1-1-0.dll", hr=0x0

2025-11-23T01:39:48.686 Engine:Setting original file name "dvsvc.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..rationsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_5c873aff49ea76e6\dcsvc.dll.mui", hr=0x0

2025-11-23T01:39:48.714 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_qps-ploc_5c9773f9ea1ce396_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:48.715 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_cs-cz_7086b4650c9e547c_memtest.efi.mui_71e15c22", hr=0x0

2025-11-23T01:39:48.760 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-23T01:39:48.762 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-23T01:39:48.763 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-23T01:39:48.812 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa78d0db4729269ff4beb393d45ca94a\dnsapi.dll.mui", hr=0x0

2025-11-23T01:39:48.828 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hr-hr_86baa9ad7eed6d52_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:48.866 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ja-jp_ed01f249e53f7235_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-23T01:39:48.872 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-file-l1-1-0.dll", hr=0x0

2025-11-23T01:39:48.896 Engine:Setting original file name "D3DX10.dll" for "c:\windows\system32\d3dx10_43.dll", hr=0x0

2025-11-23T01:39:48.967 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_da-dk_f5abc0a0339bc397_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:49.048 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-conio-l1-1-0.dll", hr=0x0

2025-11-23T01:39:49.164 Engine:Setting original file name "Auto Enrollment DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..utoenroll.resources_31bf3856ad364e35_10.0.26100.1_en-us_b82b35a9c2228d6b\pautoenr.dll.mui", hr=0x0

2025-11-23T01:39:49.249 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\windows\winsxs\amd64_microsoft-textinput-helpers.resources_31bf3856ad364e35_10.0.26100.1_nb-no_2c9a52bac4b766e3\ime_textinputhelpers.dll.mui", hr=0x0

2025-11-23T01:39:49.263 Engine:Setting original file name "Ribbons" for "c:\windows\winsxs\amd64_microsoft-windows-ribbons.resources_31bf3856ad364e35_10.0.26100.1_en-us_f85e1124efc279b5\ribbons.scr.mui", hr=0x0

2025-11-23T01:39:49.302 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_18153ede37451276\memtest.exe.mui", hr=0x0

2025-11-23T01:39:49.348 Engine:Setting original file name "scecli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\978b70ff94ed14c641fe52c5237facec\scecli.dll.mui", hr=0x0

2025-11-23T01:39:49.366 Engine:Setting original file name "mpsdrv.sys.mui" for "c:\windows\winsxs\backup\amd64_networking-mpssvc-drv.resources_31bf3856ad364e35_10.0.26100.1_nb-no_05849dc2762f9d2d_mpsdrv.sys.mui_b2aea3b6", hr=0x0

2025-11-23T01:39:49.385 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-tw_21b451d70c8c2957_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-23T01:39:49.541 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_2b309b875a6f3e1e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:49.605 Engine:Setting original file name "Vulkan Runtime" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\vulkan-1.dll", hr=0x0

2025-11-23T01:39:49.643 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-p..i-ntprint.resources_31bf3856ad364e35_10.0.26100.1_en-us_6ff199c21e8ad886\ntprint.dll.mui", hr=0x0

2025-11-23T01:39:49.704 Engine:Setting original file name "bootstr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..environment-strings_31bf3856ad364e35_10.0.26100.1_none_f575b80d757af501\bootstr.dll", hr=0x0

2025-11-23T01:39:49.731 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_zh-cn_fd81e6b68df3d1a9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:49.906 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-23T01:39:49.987 Engine:Setting original file name "liblzma.dll" for "c:\program files\windowsapps\microsoft.6365217ce6eb4_102.2509.19002.0_x64__8wekyb3d8bbwe\lzma.dll", hr=0x0

2025-11-23T01:39:50.077 Engine:Setting original file name "wuapi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\uus\x86\nb-no\c120e79170c204b0e5f1ece795e86e83\wuapicore.dll.mui", hr=0x0

2025-11-23T01:39:50.140 Engine:Setting original file name "Ontology.dll" for "c:\users\serverpc\appdata\local\nvidia corporation\nvidia app\nvbackend\applicationontology\ontology64.dll", hr=0x0

2025-11-23T01:39:50.273 Engine:Setting original file name "VpnSohDesktop.dll" for "c:\windows\system32\windows.perception.stub.dll", hr=0x0

2025-11-23T01:39:50.348 Engine:Setting original file name "kernel32" for "c:\windows\syswow64\kernel32.dll", hr=0x0

2025-11-23T01:39:50.374 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.549981c3f5f10_4.2308.1005.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-23T01:39:50.524 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_b38289243d899c4c_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:50.595 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_82eb3d34cd19fa50_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:50.742 Engine:Setting original file name "Steamclient.dll" for "c:\program files (x86)\steam\steamclient64.dll", hr=0x0

2025-11-23T01:39:50.812 Engine:Setting original file name "VrdUmde.dll" for "c:\windows\winsxs\amd64_gpuvirtualizationumed_31bf3856ad364e35_10.0.26100.1150_none_17421023ba072774\vrdumed.dll", hr=0x0

2025-11-23T01:39:50.824 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.efi.mui", hr=0x0

2025-11-23T01:39:50.957 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.winmd", hr=0x0

2025-11-23T01:39:51.275 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_lt-lt_ba1ae95b692b9594_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-23T01:39:51.385 Engine:Setting original file name "windows.ui.xaml.resources.win81.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ctui-resourceswin81_31bf3856ad364e35_10.0.26100.1301_none_b7b52abe3d381205_windows.ui.xaml.resources.win81.dll_d426e245", hr=0x0

2025-11-23T01:39:51.513 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-timezone-l1-1-0.dll", hr=0x0

2025-11-23T01:39:51.554 Engine:Setting original file name "jscript9.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\c3275836e276aea69afa458336037853\jscript9legacy.dll.mui", hr=0x0

2025-11-23T01:39:51.852 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x0

2025-11-23T01:39:51.904 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-profile-l1-1-0.dll", hr=0x0

2025-11-23T01:39:52.129 Engine:Setting original file name "Windows.FileExplorer.Common.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\84c8a2171c12d91e854ffb6a27b39453\windows.fileexplorer.common.dll.mui", hr=0x0

2025-11-23T01:39:52.332 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.26100.1_en-us_99a73e6649d69102\ndisimplatcim.dll.mui", hr=0x0

2025-11-23T01:39:52.382 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-23T01:39:52.449 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-localization-l1-2-0.dll", hr=0x0

2025-11-23T01:39:52.508 Engine:Setting original file name "Placeholder.dll" for "c:\windows\winsxs\x86_netfx4-penimc_v0400_b03f5f7f11d50a3a_4.0.15920.102_none_21046749883d249b\penimc_v0400.dll", hr=0x0

2025-11-23T01:39:52.530 Engine:Setting original file name "NvCamera.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\nvcameraallowlisting32.dll", hr=0x0

2025-11-23T01:39:52.777 Engine:Setting original file name ".NET Host Policy -" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\hostpolicy.dll", hr=0x0

2025-11-23T01:39:53.165 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sv-se_cac4b549037c269f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:53.169 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-23T01:39:53.201 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-23T01:39:53.220 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\winsxs\amd64_microsoft-windows-appx-deployment-server_31bf3856ad364e35_10.0.26100.7171_none_fd3893d466902045\applytrustoffline.exe", hr=0x0

2025-11-23T01:39:53.355 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\wow64_microsoft-windows-a..on-logger.resources_31bf3856ad364e35_10.0.26100.1_en-us_a0e09b8ec526451d\aeevts.dll.mui", hr=0x0

2025-11-23T01:39:53.446 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-23T01:39:53.623 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\4f8d3bb436c7\apex_particleschecked_x86.dll", hr=0x0

2025-11-23T01:39:53.697 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_it-it_72537c4985790e22_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:53.813 Engine:Setting original file name "EsclWiaDriver.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_esclwiadriver.dll.mui_d4a5b959", hr=0x0

2025-11-23T01:39:53.931 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_da-dk_be356ba870c91e76\msprivs.dll.mui", hr=0x0

2025-11-23T01:39:53.933 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-23T01:39:53.944 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_es-es_bdfd06f72820647a_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-23T01:39:54.050 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pl-pl\msprivs.dll.mui", hr=0x0

2025-11-23T01:39:54.065 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-23T01:39:54.085 Engine:Setting original file name "rmactivate.exe.mui" for "c:\windows\syswow64\en-us\rmactivate_isv.exe.mui", hr=0x0

2025-11-23T01:39:54.308 Engine:Setting original file name "apex.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\73be2921551d\apex_turbulencefschecked_x86.dll", hr=0x0

2025-11-23T01:39:54.334 Engine:Setting original file name "ScrCons" for "c:\windows\winsxs\amd64_microsoft-windows-w..consumers.resources_31bf3856ad364e35_10.0.26100.1_en-us_5d0e2df387a86d5d\scrcons.exe.mui", hr=0x0

2025-11-23T01:39:54.341 Engine:Setting original file name "PtpProv" for "c:\windows\winsxs\amd64_microsoft-windows-t..-provider.resources_31bf3856ad364e35_10.0.26100.1_en-us_eec70481b215edf0\ptpprov.dll.mui", hr=0x0

2025-11-23T01:39:54.346 Engine:Setting original file name "GbrtClient.dll" for "c:\program files\windowsapps\spotifyab.spotifymusic_1.276.298.0_x64__zpdnekdrzrea0\microsoft.gaming.xboxgamebar.dll", hr=0x0

2025-11-23T01:39:54.386 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\resources\themes\aero\nb-no\aerolite.msstyles.mui", hr=0x0

2025-11-23T01:39:54.548 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_cd255b4d1be69fe9_winload.efi.mui_35ee487d", hr=0x0

2025-11-23T01:39:54.578 Engine:Setting original file name "pegi.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_en-us_58f534214187451c\pegi.rs.mui", hr=0x0

2025-11-23T01:39:54.583 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-iexpress.resources_31bf3856ad364e35_11.0.26100.1_en-us_f84c0d683fdc407b\wextract.exe.mui", hr=0x0

2025-11-23T01:39:55.037 Engine:Setting original file name "updater.exe" for "c:\program files (x86)\google\update\googleupdate.exe", hr=0x0

2025-11-23T01:39:55.183 Engine:Setting original file name "ServicingBase.dll" for "c:\windows\system32\servicingcommon.dll", hr=0x0

2025-11-23T01:39:55.204 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.exe.mui", hr=0x0

2025-11-23T01:39:55.378 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\vulkan-1.dll", hr=0x0

2025-11-23T01:39:55.424 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_c77eb7b609c47f12\diagpackage.dll.mui", hr=0x0

2025-11-23T01:39:55.547 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\system32\wbem\en-us\netadaptercim.dll.mui", hr=0x0

2025-11-23T01:39:55.573 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\syswow64\nb-no\wextract.exe.mui", hr=0x0

2025-11-23T01:39:55.681 Engine:Setting original file name "NvTelemetry.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvinstallerutil.dll", hr=0x0

2025-11-23T01:39:55.729 Engine:Setting original file name "NvMessageBusBroadcast.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\localsystem\_nvmsgbusbroadcast.dll", hr=0x0

2025-11-23T01:39:55.936 Engine:Setting original file name "NVOPENCL.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvopencl64.dll", hr=0x0

2025-11-23T01:39:55.944 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x0

2025-11-23T01:39:56.021 Engine:Setting original file name "Ribbons" for "c:\windows\system32\nb-no\ribbons.scr.mui", hr=0x0

2025-11-23T01:39:56.171 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_de-de_bb6100e4729f7310\msprivs.dll.mui", hr=0x0

2025-11-23T01:39:56.326 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_en-gb_943f70b729277031_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:56.356 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570\dnsapi.dll.mui", hr=0x0

2025-11-23T01:39:56.358 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x0

2025-11-23T01:39:56.444 Engine:Setting original file name "expediteupdater" for "c:\program files\microsoft update health tools\expediteupdater.exe", hr=0x0

2025-11-23T01:39:56.490 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5fc58c6fab06ca1651cc2f24f6b3294e\dnsapi.dll.mui", hr=0x0

2025-11-23T01:39:56.538 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25101.25.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1025.47515.dll", hr=0x0

2025-11-23T01:39:56.604 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-23T01:39:56.643 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-23T01:39:56.708 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pt-br\msprivs.dll.mui", hr=0x0

2025-11-23T01:39:56.742 Engine:Setting original file name "vcomp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-23T01:39:56.796 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_pt-br_45b1cef334010120_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-23T01:39:56.841 Engine:Setting original file name "DismProvPS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..ing-management-core_31bf3856ad364e35_10.0.26100.7019_none_c721839bdaa557fd\dismcoreps.dll", hr=0x0

2025-11-23T01:39:56.946 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x0

2025-11-23T01:39:56.979 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.efi", hr=0x0

2025-11-23T01:39:56.983 Engine:Setting original file name "ProfSvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-profsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_63afbc426d007f3f_profsvc.dll.mui_32482e9e", hr=0x0

2025-11-23T01:39:57.084 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25101.25.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x0

2025-11-23T01:39:57.088 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2cfe4c864d785675f415b7e6aa962e4\msinfo32.exe.mui", hr=0x0

2025-11-23T01:39:57.287 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\6dfad87d7e49db84e1a96c1c1b32fef6\msidntld.dll.mui", hr=0x0

2025-11-23T01:39:57.302 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7\memtest.exe.mui", hr=0x0

2025-11-23T01:39:57.401 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pa-in_9c6b14ad918eaffd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:57.420 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ar-sa_51090f9ff64b96bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:57.464 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.26100.1_en-us_c94c280205b42295\bubbles.scr.mui", hr=0x0

2025-11-23T01:39:57.685 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\nb-no\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x0

2025-11-23T01:39:57.706 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-console-l1-2-0.dll", hr=0x0

2025-11-23T01:39:57.722 Engine:Setting original file name "SETUP.EXE.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-wow64-legacy.resources_31bf3856ad364e35_10.0.26100.1_nb-no_735ab890ce560efa\setup16.exe.mui", hr=0x0

2025-11-23T01:39:57.869 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x0

2025-11-23T01:39:57.902 Engine:Setting original file name "RarExt.dll" for "c:\program files\winrar\rarext32.dll", hr=0x0

2025-11-23T01:39:57.942 Engine:Setting original file name "pcw.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-pcw_31bf3856ad364e35_10.0.26100.1150_none_4bf8e6d5066a4f9f_pcw.sys_dbeb0bbd", hr=0x0

2025-11-23T01:39:58.034 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\syswow64\nb-no\ieadvpack.dll.mui", hr=0x0

2025-11-23T01:39:58.065 Engine:Setting original file name "EmbyServer.dll" for "c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe", hr=0x0

2025-11-23T01:39:58.162 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-environment-l1-1-0.dll", hr=0x0

2025-11-23T01:39:58.300 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2535f07be6867822893c0bd7f299affd\dwmcore.dll.mui", hr=0x0

2025-11-23T01:39:58.312 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_am-et_12002fbedc3ad139_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:58.351 Engine:Setting original file name "mavinject64.exe" for "c:\windows\winsxs\amd64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_4ed8aae8a286af05\mavinject.exe", hr=0x0

2025-11-23T01:39:58.505 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_b1cb38b404e84204\seclogon.dll.mui", hr=0x0

2025-11-23T01:39:58.549 Engine:Setting original file name "AuditPolicyGP.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\1e37baae98dce76981781b53776e70b9\auditpolicygpinterop.dll.mui", hr=0x0

2025-11-23T01:39:58.626 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9c4e95300400790b8d8a05d9bf7e1f5c\winnlsres.dll.mui", hr=0x0

2025-11-23T01:39:58.637 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e981bfd75ae177a858ec5c78a5cfda25\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-23T01:39:58.694 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-23T01:39:58.875 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ru-ru_e71c93fcf7d6f33e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:58.925 Engine:Setting original file name "qualityupdateassistant" for "c:\windows\system32\qualityupdateassistant.dll", hr=0x0

2025-11-23T01:39:58.937 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ro-ro_2c617f480dd85974_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:59.062 Engine:Setting original file name "wersvc" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2f884580919ab799dbe1ecd0f275799\wersvc.dll.mui", hr=0x0

2025-11-23T01:39:59.144 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_fa-ir_f7555235024374d9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:59.173 Engine:Setting original file name "ClrCompression" for "c:\program files\windowsapps\microsoft.net.native.runtime.1.7_1.7.25531.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-23T01:39:59.214 Engine:Setting original file name "WIASERVC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiaservc.dll.mui_54051b53", hr=0x0

2025-11-23T01:39:59.217 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-23T01:39:59.246 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ru-ru_0752c1c778fe6e7c_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-23T01:39:59.344 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-23T01:39:59.715 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_id-id_6be80829898706a2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:39:59.720 Engine:Setting original file name "STI.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_en-us_d64b3cbf22b2a8d1_sti.dll.mui_00a4f15b", hr=0x0

2025-11-23T01:39:59.727 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9035fe481934c33719e75dea902d1698\bcastdvruserservice.dll.mui", hr=0x0

2025-11-23T01:39:59.750 Engine:Setting original file name "NVIDIA Debug Dump" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvdebugdump.exe", hr=0x0

2025-11-23T01:39:59.768 Engine:Setting original file name "acpiex.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-acpiex_31bf3856ad364e35_10.0.26100.1150_none_d0b1f61a88e2f0e9_acpiex.sys_6a8b9aed", hr=0x0

2025-11-23T01:39:59.784 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_60b47cf61af27adc_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-23T01:39:59.797 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x0

2025-11-23T01:39:59.987 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sv-se_29319a980f7b0983_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-23T01:40:00.081 Engine:Setting original file name "pshed.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-pshed_31bf3856ad364e35_10.0.26100.1_none_633b3602ca01eb94_pshed.dll_f6ac239e", hr=0x0

2025-11-23T01:40:00.170 Engine:Setting original file name "ClipSVC.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-client-li..m-service.resources_31bf3856ad364e35_10.0.26100.1_en-us_3f436cbd520195fd_clipsvc.dll.mui_18823613", hr=0x0

2025-11-23T01:40:00.191 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_cy-gb_976c80cbdb5c65c1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:00.395 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_uk-ua_c5d15aec526b5235_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:00.456 Engine:Setting original file name "msfltr32.acm" for "c:\windows\winsxs\wow64_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_10.0.26100.1_none_e82ddbd17df6cb5b\msacm32.dll", hr=0x0

2025-11-23T01:40:00.507 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-23T01:40:00.521 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-23T01:40:00.569 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_6dcfa7c5391fe7a2_dnsapi.dll.mui_97465f8a", hr=0x0

2025-11-23T01:40:00.699 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_3cda2262e7ef70ab_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:00.799 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_10.0.26100.7171_none_f70fffd91c8f0404\winload.exe", hr=0x0

2025-11-23T01:40:00.945 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_et-ee_9786a4bcaafec5cb_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:01.213 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files\mozilla firefox\dxcompiler.dll", hr=0x0

2025-11-23T01:40:01.279 Engine:Setting original file name "Device_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\device\nb-no\edb83efa185c0a23d97fafe6a71cd608\diagpackage.dll.mui", hr=0x0

2025-11-23T01:40:01.298 Engine:Setting original file name "rtutils.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasrtutils_31bf3856ad364e35_10.0.26100.3037_none_a90518339a5ed736_rtutils.dll_243724ab", hr=0x0

2025-11-23T01:40:01.410 Engine:Setting original file name "udiapi.dll" for "c:\windows\system32\udiapiclient.dll", hr=0x0

2025-11-23T01:40:01.431 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-23T01:40:01.488 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaidvc.dll", hr=0x0

2025-11-23T01:40:01.493 Engine:Setting original file name "DWrite" for "c:\windows\winsxs\amd64_microsoft-windows-directwrite.resources_31bf3856ad364e35_10.0.26100.1_en-us_8e75f00536c95f8c\dwrite.dll.mui", hr=0x0

2025-11-23T01:40:01.500 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\windows\syswow64\nb-no\mfc40u.dll.mui", hr=0x0

2025-11-23T01:40:01.620 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.26100.1_en-us_12a038f1fa40c367_wlrmdr.exe.mui_ee563c83", hr=0x0

2025-11-23T01:40:01.717 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.xaml.winmd", hr=0x0

2025-11-23T01:40:01.789 Engine:Setting original file name "raspptp.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasbase-raspptp_31bf3856ad364e35_10.0.26100.1882_none_358d932997f7087d_raspptp.sys_25e89db1", hr=0x0

2025-11-23T01:40:01.880 Engine:Setting original file name "l3codec.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\17e7113a56f3171dc40844c9d3ee9e47\l3codeca.acm.mui", hr=0x0

2025-11-23T01:40:01.911 Engine:Setting original file name "bridgeres.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-networkbridge_31bf3856ad364e35_10.0.26100.2454_none_a3b07853b6183928_bridgeres.dll_55e40455", hr=0x0

2025-11-23T01:40:02.142 Engine:Setting original file name "mf.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..oundation.resources_31bf3856ad364e35_10.0.26100.1_en-us_8b9cc1ab2476fea1\mfpmp.exe.mui", hr=0x0

2025-11-23T01:40:02.230 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-processthreads-l1-1-1.dll", hr=0x0

2025-11-23T01:40:02.294 Engine:Setting original file name "FreeImage.dll" for "c:\program files (x86)\steam\steamapps\common\wallpaper_engine\bin\freeimage64.dll", hr=0x0

2025-11-23T01:40:02.299 Engine:Setting original file name "tier0_s.dll" for "c:\program files (x86)\steam\tier0_s64.dll", hr=0x0

2025-11-23T01:40:02.315 Engine:Setting original file name "nvaudcap.dll" for "c:\windows\syswow64\nvaudcap32v.dll", hr=0x0

2025-11-23T01:40:02.350 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mi-nz_b80bad72b6b0ee53_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:02.376 Engine:Setting original file name "CertCli" for "c:\windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_10.0.26100.1_en-us_61b2ff4b086153b8\certcli.dll.mui", hr=0x0

2025-11-23T01:40:02.380 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\en-us\wsepno.dll.mui", hr=0x0

2025-11-23T01:40:02.404 Engine:Setting original file name "ConfigurationRemotingServer.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\configurationremotingserver.exe", hr=0x0

2025-11-23T01:40:02.414 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_sr-..-rs_e67ffd847af5d250_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:02.417 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\power\en-us\diagpackage.dll.mui", hr=0x0

2025-11-23T01:40:02.440 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay8-payload_31bf3856ad364e35_1.0.26100.4202_none_bb7ce817a226517c\dpnaddr.dll", hr=0x0

2025-11-23T01:40:02.673 Engine:Setting original file name "msfltr32.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8836c193640d589410b5cc3dbe67e146\msacm32.dll.mui", hr=0x0

2025-11-23T01:40:02.756 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_6a24110114ad15ad_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-23T01:40:02.778 Engine:Setting original file name "usk.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\7c8e526d244ad657f882f8bbba0149ec\usk.rs.mui", hr=0x0

2025-11-23T01:40:02.788 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-23T01:40:02.808 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay4-payload_31bf3856ad364e35_1.0.26100.4202_none_186a372066698d60\dpmodemx.dll", hr=0x0

2025-11-23T01:40:02.988 Engine:Setting original file name "Register-CimProvider2.exe.mui" for "c:\windows\syswow64\en-us\register-cimprovider.exe.mui", hr=0x0

2025-11-23T01:40:03.078 Engine:Setting original file name "metabase.dll.mui" for "c:\windows\winsxs\wow64_microsoft-windows-iis-metabase.resources_31bf3856ad364e35_10.0.26100.1_en-us_8ff50fedc8451a7b\metadata.dll.mui", hr=0x0

2025-11-23T01:40:03.081 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x0

2025-11-23T01:40:03.162 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_de-de_ab2a1f0520f5ef2b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:03.223 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_6fced6fbf4c0e3e0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:03.343 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\en-us\diagpackage.dll.mui", hr=0x0

2025-11-23T01:40:03.362 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_7478bb53490dd7a8_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-23T01:40:03.414 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\windows\system32\nb-no\msidntld.dll.mui", hr=0x0

2025-11-23T01:40:03.419 Engine:Setting original file name "glu32" for "c:\windows\winsxs\amd64_microsoft-windows-opengl.resources_31bf3856ad364e35_10.0.26100.1_en-us_9c3b296d3d668ac3\glu32.dll.mui", hr=0x0

2025-11-23T01:40:03.442 Engine:Setting original file name "mf.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mediafoundation_31bf3856ad364e35_10.0.26100.7171_none_384874e2bca9ce3f\mfpmp.exe", hr=0x0

2025-11-23T01:40:03.465 Engine:Setting original file name "msedgeupdate.dll" for "c:\program files (x86)\microsoft\edgeupdate\1.3.207.5\microsoftedgeupdateondemand.exe", hr=0x0

2025-11-23T01:40:03.478 Engine:Setting original file name "scesrv" for "c:\windows\system32\nb-no\scesrv.dll.mui", hr=0x0

2025-11-23T01:40:03.491 Engine:Setting original file name "DWWIN" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ae2b7dc24859d1fa2a509d5b642451b4\dwwin.exe.mui", hr=0x0

2025-11-23T01:40:03.637 Engine:Setting original file name "nvcuvid.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcuvid64.dll", hr=0x0

2025-11-23T01:40:03.672 Engine:Setting original file name "AppHostNameRegistrationVerifier.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\baf91a75f57ca8730dd9a6f926a58dd0\apphostregistrationverifier.exe.mui", hr=0x0

2025-11-23T01:40:03.683 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_en-gb_9672c12aaba943d2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:03.812 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-rtlsupport-l1-1-0.dll", hr=0x0

2025-11-23T01:40:03.831 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-23T01:40:03.859 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_gu-in_97d53b15f69aaeca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:03.904 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_84875939fc6b99b1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:03.933 Engine:Setting original file name "ServDeps.exe.mui" for "c:\windows\syswow64\wbem\nb-no\servdeps.dll.mui", hr=0x0

2025-11-23T01:40:03.969 Engine:Setting original file name "schtasks.exe" for "c:\windows\winsxs\amd64_microsoft-windows-sctasks_31bf3856ad364e35_10.0.26100.6725_none_25e27f3a6574108c\schtasks.exe", hr=0x0

2025-11-23T01:40:03.979 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_e38364b045f31518_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:04.031 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_el-gr_b382575af3d00da3_memtest.efi.mui_71e15c22", hr=0x0

2025-11-23T01:40:04.190 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.26100.1_en-us_0e875971ea5fda56\ieadvpack.dll.mui", hr=0x0

2025-11-23T01:40:04.231 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-datetime-l1-1-0.dll", hr=0x0

2025-11-23T01:40:04.253 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-23T01:40:04.300 Engine:Setting original file name "user32" for "c:\windows\system32\user32.dll", hr=0x0

2025-11-23T01:40:04.371 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.642.119.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-23T01:40:04.382 Engine:Setting original file name "shutdownui" for "c:\windows\winsxs\amd64_microsoft-windows-shutdownext.resources_31bf3856ad364e35_10.0.26100.1_en-us_9bd0f22e3578c871\shutdownext.dll.mui", hr=0x0

2025-11-23T01:40:04.530 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4\memtest.exe.mui", hr=0x0

2025-11-23T01:40:04.570 Engine:Setting original file name ".NET Host Resolver - 8.0.20" for "c:\users\serverpc\appdata\local\temp\emby-server-updater\hostfxr.dll", hr=0x0

2025-11-23T01:40:04.588 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_bs-..-ba_3017f7e2648d7e73_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:04.666 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_quz-pe_0266e81632046792_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:04.765 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lb-lu_cb546bb0b0d79a98_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:04.800 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\amd64_microsoft-windows-a..perience-ait-static_31bf3856ad364e35_10.0.26100.7019_none_ccd1f49f5e2b3b28\aitstatic.exe", hr=0x0

2025-11-23T01:40:04.897 Engine:Setting original file name "UNPShared.dll" for "c:\windows\winsxs\amd64_microsoft-windows-update-upshared_31bf3856ad364e35_10.0.26100.5074_none_29764f36135e6d4c\upshared.dll", hr=0x0

2025-11-23T01:40:04.968 Engine:Setting original file name "messagin.dll" for "c:\program files\bitdefender agent\27.1.1.23\messaging.dll", hr=0x0

2025-11-23T01:40:05.044 Engine:Setting original file name "WindowsCodecs" for "c:\windows\syswow64\windowscodecs.dll", hr=0x0

2025-11-23T01:40:05.078 Engine:Setting original file name "WerMgr" for "c:\windows\system32\wermgr.exe", hr=0x0

2025-11-23T01:40:05.124 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d\memtest.exe.mui", hr=0x0

2025-11-23T01:40:05.127 Engine:Setting original file name "imapi.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bd7c223153b9576fe4c4e66ebf1c6ece\imapi.dll.mui", hr=0x0

2025-11-23T01:40:05.246 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hi-in_8555c5797fc8795e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:05.313 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\esrb.rs.mui", hr=0x0

2025-11-23T01:40:05.398 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-23T01:40:05.418 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_zh-tw_ff4ad39908e2da78_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:05.422 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-23T01:40:05.469 Engine:Setting original file name "microsoftedgedevtools.exe" for "c:\windows\system32\microsoftedgecp.exe", hr=0x0

2025-11-23T01:40:05.489 Engine:Setting original file name "la57setup.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ec428185df2994f7d7954c1efe1b2738\la57setup.exe.mui", hr=0x0

2025-11-23T01:40:05.495 Engine:Setting original file name "wuapi.dll" for "c:\windows\uus\x86\wuapicore.dll", hr=0x0

2025-11-23T01:40:05.573 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\system32\en-us\dsprop.dll.mui", hr=0x0

2025-11-23T01:40:05.676 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-23T01:40:05.695 Engine:Setting original file name "etweseproviderresources.dll" for "c:\windows\winsxs\backup\amd64_microsoft-etw-ese_31bf3856ad364e35_10.0.26100.1_none_cc4e7afeeee8d3b1_etweseproviderresources.dll_f21e8ea7", hr=0x0

2025-11-23T01:40:05.759 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_2821a024e044bada_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:05.761 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-23T01:40:05.798 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bf8ce2a53903d9e6d302aee07de95dd9\mfc40u.dll.mui", hr=0x0

2025-11-23T01:40:05.810 Engine:Setting original file name "TAPISRV.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-tapiservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_83c985f74a352be9\tapisrv.dll.mui", hr=0x0

2025-11-23T01:40:05.985 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lo-la_099683f3cb70d44f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:05.988 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x0

2025-11-23T01:40:06.076 Engine:Setting original file name "wininet.dll" for "c:\windows\systemresources\wininet.dll.mun", hr=0x0

2025-11-23T01:40:06.104 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\nb-no\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x0

2025-11-23T01:40:06.129 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_hu-hu_9dd052ebcaf187fd_memtest.efi.mui_71e15c22", hr=0x0

2025-11-23T01:40:06.132 Engine:Setting original file name "PrintBrmEng.exe.mui" for "c:\windows\system32\spool\tools\en-us\printbrmengine.exe.mui", hr=0x0

2025-11-23T01:40:06.133 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_it-it_4087c8eabdc39e5f_memtest.efi.mui_71e15c22", hr=0x0

2025-11-23T01:40:06.164 Engine:Setting original file name "audioadg.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f411807b0749e7d602e77baf3c1c4e60\audiodg.exe.mui", hr=0x0

2025-11-23T01:40:06.231 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x0

2025-11-23T01:40:06.303 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-t..iprovider.resources_31bf3856ad364e35_10.0.26100.1_en-us_41b711b4f2db4fe7\rdpsign.exe.mui", hr=0x0

2025-11-23T01:40:06.427 Engine:Setting original file name "Video_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\video\nb-no\2ca5a0690699da595bd35a22420a1c04\diagpackage.dll.mui", hr=0x0

2025-11-23T01:40:06.435 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-23T01:40:06.456 Engine:Setting original file name "FvSDKTestClientPublic" for "c:\program files\nvidia corporation\frameviewsdk\sdk\fvsdktestclient_public.exe", hr=0x0

2025-11-23T01:40:06.497 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\qps-ploc\msprivs.dll.mui", hr=0x0

2025-11-23T01:40:06.499 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-23T01:40:06.606 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\windows\system32\nb-no\pnpclean.dll.mui", hr=0x0

2025-11-23T01:40:06.617 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_or-in_f89501f89f876dc5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:06.646 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.26100.7171_none_4ad020869b677502\taskmgr.exe.mun", hr=0x0

2025-11-23T01:40:06.695 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_ca98740be1962356_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:06.748 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x0

2025-11-23T01:40:06.801 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_it-it_f0fca0072ba86c5a\msprivs.dll.mui", hr=0x0

2025-11-23T01:40:06.842 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps-ploc_7ccda1c46b445ed4\memtest.exe.mui", hr=0x0

2025-11-23T01:40:06.858 Engine:Setting original file name "NETBIOS.SYS" for "c:\windows\winsxs\backup\amd64_microsoft-windows-netbios_31bf3856ad364e35_10.0.26100.1_none_56d5608ad3abe945_netbios.sys_6f23c4df", hr=0x0

2025-11-23T01:40:06.911 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-process-l1-1-0.dll", hr=0x0

2025-11-23T01:40:07.036 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\systemresources\etwcoreuicomponentsresources.dll.mun", hr=0x0

2025-11-23T01:40:07.048 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pt-br_55b72b827c87f88f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:07.160 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_0dc0948c02e4507b_memtest.efi.mui_71e15c22", hr=0x0

2025-11-23T01:40:07.173 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mt-mt_b4ebaa02b8bfece3_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:07.204 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.devices.winmd", hr=0x0

2025-11-23T01:40:07.242 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_576ce8a1070e9744_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:07.253 Engine:Setting original file name "FileInfo.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-fileinfominifilter_31bf3856ad364e35_10.0.26100.1150_none_729c4b9be137bb96_fileinfo.sys_9be2dfcd", hr=0x0

2025-11-23T01:40:07.327 Engine:Setting original file name "aclui.dll" for "c:\windows\winsxs\amd64_microsoft-windows-aclui_31bf3856ad364e35_10.0.26100.7019_none_f0f7bbb4638cf785\aclui.dll.mun", hr=0x0

2025-11-23T01:40:07.332 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\73be2921551d\apex_fieldsamplerchecked_x86.dll", hr=0x0

2025-11-23T01:40:07.385 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.777.2143.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-23T01:40:07.442 Engine:Setting original file name "qualityupdateassistant" for "c:\program files\microsoft update health tools\qualityupdateassistant.dll", hr=0x0

2025-11-23T01:40:07.470 Engine:Setting original file name "NVPPE.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvppex.dll", hr=0x0

2025-11-23T01:40:07.547 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_en-us_4761fcc7ecd6d884_winresume.efi.mui_f412814e", hr=0x0

2025-11-23T01:40:07.723 Engine:Setting original file name "NVPrxy.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvprxy32.dll", hr=0x0

2025-11-23T01:40:07.823 Engine:Setting original file name "Mystify" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\589bec7339e102473dc7566c3b9b0f45\mystify.scr.mui", hr=0x0

2025-11-23T01:40:07.846 Engine:Setting original file name "volmgrx.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..memanager.resources_31bf3856ad364e35_10.0.26100.1_en-us_a18734abf077f9b4_volmgrx.sys.mui_b0c205d7", hr=0x0

2025-11-23T01:40:07.882 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-23T01:40:07.983 Engine:Setting original file name "libcrypto" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\libcrypto-3-x64.dll", hr=0x0

2025-11-23T01:40:08.006 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-string-l1-1-0.dll", hr=0x0

2025-11-23T01:40:08.039 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hi-in_83227505fd46a5bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:08.079 Engine:Setting original file name "CertCa" for "c:\windows\winsxs\amd64_microsoft-windows-c..ertca-dll.resources_31bf3856ad364e35_10.0.26100.1_nb-no_25e015431023bb9b\certca.dll.mui", hr=0x0

2025-11-23T01:40:08.179 Engine:Setting original file name "PCW_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_ddc581f4a364804b\diagpackage.dll.mui", hr=0x0

2025-11-23T01:40:08.264 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..subsystem.resources_31bf3856ad364e35_10.0.26100.1_nb-no_ab8620bc0ed41a36\scardsvr.dll.mui", hr=0x0

2025-11-23T01:40:08.282 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_6.0.3624.51421.dll", hr=0x0

2025-11-23T01:40:08.359 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-23T01:40:08.392 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_06d4a9c0547686dc\msprivs.dll.mui", hr=0x0

2025-11-23T01:40:08.541 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mapi_31bf3856ad364e35_10.0.26100.7019_none_473a9ee5c9a5ebee\mapistub.dll", hr=0x0

2025-11-23T01:40:08.657 Engine:Setting original file name "mofcomp.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_nb-no_8c87dcbbb8114be3_mofcomp.exe.mui_35badf56", hr=0x0

2025-11-23T01:40:08.661 Engine:Setting original file name "MspsProv.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..oning-wmi.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd6de3cbb42de1cb\mspsprov.dll.mui", hr=0x0

2025-11-23T01:40:08.710 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x0

2025-11-23T01:40:08.802 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.26100.7019_none_4a484d6501b73a17\wwanapi.dll", hr=0x0

2025-11-23T01:40:08.869 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ne-np_591939d32e7d4223_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:08.940 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.xboxidentityprovider_12.130.16001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-23T01:40:09.101 Engine:Setting original file name "Operativsystemet Microsoft� Windows�" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e2a170892be5347a116ae0806fb5309d\pcalua.exe.mui", hr=0x0

2025-11-23T01:40:09.174 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x0

2025-11-23T01:40:09.189 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x0

2025-11-23T01:40:09.463 Engine:Setting original file name "imageres.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-imageres_31bf3856ad364e35_10.0.26100.1_none_d9b14b936072a0bc\imageres.dll.mun", hr=0x0

2025-11-23T01:40:09.677 Engine:Setting original file name "vcruntime140.dll" for "c:\config.msi\1c742.rbf", hr=0x0

2025-11-23T01:40:09.716 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-23T01:40:09.755 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_kk-kz_71b9c9e0d19e9ee0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:09.940 Engine:Setting original file name "Apps_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\apps\nb-no\d2a92c7cfed83dc547a21508b5b0ea0f\diagpackage.dll.mui", hr=0x0

2025-11-23T01:40:09.956 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32.dll", hr=0x0

2025-11-23T01:40:10.007 Engine:Setting original file name "CertPKICmdlet" for "c:\windows\system32\en-us\certpkicmdlet.dll.mui", hr=0x0

2025-11-23T01:40:10.070 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ed4232cecc06e9efb72d2a7c142b63b4\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x0

2025-11-23T01:40:10.080 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.424.1611.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-23T01:40:10.137 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_0cb2119581e88ce0\diagpackage.dll.mui", hr=0x0

2025-11-23T01:40:10.303 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\system32\bcp47langs.dll", hr=0x0

2025-11-23T01:40:10.370 Engine:Setting original file name "gpapi.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-g..licy-base.resources_31bf3856ad364e35_10.0.26100.1_en-us_be2843fbd972ca37_gpapi.dll.mui_ef0a9748", hr=0x0

2025-11-23T01:40:10.373 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-math-l1-1-0.dll", hr=0x0

2025-11-23T01:40:10.425 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x0

2025-11-23T01:40:10.434 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\winsxs\amd64_microsoft-windows-aerolite.resources_31bf3856ad364e35_10.0.26100.1_en-us_bc993ceae8fc48bf\aerolite.msstyles.mui", hr=0x0

2025-11-23T01:40:10.711 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\en-us\utilman.exe.mui", hr=0x0

2025-11-23T01:40:10.850 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x0

2025-11-23T01:40:10.957 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-23T01:40:10.965 Engine:Setting original file name "sqlite3" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\sqlite3.dll", hr=0x0

2025-11-23T01:40:11.027 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x0

2025-11-23T01:40:11.071 Engine:Setting original file name "w32time.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-time-tool.resources_31bf3856ad364e35_10.0.26100.1_en-us_7b897a2738f484fc\w32tm.exe.mui", hr=0x0

2025-11-23T01:40:11.075 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd473133072db5bb\diagpackage.dll.mui", hr=0x0

2025-11-23T01:40:11.100 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_80a1d04cb31f8eca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:11.104 Engine:Setting original file name "ERC" for "c:\windows\system32\nb-no\wercplsupport.dll.mui", hr=0x0

2025-11-23T01:40:11.137 Engine:Setting original file name "vdsutil.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-v..skservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_59d12af3dce743c1_vdsutil.dll.mui_0caf9b0e", hr=0x0

2025-11-23T01:40:11.220 Engine:Setting original file name "AppLockerCSP.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appidcore.resources_31bf3856ad364e35_10.0.26100.1_en-us_564c6ad9b132641f_applockercsp.dll.mui_d2a0df70", hr=0x0

2025-11-23T01:40:11.275 Engine:Setting original file name "dnsrslvr.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570_dnsrslvr.dll.mui_1e1a1ed1", hr=0x0

2025-11-23T01:40:11.339 Engine:Setting original file name "PSAPI" for "c:\windows\winsxs\backup\wow64_microsoft-windows-basedependencies_31bf3856ad364e35_10.0.26100.1_none_09ea4476c5bcc4c0_psapi.dll_e8b5b4d1", hr=0x0

2025-11-23T01:40:11.364 Engine:Setting original file name "AcPlugin.dll" for "c:\program files\windowsapps\microsoft.applicationcompatibilityenhancements_1.2511.9.0_x64__8wekyb3d8bbwe\amd64\acplugin_test.dll", hr=0x0

2025-11-23T01:40:11.374 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\426c2b1101abec586136a4bbd67a716e\narrator.exe.mui", hr=0x0

2025-11-23T01:40:11.388 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..tiator_ui.resources_31bf3856ad364e35_10.0.26100.1_en-us_7967a83a130d426e\iscsicpl.dll.mui", hr=0x0

2025-11-23T01:40:11.475 Engine:Setting original file name "WindowsMediaPlayerPlayDVD_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_587c1f8aa98a4a71\diagpackage.dll.mui", hr=0x0

2025-11-23T01:40:11.646 Engine:Setting original file name "scecli" for "c:\windows\system32\nb-no\scecli.dll.mui", hr=0x0

2025-11-23T01:40:11.664 Engine:Setting original file name "scesrv" for "c:\windows\winsxs\amd64_microsoft-windows-s..ionengine.resources_31bf3856ad364e35_10.0.26100.1_en-us_e63bd45b831a32e3\scesrv.dll.mui", hr=0x0

2025-11-23T01:40:11.693 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_bg-bg_af9bba51d24fbf0e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:11.750 Engine:Setting original file name "nvhda.sys" for "c:\windows\system32\driverstore\filerepository\nvhda.inf_amd64_c32d8360d192a82e\nvhda64v.sys", hr=0x0

2025-11-23T01:40:11.762 Engine:Setting original file name "wmiutils.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiutils.dll.mui_42583eaf", hr=0x0

2025-11-23T01:40:11.776 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_te-in_e10bae4a47776b9f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:11.804 Engine:Setting original file name "BdncProxy.dll" for "c:\program files\bitdefender agent\27.1.1.23\crash_handler\bdnc.dll", hr=0x0

2025-11-23T01:40:11.875 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.26100.1_nb-no_e175a2f7bf27ee8d_ws2ifsl.sys.mui_b672c7b4", hr=0x0

2025-11-23T01:40:11.937 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_eu-es_e55e702bbb854a24_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:11.971 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-msinfo32-exe.resources_31bf3856ad364e35_10.0.26100.1_en-us_53ae64398a08feba\msinfo32.exe.mui", hr=0x0

2025-11-23T01:40:12.020 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-23T01:40:12.115 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x86__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-23T01:40:12.135 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x0

2025-11-23T01:40:12.229 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x0

2025-11-23T01:40:12.236 Engine:Setting original file name "NxCooking.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\v2.7.6\physxcooking.dll", hr=0x0

2025-11-23T01:40:12.265 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-23T01:40:12.398 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x0

2025-11-23T01:40:12.471 Engine:Setting original file name "filterLib.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\4fffc8576907b0b5da815790887fb244\fltlib.dll.mui", hr=0x0

2025-11-23T01:40:12.499 Engine:Setting original file name "srpuxgp.dll" for "c:\windows\systemresources\srpuxnativesnapin.dll.mun", hr=0x0

2025-11-23T01:40:12.502 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-23T01:40:12.687 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_nl-nl_0d26e65c98dbf6f7_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:12.696 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sl-si_8549ba61ed8af84b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:12.701 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x0

2025-11-23T01:40:12.864 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_pl-pl_9d43c82914fc6152_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:12.885 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.web.winmd", hr=0x0

2025-11-23T01:40:12.947 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-23T01:40:13.059 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ca-es_584cefb2c144b7d8_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:13.068 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\winsxs\amd64_microsoft-windows-qedwipes_31bf3856ad364e35_10.0.26100.1_none_5473011012d79dc1\qedwipes.dll.mun", hr=0x0

2025-11-23T01:40:13.228 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_et-ee_4da61d721400c924_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:13.269 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_fb2fbffb5205c552_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:13.486 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..xe-common.resources_31bf3856ad364e35_10.0.26100.1_en-us_58b62bf54b9ae38a\msinfo32.exe.mui", hr=0x0

2025-11-23T01:40:13.603 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.70.1338.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-23T01:40:13.607 Engine:Setting original file name "netcfgx.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-tcpip.resources_31bf3856ad364e35_10.0.26100.1_en-us_c93621b935b09922_tcpipcfg.dll.mui_a5479fc1", hr=0x0

2025-11-23T01:40:13.655 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_f4c1513bcd79893e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:13.698 Engine:Setting original file name "nvxdsync.exe" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\session\nvxdsyncplugin.dll", hr=0x0

2025-11-23T01:40:13.846 Engine:Setting original file name "ReShade" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\reshadefxc64.exe", hr=0x0

2025-11-23T01:40:13.891 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-23T01:40:13.933 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_0fbfb1c9f2926e3e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:13.962 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\power\nb-no\2803551e72f3605cc0b181750700647e\diagpackage.dll.mui", hr=0x0

2025-11-23T01:40:14.023 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_th-th_25ee4fb15dc2e739_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:14.029 Engine:Setting original file name "Umpo.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-u..erservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_a887c532823d0a08_umpo.dll.mui_cac12e54", hr=0x0

2025-11-23T01:40:14.032 Engine:Setting original file name "bootres" for "c:\windows\boot\resources\nb-no\bootres.dll.mui", hr=0x0

2025-11-23T01:40:14.054 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\b74f41bc269d13282681d018820fb031\ddores.dll.mui", hr=0x0

2025-11-23T01:40:14.076 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x0

2025-11-23T01:40:14.085 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\mscordaccore_amd64_amd64_8.0.2125.47513.dll", hr=0x0

2025-11-23T01:40:14.111 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-namedpipe-l1-1-0.dll", hr=0x0

2025-11-23T01:40:14.207 Engine:Setting original file name "dxmasf.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_10.0.26100.7019_none_b1abcb083360b859\msdxm.ocx", hr=0x0

2025-11-23T01:40:14.331 Engine:Setting original file name "Bubbles" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ee15dd2b573766654f76694ac2f468d4\bubbles.scr.mui", hr=0x0

2025-11-23T01:40:14.372 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_tr-tr_2c24c8b8ddbbff8a_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:14.394 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_es-mx_9dca765f230af946_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-23T01:40:14.416 Engine:Setting original file name "CUDART64_65_19.DLL" for "c:\program files (x86)\nvidia corporation\physx\common\cudart64_65.dll", hr=0x0

2025-11-23T01:40:14.433 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-errorhandling-l1-1-0.dll", hr=0x0

2025-11-23T01:40:14.558 Engine:Setting original file name "wcp.dll" for "c:\windows\system32\ssshim.dll", hr=0x0

2025-11-23T01:40:14.654 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.exe", hr=0x0

2025-11-23T01:40:14.690 OriginalFileName Maintenance::11309 files in Moac, 0 skipped (cached), 431 filename set

2025-11-23T01:40:14.690 [AutoPurge] Routine task for Cache Maintenance has ended.

Internal signature match:subtype=Lowfi, sigseq=0x0000157E64CB44FC, sigsha=7c0b559aa2db6c78a415037aa029894b41e6d3eb, cached=false, source=2, resourceid=0xa305d829

Internal signature match:subtype=Lowfi, sigseq=0x0000157E438D3445, sigsha=8ae8752b953590c958b0c8f046232237ead1313e, cached=false, source=2, resourceid=0xa305d829

Internal signature match:subtype=Lowfi, sigseq=0x0000157E44D6FE51, sigsha=57c5b33aed8fd23766000a3467a65f287bda9f45, cached=false, source=2, resourceid=0xa305d829

Internal signature match:subtype=Lowfi, sigseq=0x0000157E4BE8B987, sigsha=a147a1bd4255971ce0ff7ec275b37724ba8bd537, cached=false, source=2, resourceid=0xa305d829

Internal signature match:subtype=Lowfi, sigseq=0x0000157E62DAF59A, sigsha=412bb4ad89051211df5fa9b2f63557d107875d94, cached=false, source=2, resourceid=0xa305d829

Internal signature match:subtype=Lowfi, sigseq=0x0000157EEDC1FDAA, sigsha=957d8fbfe7987111d93ac432453760da86bb5a7d, cached=false, source=2, resourceid=0xa305d829

2025-11-23T01:48:04.044 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #215757, FileId: 0x1cd000000018e22, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T01:52:06.226 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #215852, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T01:52:06.228 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #215853, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T01:52:16.235 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #215860, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T01:52:16.242 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #215861, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T01:52:28.985 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T02:03:05.448 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #216181, FileId: 0x91000000019635, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T02:07:09.498 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

2025-11-23T02:07:09.508 [DLP] DlpEngineConfigStorage::OnConfigChange DlpDwordSettingsMap:

2025-11-23T02:07:09.508 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-23T02:07:09.508 [RTP] Duplicating the current plugin configuration object...

2025-11-23T02:07:09.508 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-23T02:07:09.508 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-23T02:07:09.508 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-23T02:07:09.508 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-23T02:07:09.508 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-23T02:07:09.508 [RTP] No config change detected. Not updating plugin configuration.

2025-11-23T02:07:09.508 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-23T02:07:09.508 [RTP] No config changes found. No configuration switch.

2025-11-23T02:07:09.508 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-23T02:07:09.508 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-23T02:07:09.508 [RTP] [RtpConfig] Config change detected, type: 16

2025-11-23T02:07:09.509 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-23T02:07:09.509 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-23T02:07:09.509 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-23T02:07:09.509 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-23T02:07:09.509 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-23T02:07:09.509 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-23T02:07:09.509 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-23T02:07:09.509 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-23T02:07:09.509 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-23T02:07:09.509 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-23T02:07:09.509 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-23T02:07:09.509 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-23T02:07:09.509 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-23T02:07:09.509 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-23T02:07:09.509 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T02:07:09.511 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T02:07:09.512 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T02:07:09.514 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T02:07:09.515 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T02:07:09.516 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 1990959(ms) from now at 03:40 (02:40 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-23T02:07:12.047 [RTP] Duplicating the current plugin configuration object...

2025-11-23T02:07:12.047 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-23T02:07:12.047 [RTP] Updating plugin configuration due to recent config changes (0x41e) ...

2025-11-23T02:07:12.047 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-23T02:07:12.049 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x218

2025-11-23T02:07:33.974 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T02:07:42.951 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #216745, FileId: 0xe8000000015fd2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T02:17:23.329 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1503, Count: 81, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 85%

2025-11-23T02:17:23.329 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 1259, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\1999a338-d17c-473c-8625-cb2703c27ebb.tmp, EstimatedImpact: 0%

2025-11-23T02:17:23.329 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 1257, Count: 86, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\20a096e0-54de-49c9-bb8f-0cb5c7ddb332.tmp, EstimatedImpact: 0%

2025-11-23T02:17:23.329 ProcessImageName: RuntimeBroker.exe, Pid: 8636, TotalTime: 557, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-23T02:17:23.329 ProcessImageName: RuntimeBroker.exe, Pid: 26444, TotalTime: 557, Count: 21, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 36%

2025-11-23T02:17:23.329 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 556, Count: 123, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 75%

2025-11-23T02:17:23.329 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 405, Count: 89, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Data\7a\7ade6a69fe708f6b69ee17d11aa7016ae7cd0e30.file, EstimatedImpact: 0%

2025-11-23T02:17:23.329 ProcessImageName: taskhostw.exe, Pid: 26616, TotalTime: 271, Count: 43, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\UCPD.sys, EstimatedImpact: 15%

2025-11-23T02:17:23.329 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 225, Count: 48, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-23T02:17:23.329 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 121, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T02:17:23.329 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-23T02:17:23.329 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-23T02:17:23.329 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 62, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\Temp\DO757E.tmp, EstimatedImpact: 11%

2025-11-23T02:17:23.329 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-23T02:17:23.329 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-23T02:17:23.329 ProcessImageName: taskhostw.exe, Pid: 4676, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-23T02:17:23.330 ProcessImageName: taskhostw.exe, Pid: 25796, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-23T02:17:23.330 ProcessImageName: updater.exe, Pid: 22512, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-23T02:17:23.330 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0D1686C3FBB7F7352C5A7B6BA00CB0A6, EstimatedImpact: 0%

2025-11-23T02:17:23.330 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-23T02:17:23.330 ProcessImageName: HxTsr.exe, Pid: 20900, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22342.0_neutral_nb-no_8wekyb3d8bbwe\resources.pri, EstimatedImpact: 7%

2025-11-23T02:17:23.330 ProcessImageName: Spotify.exe, Pid: 17104, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-23T02:17:23.330 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-23T02:18:06.974 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #216842, FileId: 0x13d000000019960, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T02:22:38.977 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T02:33:08.453 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #216992, FileId: 0x55000000019a6f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T02:37:43.973 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T02:48:08.745 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #217300, FileId: 0x149000000019278, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T02:52:07.335 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #217337, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T02:52:07.339 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #217338, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T02:52:17.338 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #217343, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T02:52:17.342 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #217344, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T02:52:48.962 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T03:03:09.049 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #217553, FileId: 0x1b3000000019856, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T03:07:53.961 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T03:18:09.382 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #217921, FileId: 0x1a000000015e5b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T03:22:58.946 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T03:28:28.459 Bm signature throttled:0x0000fab3228bcd4d

2025-11-23T03:33:09.697 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #217998, FileId: 0xec000000019749, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T03:38:03.940 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T03:48:09.755 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #218127, FileId: 0x1c5000000018c39, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T03:52:06.333 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #218166, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T03:52:06.340 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #218167, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T03:52:16.347 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #218176, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T03:52:16.351 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #218177, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T03:53:08.948 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T03:57:36.912 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\C39F5477-0C4A-4E93-990D-2AF9EE3353AF1fdc.1dc5c2d4d4c6ec2

2025-11-23T03:57:36.943 Verifying engine and signature files (source: 0) ...

2025-11-23T03:57:36.943 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6203A63D-406D-42D6-AE00-6D2ACB19734C}\mpengine.dll] due to PPL.

2025-11-23T03:57:36.943 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6203A63D-406D-42D6-AE00-6D2ACB19734C}\mpasbase.vdm] (file in cache)

2025-11-23T03:57:36.943 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6203A63D-406D-42D6-AE00-6D2ACB19734C}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-23T03:57:36.953 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6203A63D-406D-42D6-AE00-6D2ACB19734C}\mpasdlta.vdm]

2025-11-23T03:57:36.953 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6203A63D-406D-42D6-AE00-6D2ACB19734C}\mpavbase.vdm] (file in cache)

2025-11-23T03:57:36.953 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6203A63D-406D-42D6-AE00-6D2ACB19734C}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-23T03:57:36.961 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6203A63D-406D-42D6-AE00-6D2ACB19734C}\mpavdlta.vdm]

2025-11-23T03:57:37.034 [Engine] IsHybridMode: 0

2025-11-23T03:57:37.035 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-23T03:57:37.044 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-2B14F84B0408EE14E89657793C21B667E54D0F05.bin): 0x00000002

2025-11-23T03:57:37.046 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-2B14F84B0408EE14E89657793C21B667E54D0F05.bin)

2025-11-23T03:57:37.046 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-23T03:57:37.046 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-23T03:57:37.046 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-23T03:57:37.046 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-23T03:57:42.471 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-23T03:57:42.471 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-23T03:57:42.477 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7A9CA660, lRefCount: 5, hr=0

2025-11-23T03:57:42.477 [Engine] New active engine 00007FFE7E88A660 replacing engine 00007FFE7A9CA660. Number of active engines: 2

2025-11-23T03:57:42.483 EngineInit:Global ASOC is enabled

2025-11-23T03:57:42.483 EngineInit:ASOO is enabled for developer volumes

2025-11-23T03:57:42.516 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-23T03:57:42.516 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.516 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-23T03:57:42.517 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-23T03:57:42.517 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-23T03:57:42.517 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.518 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.518 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.518 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-23T03:57:42.518 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.519 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.519 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-23T03:57:42.519 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.519 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.520 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.520 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.520 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.521 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.521 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T03:57:42.521 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ef19a1e7d03ed68772afd197dc302c12174e05da

Dynamic Signature Compilation Timestamp:11-22-2025 02:57:56

Persistence Type:Duration

Time remaining:864000000

2025-11-23T03:57:42.522 Dynamic signature dropped

2025-11-23T03:57:42.523 MpWriteUupSignatureVersion 1.441.423.0, hr = 0

2025-11-23T03:57:42.524 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-23T03:57:42.537 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-23T03:57:42.538 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-23T03:57:42.538 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-23T03:57:42.538 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-23T03:57:42.538 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-23T03:57:42.551 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-23T03:57:42.551 [Plugin] Initializing RTP plugin state...

2025-11-23T03:57:42.551 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-23T03:57:42.551 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 23 - 2025 01:17:23

Last Perf: 11 - 23 - 2025 01:17:23

First RTP Scan: 11 - 23 - 2025 01:17:24

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1043

  Misses:3000

BM Queue:0,32,0

  Proc:0,31,0

  File:0,13,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:218689

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1191662620

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:17

  TotalStreamCon:30831

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:978847

   TotalHits:1647594

   InstanceCacheInserts:73299

   InstanceCacheUpdates:0

   InstanceCacheDeletes:55837

   InstanceCacheHits:4613

   InstanceCacheMisses:284483

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:1ms (373/365)

   Success: 365, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-23T03:57:42.552 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6203A63D-406D-42D6-AE00-6D2ACB19734C}

2025-11-23T03:57:42.552 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CF1F707-13B8-41E9-901F-730F383A4FD4}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CF1F707-13B8-41E9-901F-730F383A4FD4}\mpasbase.vdm in use, hr=0x80070020

2025-11-23T03:57:42.552 [SCC][CID=555490843_10252] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-23T03:57:42.553 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-23T03:57:42.553 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-23T03:57:42.553 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-23T03:57:42.553 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-23T03:57:42.553 MdCoreSvc is supported in this platform and OS

2025-11-23T03:57:42.554 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-23-2025 03:57:42

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-23-2025 03:57:42

2025-11-23T03:57:42.556 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-23T03:57:42.556 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-23T03:57:42.556 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-23T03:57:42.556 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-23-2025 03:57:42

END TDT(U) telemetry



2025-11-23T03:57:42.558 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T03:57:42.559 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-23T03:57:42.559 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-23T03:57:42.559 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-23T03:57:42.559 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-23T03:57:42.559 MdCoreSvc is supported in this platform and OS

Signature updated on 11-23-2025 03:57:42

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.423.0

AV Signature Version: 1.441.423.0

************************************************************

2025-11-23T03:57:42.560 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-23T03:57:42.560 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\C39F5477-0C4A-4E93-990D-2AF9EE3353AF1fdc.1dc5c2d4d4c6ec2

2025-11-23T03:57:42.583 Process scan (postsignatureupdatescan) started.

2025-11-23T03:57:42.605 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-23T03:57:42.606 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-23T03:57:42.739 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-23T03:57:42.739 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-23T03:57:42.739 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-23T03:57:42.739 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-23T03:57:42.739 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-23T03:57:42.741 [Engine] Engine 00007FFE7A9CA660 no longer in use. Number of active engines: 1

2025-11-23T03:57:42.741 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-23T03:57:42.741 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-23T03:57:42.887 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 2257, Count: 159, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\20a096e0-54de-49c9-bb8f-0cb5c7ddb332.tmp, EstimatedImpact: 0%

2025-11-23T03:57:42.887 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 1969, Count: 122, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\76b6ae7e-0365-46c3-b3a3-4e9c7d3578df.tmp, EstimatedImpact: 0%

2025-11-23T03:57:42.887 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1503, Count: 81, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 85%

2025-11-23T03:57:42.887 ProcessImageName: RuntimeBroker.exe, Pid: 8636, TotalTime: 557, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-23T03:57:42.887 ProcessImageName: RuntimeBroker.exe, Pid: 26444, TotalTime: 557, Count: 21, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 36%

2025-11-23T03:57:42.887 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 556, Count: 123, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 75%

2025-11-23T03:57:42.887 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 405, Count: 90, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Data\7a\7ade6a69fe708f6b69ee17d11aa7016ae7cd0e30.file, EstimatedImpact: 0%

2025-11-23T03:57:42.887 ProcessImageName: DeviceCensus.exe, Pid: 6556, TotalTime: 341, Count: 15, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-23T03:57:42.887 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 315, Count: 90, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-23T03:57:42.887 ProcessImageName: taskhostw.exe, Pid: 26616, TotalTime: 271, Count: 43, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\UCPD.sys, EstimatedImpact: 15%

2025-11-23T03:57:42.887 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 196, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T03:57:42.887 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 165, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-23T03:57:42.887 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 139, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-23T03:57:42.887 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-23T03:57:42.887 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 62, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\Temp\DO757E.tmp, EstimatedImpact: 11%

2025-11-23T03:57:42.887 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 60, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-23T03:57:42.903 [Engine] RSIG_UNLOADENGINE, 00007FFE7A9CA660, err=0x0

2025-11-23T03:57:42.919 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CF1F707-13B8-41E9-901F-730F383A4FD4} removed

2025-11-23T03:57:43.052 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-23T03:57:43.058 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-23T03:57:43.058 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-23T03:57:43.058 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-23T03:57:43.058 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-23T03:57:43.058 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-23T03:57:43.058 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-23T03:57:43.061 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-23T03:57:43.061 [RTP] Duplicating the current plugin configuration object...

2025-11-23T03:57:43.061 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-23T03:57:43.061 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-23T03:57:43.061 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-23T03:57:43.061 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-23T03:57:43.061 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-23T03:57:43.061 [RTP] No config change detected. Not updating plugin configuration.

2025-11-23T03:57:43.061 [RTP] No config changes found. No configuration switch.

2025-11-23T03:57:43.061 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-23T03:57:43.061 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-23T03:57:43.061 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-23T03:57:43.061 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-23T03:57:43.061 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-23T03:57:43.061 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-23T03:57:43.061 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-23T03:57:43.062 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-23T03:57:43.062 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-23T03:57:43.062 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-23T03:57:43.062 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-23T03:57:43.062 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-23T03:57:43.062 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-23T03:57:43.062 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-23T03:57:43.062 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-23T03:57:43.062 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-23T03:57:43.062 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T03:57:43.065 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T03:57:43.066 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T03:57:43.068 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T03:57:43.069 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T03:57:43.070 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 1703185(ms) from now at 05:26 (04:26 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-23T03:57:44.580 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-23T03:57:44.584 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-23T03:57:44.584 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-23T03:57:45.601 [RTP] Duplicating the current plugin configuration object...

2025-11-23T03:57:45.601 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-23T03:57:45.601 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-23T03:57:45.601 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-23T03:57:45.601 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157ED7C270CE, sigsha=5eded354160aa060b3f2a16db0725661264de9cd, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EC4695FB0, sigsha=52047109963df3b68264cf6c70eb58a332f0e384, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EE3E9E96F, sigsha=bb73eddcceeb861170c0e1ea3e27e4478d601280, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157E24ECD9EE, sigsha=b8666aeb5330bc151c524a8796313de114549911, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF9518016, sigsha=8fa60ffaf004b3696b5767c35f78f1425d04eb09, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0xa85b3f00

2025-11-23T03:57:48.242 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-23T03:57:48.242 [Cloud] Start of cloud request. Passive mode: 0

2025-11-23T03:57:48.242 [Cloud] Queued cloud request.

2025-11-23T03:57:48.242 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-23T03:57:48.242 [Cloud] Dequeued cloud request.

2025-11-23T03:57:48.242 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5fc6fda8dcec63245787d0ecea66aa1d0af5fbef

Dynamic Signature Compilation Timestamp:11-23-2025 03:57:48

Persistence Type:Duration

Time remaining:864000000

2025-11-23T03:57:48.586 Dynamic signature received

2025-11-23T03:57:48.587 [Cloud] End of cloud request.

2025-11-23T03:57:48.588 RTSD:RTSD recieved, rescanning impacted resources

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-23T03:57:49.102 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T03:57:49.915 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-23T03:57:49.915 [Cloud] Start of cloud request. Passive mode: 0

2025-11-23T03:57:49.915 [Cloud] Queued cloud request.

2025-11-23T03:57:49.915 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-23T03:57:49.915 [Cloud] Dequeued cloud request.

2025-11-23T03:57:49.915 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-23T03:57:50.453 [Cloud] End of cloud request.

2025-11-23T03:57:50.973 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T03:57:59.451 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-23T03:57:59.452 Process scan (postsignatureupdatescan) completed.

2025-11-23T03:58:18.928 [RTP] 25 newly mounted volumes accumulated, forcing a config update ...

2025-11-23T03:58:18.928 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy13\pagefile.sys

2025-11-23T03:58:18.928 [RTP] Duplicating the current plugin configuration object...

2025-11-23T03:58:18.928 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-23T03:58:18.928 [RTP] Updating plugin configuration due to recent config changes (0x1) ...

2025-11-23T03:58:18.928 [RTP] Calling GenerateEngineConfigStruct (0) ...

2025-11-23T03:58:18.928 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200

2025-11-23T03:58:20.726 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy13\pagefile.sys

2025-11-23T03:58:28.520 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy14\pagefile.sys

2025-11-23T03:58:30.260 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy14\pagefile.sys

2025-11-23T03:58:39.222 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy15\pagefile.sys

2025-11-23T03:58:41.010 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy15\pagefile.sys

2025-11-23T03:58:49.677 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy16\pagefile.sys

2025-11-23T03:58:51.371 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy16\pagefile.sys

2025-11-23T04:02:42.500 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-23T04:03:11.167 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #221352, FileId: 0x20f00000000a147, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T04:08:13.932 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T04:18:12.655 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #221793, FileId: 0x198000000004352, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T04:23:18.927 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T04:33:12.727 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #221924, FileId: 0x22300000001a094, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T04:38:23.928 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T04:48:13.063 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #222133, FileId: 0x50000000019ff5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T04:52:06.389 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #222263, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T04:52:06.391 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #222264, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T04:52:16.402 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #222275, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T04:52:16.406 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #222276, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T04:53:28.930 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T05:03:13.387 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #222408, FileId: 0xc7000000019234, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T05:08:33.922 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T05:18:13.402 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #223136, FileId: 0x6000000001d472, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T05:23:38.919 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T05:28:30.473 Bm signature throttled:0x0000fab3228bcd4d

2025-11-23T05:33:13.944 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #223196, FileId: 0x7000000001d472, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T05:38:43.912 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T05:48:15.290 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #223337, FileId: 0x117000000019817, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T05:52:07.353 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #223414, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T05:52:07.356 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #223415, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T05:52:17.368 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #223420, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T05:52:17.372 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #223421, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T05:52:17.381 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #223422, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T05:52:17.385 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #223423, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T05:53:48.905 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T05:57:42.456 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1614, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 86%

2025-11-23T05:57:42.456 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 1353, Count: 84, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7b6e3a58-49cb-426c-8aa1-d42513d0e664.tmp, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1037, Count: 32, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\xampp-portable-windows-x64-8.2.12-0-VS16-installer.exe, EstimatedImpact: 10%

2025-11-23T05:57:42.456 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 880, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\2e36b8a5-11aa-4e03-962d-8a92371b7ee0.tmp, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 780, Count: 94, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.3_2.32002.13001.0_x86__8wekyb3d8bbwe\AppxManifest.xml->(UTF-8), EstimatedImpact: 30%

2025-11-23T05:57:42.456 ProcessImageName: , Pid: 4, TotalTime: 645, Count: 124, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy13\System Volume Information\{3070b5dc-ba74-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 1%

2025-11-23T05:57:42.456 ProcessImageName: RuntimeBroker.exe, Pid: 23308, TotalTime: 401, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 23%

2025-11-23T05:57:42.456 ProcessImageName: VSSVC.exe, Pid: 24380, TotalTime: 327, Count: 2, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100%

2025-11-23T05:57:42.456 ProcessImageName: PhoneExperienceHost.exe, Pid: 9392, TotalTime: 270, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 13%

2025-11-23T05:57:42.456 ProcessImageName: svchost.exe, Pid: 7060, TotalTime: 182, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: taskhostw.exe, Pid: 2668, TotalTime: 180, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\Packages\Preview\uusp.json, EstimatedImpact: 9%

2025-11-23T05:57:42.456 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 165, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\c7fb3d4b-4bdc-48f3-8235-2865337e93cf\content.phf, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\221e69c75d2ebd901f43b49f837382c045686b79ba68ba6ace4a7e0a20cd9177, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0D1686C3FBB7F7352C5A7B6BA00CB0A6, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: updater.exe, Pid: 26896, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ec9a4227-7502-46b0-9850-e83d720f5152.tmp, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: SrTasks.exe, Pid: 7316, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 0%

2025-11-23T05:57:42.456 ProcessImageName: updater.exe, Pid: 24828, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-23T06:03:16.749 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #223643, FileId: 0x49000000009119, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T06:08:53.902 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T06:18:17.128 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #223858, FileId: 0x830000000197d7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T06:23:58.898 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T06:33:17.658 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #223969, FileId: 0x7f000000024150, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T06:39:03.903 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T06:48:17.800 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #224126, FileId: 0x4e000000029572, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T06:52:06.923 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #224137, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T06:52:06.925 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #224138, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T06:52:16.927 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #224143, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T06:52:16.932 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #224144, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T06:52:16.937 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #224145, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T06:52:16.940 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #224146, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T06:54:08.900 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T07:03:18.351 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #224269, FileId: 0xdf000000009bd3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T07:09:13.893 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T07:18:18.534 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #224546, FileId: 0x39e000000023eba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T07:24:18.890 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T07:28:32.580 Bm signature throttled:0x0000fab3228bcd4d

2025-11-23T07:33:19.795 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #224611, FileId: 0x1310000000195c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T07:39:23.884 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T07:48:20.195 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #225564, FileId: 0x9b00000000ae5f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T07:52:06.339 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #225595, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T07:52:06.342 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #225596, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T07:52:16.352 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #225603, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T07:52:16.358 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #225604, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T07:54:28.881 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T07:57:42.443 ProcessImageName: ffmpeg.exe, Pid: 18872, TotalTime: 5775, Count: 627, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\transcoding-temp\CC53B3\CC53B3_564.ts.tmp, EstimatedImpact: 7%

2025-11-23T07:57:42.443 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 2719, Count: 171, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7b6e3a58-49cb-426c-8aa1-d42513d0e664.tmp, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 1744, Count: 104, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\de821f9d-6299-42c2-9bfd-7f91fba65bf6.tmp, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1651, Count: 197, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1614, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 86%

2025-11-23T07:57:42.443 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1037, Count: 32, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\xampp-portable-windows-x64-8.2.12-0-VS16-installer.exe, EstimatedImpact: 10%

2025-11-23T07:57:42.443 ProcessImageName: , Pid: 4, TotalTime: 645, Count: 124, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy13\System Volume Information\{3070b5dc-ba74-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 1%

2025-11-23T07:57:42.443 ProcessImageName: RuntimeBroker.exe, Pid: 23308, TotalTime: 401, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 23%

2025-11-23T07:57:42.443 ProcessImageName: ffmpeg.exe, Pid: 9344, TotalTime: 334, Count: 20, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\libx265_main12.dll, EstimatedImpact: 3%

2025-11-23T07:57:42.443 ProcessImageName: VSSVC.exe, Pid: 24380, TotalTime: 327, Count: 2, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100%

2025-11-23T07:57:42.443 ProcessImageName: PhoneExperienceHost.exe, Pid: 9392, TotalTime: 270, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 13%

2025-11-23T07:57:42.443 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 210, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 195, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: svchost.exe, Pid: 7060, TotalTime: 182, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: taskhostw.exe, Pid: 2668, TotalTime: 180, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\Packages\Preview\uusp.json, EstimatedImpact: 9%

2025-11-23T07:57:42.443 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 152, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 135, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\c7fb3d4b-4bdc-48f3-8235-2865337e93cf\content.phf, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: taskhostw.exe, Pid: 6216, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 2%

2025-11-23T07:57:42.443 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\221e69c75d2ebd901f43b49f837382c045686b79ba68ba6ace4a7e0a20cd9177, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: SrTasks.exe, Pid: 7316, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: updater.exe, Pid: 26896, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ec9a4227-7502-46b0-9850-e83d720f5152.tmp, EstimatedImpact: 0%

2025-11-23T07:57:42.443 ProcessImageName: updater.exe, Pid: 24828, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-23T08:01:21.641 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #225769, FileId: 0xe6000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T08:03:21.453 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #225783, FileId: 0x2d000000029759, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T08:09:33.872 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T08:18:21.829 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #226036, FileId: 0xb8000000019fa3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T08:24:38.872 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T08:33:23.117 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #226147, FileId: 0xc4000000019fa3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T08:39:43.867 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T08:48:23.304 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #226255, FileId: 0x750000000166c6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T08:52:05.810 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #226274, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T08:52:05.812 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #226275, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T08:52:15.823 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #226281, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T08:52:15.827 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #226282, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T08:54:48.859 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T09:03:23.341 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #226424, FileId: 0x64000000029927, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T09:09:53.854 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T09:18:23.526 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #226675, FileId: 0x29b000000023f41, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T09:24:58.859 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T09:28:34.974 Bm signature throttled:0x0000fab3228bcd4d

2025-11-23T09:33:24.891 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #227123, FileId: 0x2aa000000023f41, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T09:40:03.847 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T09:45:39.965 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #227356, FileId: 0xe9000000015fd2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T09:48:24.917 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #227370, FileId: 0xcf00000000ae5f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T09:52:06.957 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #227403, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T09:52:06.960 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #227404, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T09:52:16.972 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #227412, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T09:52:16.976 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #227413, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T09:55:08.842 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T09:57:42.418 ProcessImageName: ffmpeg.exe, Pid: 18872, TotalTime: 5775, Count: 627, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\transcoding-temp\CC53B3\CC53B3_564.ts.tmp, EstimatedImpact: 7%

2025-11-23T09:57:42.418 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 4169, Count: 256, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7b6e3a58-49cb-426c-8aa1-d42513d0e664.tmp, EstimatedImpact: 0%

2025-11-23T09:57:42.418 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 2576, Count: 156, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\de821f9d-6299-42c2-9bfd-7f91fba65bf6.tmp, EstimatedImpact: 0%

2025-11-23T09:57:42.418 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1682, Count: 199, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 0%

2025-11-23T09:57:42.418 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1614, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 86%

2025-11-23T09:57:42.418 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1037, Count: 32, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\xampp-portable-windows-x64-8.2.12-0-VS16-installer.exe, EstimatedImpact: 10%

2025-11-23T09:57:42.418 ProcessImageName: , Pid: 4, TotalTime: 645, Count: 124, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy13\System Volume Information\{3070b5dc-ba74-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 1%

2025-11-23T09:57:42.418 ProcessImageName: RuntimeBroker.exe, Pid: 23308, TotalTime: 401, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 23%

2025-11-23T09:57:42.418 ProcessImageName: ffmpeg.exe, Pid: 9344, TotalTime: 334, Count: 20, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\libx265_main12.dll, EstimatedImpact: 3%

2025-11-23T09:57:42.418 ProcessImageName: VSSVC.exe, Pid: 24380, TotalTime: 327, Count: 2, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100%

2025-11-23T09:57:42.419 ProcessImageName: PhoneExperienceHost.exe, Pid: 9392, TotalTime: 270, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 13%

2025-11-23T09:57:42.419 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 270, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 240, Count: 55, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 228, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 210, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: svchost.exe, Pid: 7060, TotalTime: 182, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: taskhostw.exe, Pid: 2668, TotalTime: 180, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\Packages\Preview\uusp.json, EstimatedImpact: 9%

2025-11-23T09:57:42.419 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 75, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\221e69c75d2ebd901f43b49f837382c045686b79ba68ba6ace4a7e0a20cd9177, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\c7fb3d4b-4bdc-48f3-8235-2865337e93cf\content.phf, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: taskhostw.exe, Pid: 6216, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 2%

2025-11-23T09:57:42.419 ProcessImageName: taskhostw.exe, Pid: 27072, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 17%

2025-11-23T09:57:42.419 ProcessImageName: updater.exe, Pid: 26896, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ec9a4227-7502-46b0-9850-e83d720f5152.tmp, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: SrTasks.exe, Pid: 7316, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: taskhostw.exe, Pid: 25888, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-23T09:57:42.419 ProcessImageName: updater.exe, Pid: 24828, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-23T10:03:25.243 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #227618, FileId: 0x40000000029936, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T10:10:13.840 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T10:18:25.497 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #227886, FileId: 0x11700000001e11e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T10:25:18.837 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T10:33:25.642 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #228048, FileId: 0xa10000000298d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T10:40:23.828 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T10:48:25.812 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #228159, FileId: 0x17000000009b1a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T10:52:05.967 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #228177, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T10:52:05.972 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #228178, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T10:52:15.978 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #228184, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T10:52:15.982 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #228185, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T10:52:15.990 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #228186, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T10:52:15.994 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #228187, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T10:55:28.823 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T11:03:27.253 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #228314, FileId: 0x1f000000009b1a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T11:10:33.827 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T11:18:28.575 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #228568, FileId: 0x8a0000000299a1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T11:25:38.820 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T11:28:36.614 Bm signature throttled:0x0000fab3228bcd4d

2025-11-23T11:33:28.808 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #228633, FileId: 0x59000000019541, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T11:40:43.809 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T11:48:28.897 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #228822, FileId: 0xed000000029756, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T11:52:07.118 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #228868, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T11:52:07.122 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #228869, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T11:52:17.129 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #228877, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T11:52:17.144 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #228878, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T11:55:48.811 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T11:57:42.395 ProcessImageName: ffmpeg.exe, Pid: 18872, TotalTime: 5775, Count: 627, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\transcoding-temp\CC53B3\CC53B3_564.ts.tmp, EstimatedImpact: 7%

2025-11-23T11:57:42.395 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 5212, Count: 341, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7b6e3a58-49cb-426c-8aa1-d42513d0e664.tmp, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 3346, Count: 208, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\de821f9d-6299-42c2-9bfd-7f91fba65bf6.tmp, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1682, Count: 199, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1614, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 86%

2025-11-23T11:57:42.395 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1037, Count: 32, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\xampp-portable-windows-x64-8.2.12-0-VS16-installer.exe, EstimatedImpact: 10%

2025-11-23T11:57:42.395 ProcessImageName: , Pid: 4, TotalTime: 645, Count: 124, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy13\System Volume Information\{3070b5dc-ba74-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 1%

2025-11-23T11:57:42.395 ProcessImageName: RuntimeBroker.exe, Pid: 23308, TotalTime: 401, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 23%

2025-11-23T11:57:42.395 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 346, Count: 33, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: ffmpeg.exe, Pid: 9344, TotalTime: 334, Count: 20, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\libx265_main12.dll, EstimatedImpact: 3%

2025-11-23T11:57:42.395 ProcessImageName: VSSVC.exe, Pid: 24380, TotalTime: 327, Count: 2, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100%

2025-11-23T11:57:42.395 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 285, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 273, Count: 35, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: PhoneExperienceHost.exe, Pid: 9392, TotalTime: 270, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 13%

2025-11-23T11:57:42.395 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 240, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 183, Count: 16, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: svchost.exe, Pid: 7060, TotalTime: 182, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: taskhostw.exe, Pid: 2668, TotalTime: 180, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\Packages\Preview\uusp.json, EstimatedImpact: 9%

2025-11-23T11:57:42.395 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 75, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\221e69c75d2ebd901f43b49f837382c045686b79ba68ba6ace4a7e0a20cd9177, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\c7fb3d4b-4bdc-48f3-8235-2865337e93cf\content.phf, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\723642f5-d482-4ce3-a705-c662eb87d512.tmp, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: taskhostw.exe, Pid: 6216, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 2%

2025-11-23T11:57:42.395 ProcessImageName: updater.exe, Pid: 21076, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\539eaa70-fe10-4cff-9f5e-93384be6744e.tmp, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: taskhostw.exe, Pid: 27072, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 17%

2025-11-23T11:57:42.395 ProcessImageName: updater.exe, Pid: 26896, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ec9a4227-7502-46b0-9850-e83d720f5152.tmp, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: SrTasks.exe, Pid: 7316, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: taskhostw.exe, Pid: 25888, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-23T11:57:42.395 ProcessImageName: updater.exe, Pid: 24828, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-23T12:03:29.111 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #229355, FileId: 0x24f00000000947f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T12:10:53.806 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T12:18:29.323 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #229596, FileId: 0xcb00000001a608, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T12:25:58.801 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T12:33:29.424 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #229672, FileId: 0xc200000000483c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T12:41:03.797 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T12:48:30.489 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #229789, FileId: 0x1df000000002211, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T12:52:06.076 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #229816, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T12:52:06.078 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #229817, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T12:52:16.089 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #229823, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T12:52:16.094 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #229824, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T12:56:08.791 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T13:03:30.685 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #229929, FileId: 0x4c0000000299a6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T13:11:13.779 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T13:18:30.809 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #230152, FileId: 0x24500000001a094, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T13:26:18.773 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T13:28:38.428 Bm signature throttled:0x0000fab3228bcd4d

2025-11-23T13:33:31.229 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #230214, FileId: 0xdc00000001a05c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T13:41:23.778 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T13:48:31.543 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #230764, FileId: 0x25700000001a094, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T13:52:06.982 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #230808, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T13:52:06.997 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #230809, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T13:52:16.984 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #230817, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T13:52:16.985 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #230818, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T13:52:16.987 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #230819, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T13:52:16.988 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #230820, FileId: 0xe6000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T13:56:28.764 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T13:57:42.362 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 6332, Count: 428, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7b6e3a58-49cb-426c-8aa1-d42513d0e664.tmp, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: ffmpeg.exe, Pid: 18872, TotalTime: 5775, Count: 627, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\transcoding-temp\CC53B3\CC53B3_564.ts.tmp, EstimatedImpact: 7%

2025-11-23T13:57:42.362 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 4133, Count: 260, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\de821f9d-6299-42c2-9bfd-7f91fba65bf6.tmp, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1682, Count: 199, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1614, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 86%

2025-11-23T13:57:42.362 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1037, Count: 32, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\xampp-portable-windows-x64-8.2.12-0-VS16-installer.exe, EstimatedImpact: 10%

2025-11-23T13:57:42.362 ProcessImageName: , Pid: 4, TotalTime: 645, Count: 124, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy13\System Volume Information\{3070b5dc-ba74-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 1%

2025-11-23T13:57:42.362 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 451, Count: 41, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: RuntimeBroker.exe, Pid: 23308, TotalTime: 401, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 23%

2025-11-23T13:57:42.362 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 349, Count: 43, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: ffmpeg.exe, Pid: 9344, TotalTime: 334, Count: 20, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\libx265_main12.dll, EstimatedImpact: 3%

2025-11-23T13:57:42.362 ProcessImageName: VSSVC.exe, Pid: 24380, TotalTime: 327, Count: 2, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100%

2025-11-23T13:57:42.362 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 315, Count: 67, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 300, Count: 48, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: WmiPrvSE.exe, Pid: 4520, TotalTime: 270, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\wstorvsp.inf, EstimatedImpact: 26%

2025-11-23T13:57:42.362 ProcessImageName: PhoneExperienceHost.exe, Pid: 9392, TotalTime: 270, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 13%

2025-11-23T13:57:42.362 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 228, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: svchost.exe, Pid: 7060, TotalTime: 182, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: taskhostw.exe, Pid: 2668, TotalTime: 180, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\Packages\Preview\uusp.json, EstimatedImpact: 9%

2025-11-23T13:57:42.362 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 75, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\221e69c75d2ebd901f43b49f837382c045686b79ba68ba6ace4a7e0a20cd9177, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\c7fb3d4b-4bdc-48f3-8235-2865337e93cf\content.phf, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\723642f5-d482-4ce3-a705-c662eb87d512.tmp, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: taskhostw.exe, Pid: 6216, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 2%

2025-11-23T13:57:42.362 ProcessImageName: updater.exe, Pid: 21076, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\539eaa70-fe10-4cff-9f5e-93384be6744e.tmp, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: backgroundTaskHost.exe, Pid: 22460, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1763891627->(UTF-16LE), EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: taskhostw.exe, Pid: 18528, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-23T13:57:42.362 ProcessImageName: taskhostw.exe, Pid: 27072, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 17%

2025-11-23T13:57:42.362 ProcessImageName: updater.exe, Pid: 26896, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ec9a4227-7502-46b0-9850-e83d720f5152.tmp, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: SrTasks.exe, Pid: 7316, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: taskhostw.exe, Pid: 25888, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-23T13:57:42.362 ProcessImageName: updater.exe, Pid: 24828, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-23T14:03:31.634 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #230955, FileId: 0x8600000000b881, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T14:09:54.196 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #231201, FileId: 0xe7000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T14:11:33.768 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T14:18:33.037 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #231259, FileId: 0xb00000000299a1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T14:26:38.754 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T14:33:33.212 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #231362, FileId: 0x530000000299c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T14:41:43.762 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T14:48:33.238 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #231512, FileId: 0x2e200000001a6cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T14:52:05.823 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #231526, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000001, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T14:52:05.825 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #231527, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T14:52:15.833 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #231534, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T14:52:15.846 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #231536, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T14:52:15.847 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #231535, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T14:56:48.750 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T15:11:53.739 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T15:26:58.745 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T15:28:40.560 Bm signature throttled:0x0000fab3228bcd4d

2025-11-23T15:42:03.743 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T15:52:15.521 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #232577, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T15:57:08.745 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T15:57:42.332 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 7608, Count: 514, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7b6e3a58-49cb-426c-8aa1-d42513d0e664.tmp, EstimatedImpact: 0%

2025-11-23T15:57:42.332 ProcessImageName: ffmpeg.exe, Pid: 18872, TotalTime: 5775, Count: 627, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\transcoding-temp\CC53B3\CC53B3_564.ts.tmp, EstimatedImpact: 7%

2025-11-23T15:57:42.332 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 4983, Count: 314, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\de821f9d-6299-42c2-9bfd-7f91fba65bf6.tmp, EstimatedImpact: 0%

2025-11-23T15:57:42.332 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1773, Count: 212, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 0%

2025-11-23T15:57:42.332 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1614, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 86%

2025-11-23T15:57:42.332 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1037, Count: 32, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\xampp-portable-windows-x64-8.2.12-0-VS16-installer.exe, EstimatedImpact: 10%

2025-11-23T15:57:42.332 ProcessImageName: , Pid: 4, TotalTime: 645, Count: 124, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy13\System Volume Information\{3070b5dc-ba74-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 1%

2025-11-23T15:57:42.332 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 526, Count: 49, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T15:57:42.332 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 425, Count: 51, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-23T15:57:42.332 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 420, Count: 66, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-23T15:57:42.332 ProcessImageName: RuntimeBroker.exe, Pid: 23308, TotalTime: 401, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 23%

2025-11-23T15:57:42.332 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 345, Count: 71, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-23T15:57:42.332 ProcessImageName: ffmpeg.exe, Pid: 9344, TotalTime: 334, Count: 20, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\libx265_main12.dll, EstimatedImpact: 3%

2025-11-23T15:57:42.332 ProcessImageName: VSSVC.exe, Pid: 24380, TotalTime: 327, Count: 2, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100%

2025-11-23T15:57:42.332 ProcessImageName: WmiPrvSE.exe, Pid: 4520, TotalTime: 270, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\wstorvsp.inf, EstimatedImpact: 26%

2025-11-23T15:57:42.332 ProcessImageName: PhoneExperienceHost.exe, Pid: 9392, TotalTime: 270, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 13%

2025-11-23T15:57:42.332 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 228, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-23T15:57:42.332 ProcessImageName: svchost.exe, Pid: 7060, TotalTime: 182, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 0%

2025-11-23T15:57:42.332 ProcessImageName: taskhostw.exe, Pid: 2668, TotalTime: 180, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\Packages\Preview\uusp.json, EstimatedImpact: 9%

2025-11-23T15:57:42.332 ProcessImageName: ngentask.exe, Pid: 6200, TotalTime: 137, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 16%

2025-11-23T15:57:42.332 ProcessImageName: WmiPrvSE.exe, Pid: 9880, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 92%

2025-11-23T15:57:42.332 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 105, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\221e69c75d2ebd901f43b49f837382c045686b79ba68ba6ace4a7e0a20cd9177, EstimatedImpact: 0%

2025-11-23T15:57:42.332 ProcessImageName: ngentask.exe, Pid: 27228, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 10%

2025-11-23T15:57:42.334 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-23T15:57:42.334 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\79b661cf-c715-41c6-ba13-304499dedbf4.tmp, EstimatedImpact: 0%

2025-11-23T15:57:42.334 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-23T15:57:42.334 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\c7fb3d4b-4bdc-48f3-8235-2865337e93cf\content.phf, EstimatedImpact: 0%

2025-11-23T15:57:42.334 ProcessImageName: ngentask.exe, Pid: 16324, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 51%

2025-11-23T15:57:42.334 ProcessImageName: ngentask.exe, Pid: 8088, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 42%

2025-11-23T15:57:42.334 ProcessImageName: taskhostw.exe, Pid: 4908, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 2%

2025-11-23T15:57:42.334 ProcessImageName: ngentask.exe, Pid: 9204, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 14%

2025-11-23T15:57:42.334 ProcessImageName: ngentask.exe, Pid: 24800, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-23T15:57:42.334 ProcessImageName: taskhostw.exe, Pid: 6216, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 2%

2025-11-23T15:57:42.334 ProcessImageName: updater.exe, Pid: 21076, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\539eaa70-fe10-4cff-9f5e-93384be6744e.tmp, EstimatedImpact: 0%

2025-11-23T15:57:42.334 ProcessImageName: tzsync.exe, Pid: 1980, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Globalization\Time Zone\timezones.xml->(UTF-8), EstimatedImpact: 10%

2025-11-23T15:57:42.334 ProcessImageName: backgroundTaskHost.exe, Pid: 22460, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1763891627->(UTF-16LE), EstimatedImpact: 0%

2025-11-23T15:57:42.334 ProcessImageName: taskhostw.exe, Pid: 27072, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 17%

2025-11-23T15:57:42.334 ProcessImageName: taskhostw.exe, Pid: 18528, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-23T15:57:42.334 ProcessImageName: taskhostw.exe, Pid: 3432, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 19%

2025-11-23T15:57:42.334 ProcessImageName: updater.exe, Pid: 18080, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\210569d5-143e-4967-a284-59a34799363f.tmp, EstimatedImpact: 0%

2025-11-23T15:57:42.334 ProcessImageName: updater.exe, Pid: 26896, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ec9a4227-7502-46b0-9850-e83d720f5152.tmp, EstimatedImpact: 0%

2025-11-23T15:57:42.334 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-23T15:57:42.334 ProcessImageName: SrTasks.exe, Pid: 7316, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 0%

2025-11-23T15:57:42.334 ProcessImageName: taskhostw.exe, Pid: 25888, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-23T15:57:42.334 ProcessImageName: updater.exe, Pid: 24828, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-23T16:12:13.737 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T16:27:18.738 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T16:42:23.724 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T16:52:14.643 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #233297, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T16:57:28.719 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T16:57:45.117 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\3E7E6B35-D215-4E93-8534-F3282AFE7DB66700.1dc5c9a470604e4

2025-11-23T16:57:45.641 Verifying engine and signature files (source: 0) ...

2025-11-23T16:57:45.641 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9998FD2-F6BB-4E88-A55D-5B9B576C6CA2}\mpengine.dll] due to PPL.

2025-11-23T16:57:45.641 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9998FD2-F6BB-4E88-A55D-5B9B576C6CA2}\mpasbase.vdm] (file in cache)

2025-11-23T16:57:45.642 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9998FD2-F6BB-4E88-A55D-5B9B576C6CA2}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-23T16:57:45.657 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9998FD2-F6BB-4E88-A55D-5B9B576C6CA2}\mpasdlta.vdm]

2025-11-23T16:57:45.657 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9998FD2-F6BB-4E88-A55D-5B9B576C6CA2}\mpavbase.vdm] (file in cache)

2025-11-23T16:57:45.657 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9998FD2-F6BB-4E88-A55D-5B9B576C6CA2}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-23T16:57:45.666 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9998FD2-F6BB-4E88-A55D-5B9B576C6CA2}\mpavdlta.vdm]

2025-11-23T16:57:46.622 [Engine] IsHybridMode: 0

2025-11-23T16:57:46.623 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-23T16:57:47.084 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EE6900BBA73652DA2B8838BD05FD51D7C4D041CF.bin): 0x00000002

2025-11-23T16:57:47.087 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EE6900BBA73652DA2B8838BD05FD51D7C4D041CF.bin)

2025-11-23T16:57:47.087 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-23T16:57:47.087 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-23T16:57:47.087 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-23T16:57:47.087 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-23T16:57:56.361 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-23T16:57:56.361 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-23T16:57:56.369 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7E88A660, lRefCount: 5, hr=0

2025-11-23T16:57:56.369 [Engine] New active engine 00007FFE7A9CA660 replacing engine 00007FFE7E88A660. Number of active engines: 2

2025-11-23T16:57:56.371 EngineInit:Global ASOC is enabled

2025-11-23T16:57:56.371 EngineInit:ASOO is enabled for developer volumes

2025-11-23T16:57:56.406 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-23T16:57:56.406 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.406 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.407 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-23T16:57:56.409 MpWriteUupSignatureVersion 1.441.435.0, hr = 0

2025-11-23T16:57:56.410 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-23T16:57:56.422 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-23T16:57:56.423 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-23T16:57:56.423 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-23T16:57:56.423 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-23T16:57:56.423 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-23T16:57:56.436 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-23T16:57:56.436 [Plugin] Initializing RTP plugin state...

2025-11-23T16:57:56.436 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-23T16:57:56.436 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 23 - 2025 04:57:42

Last Perf: 11 - 23 - 2025 04:57:42

First RTP Scan: 11 - 23 - 2025 04:57:42

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1170

  Misses:9806

BM Queue:0,35,0

  Proc:0,34,0

  File:0,14,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:233520

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1247564590

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:21

  TotalStreamCon:14694

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:1041008

   TotalHits:1737903

   InstanceCacheInserts:77967

   InstanceCacheUpdates:0

   InstanceCacheDeletes:56766

   InstanceCacheHits:4623

   InstanceCacheMisses:299528

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:1ms (1270/1120)

   Success: 1120, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-23T16:57:56.436 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9998FD2-F6BB-4E88-A55D-5B9B576C6CA2}

2025-11-23T16:57:56.436 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6203A63D-406D-42D6-AE00-6D2ACB19734C}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6203A63D-406D-42D6-AE00-6D2ACB19734C}\mpasbase.vdm in use, hr=0x80070020

2025-11-23T16:57:56.436 [SCC][CID=602304937_8976] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-23T16:57:56.437 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-23T16:57:56.437 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-23T16:57:56.437 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-23T16:57:56.437 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-23T16:57:56.438 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-23T16:57:56.438 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-23-2025 16:57:56

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-23-2025 16:57:56

2025-11-23T16:57:56.441 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-23T16:57:56.441 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-23T16:57:56.441 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-23T16:57:56.441 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-23-2025 16:57:56

END TDT(U) telemetry



2025-11-23T16:57:56.443 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T16:57:56.443 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-23T16:57:56.443 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-23T16:57:56.443 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-23T16:57:56.443 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-23T16:57:56.444 MdCoreSvc is supported in this platform and OS

Signature updated on 11-23-2025 16:57:56

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.435.0

AV Signature Version: 1.441.435.0

************************************************************

2025-11-23T16:57:56.445 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-23T16:57:56.445 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\3E7E6B35-D215-4E93-8534-F3282AFE7DB66700.1dc5c9a470604e4

2025-11-23T16:57:56.457 Process scan (postsignatureupdatescan) started.

2025-11-23T16:57:56.487 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-23T16:57:56.489 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-23T16:57:56.634 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-23T16:57:56.634 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-23T16:57:56.634 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-23T16:57:56.634 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-23T16:57:56.634 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-23T16:57:56.754 [Engine] Engine 00007FFE7E88A660 no longer in use. Number of active engines: 1

2025-11-23T16:57:56.754 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-23T16:57:56.754 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-23T16:57:56.927 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-23T16:57:56.933 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-23T16:57:56.933 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-23T16:57:56.933 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-23T16:57:56.933 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-23T16:57:56.933 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-23T16:57:56.933 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-23T16:57:56.937 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-23T16:57:56.937 [RTP] Duplicating the current plugin configuration object...

2025-11-23T16:57:56.937 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-23T16:57:56.937 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-23T16:57:56.937 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-23T16:57:56.937 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-23T16:57:56.937 [RTP] No config change detected. Not updating plugin configuration.

2025-11-23T16:57:56.937 [RTP] No config changes found. No configuration switch.

2025-11-23T16:57:56.937 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-23T16:57:56.937 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-23T16:57:56.937 [RTP] Duplicating the current plugin configuration object...

2025-11-23T16:57:56.937 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-23T16:57:56.937 [RTP] Updating plugin configuration due to recent config changes (0x2) ...

2025-11-23T16:57:56.937 [RTP] No config change detected. Not updating plugin configuration.

2025-11-23T16:57:56.937 [RTP] No config changes found. No configuration switch.

2025-11-23T16:57:56.937 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0

2025-11-23T16:57:56.937 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-23T16:57:56.937 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-23T16:57:56.937 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-23T16:57:56.952 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T16:57:56.952 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-23T16:57:56.952 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-23T16:57:56.952 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-23T16:57:56.953 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-23T16:57:56.953 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-23T16:57:56.953 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-23T16:57:56.953 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-23T16:57:56.953 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-23T16:57:56.953 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-23T16:57:56.953 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-23T16:57:56.953 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-23T16:57:56.953 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-23T16:57:56.954 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T16:57:56.955 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T16:57:56.957 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T16:57:56.959 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T16:57:56.961 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 39985761(ms) from now at 05:04 (04:04 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-23T16:57:58.453 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-23T16:57:58.457 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-23T16:57:58.458 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-23T16:57:59.482 [RTP] Duplicating the current plugin configuration object...

2025-11-23T16:57:59.482 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-23T16:57:59.482 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-23T16:57:59.482 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-23T16:57:59.483 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

2025-11-23T16:58:00.539 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 8231, Count: 557, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7b6e3a58-49cb-426c-8aa1-d42513d0e664.tmp, EstimatedImpact: 0%

2025-11-23T16:58:00.539 ProcessImageName: ffmpeg.exe, Pid: 18872, TotalTime: 5775, Count: 627, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\transcoding-temp\CC53B3\CC53B3_564.ts.tmp, EstimatedImpact: 7%

2025-11-23T16:58:00.539 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 5607, Count: 351, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\de821f9d-6299-42c2-9bfd-7f91fba65bf6.tmp, EstimatedImpact: 0%

2025-11-23T16:58:00.539 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1773, Count: 212, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 0%

2025-11-23T16:58:00.539 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1614, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 86%

2025-11-23T16:58:00.539 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1037, Count: 32, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\xampp-portable-windows-x64-8.2.12-0-VS16-installer.exe, EstimatedImpact: 10%

2025-11-23T16:58:00.539 ProcessImageName: , Pid: 4, TotalTime: 645, Count: 124, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy13\System Volume Information\{3070b5dc-ba74-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 1%

2025-11-23T16:58:00.539 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 587, Count: 53, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T16:58:00.539 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 454, Count: 61, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Data\f2\f293cc103f42d2ecd4aaa8d34a936d2f6364067f.file, EstimatedImpact: 0%

2025-11-23T16:58:00.539 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 450, Count: 78, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-23T16:58:00.539 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 440, Count: 55, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-23T16:58:00.539 ProcessImageName: RuntimeBroker.exe, Pid: 23308, TotalTime: 401, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 23%

2025-11-23T16:58:00.539 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 390, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-23T16:58:00.539 ProcessImageName: ffmpeg.exe, Pid: 9344, TotalTime: 334, Count: 20, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\libx265_main12.dll, EstimatedImpact: 3%

2025-11-23T16:58:00.539 ProcessImageName: VSSVC.exe, Pid: 24380, TotalTime: 327, Count: 2, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100%

2025-11-23T16:58:00.539 ProcessImageName: WmiPrvSE.exe, Pid: 4520, TotalTime: 270, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\wstorvsp.inf, EstimatedImpact: 26%

2025-11-23T16:58:00.555 [Engine] RSIG_UNLOADENGINE, 00007FFE7E88A660, err=0x0

2025-11-23T16:58:00.567 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6203A63D-406D-42D6-AE00-6D2ACB19734C} removed

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-23T16:58:03.727 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-23T16:58:03.727 [Cloud] Start of cloud request. Passive mode: 0

2025-11-23T16:58:03.727 [Cloud] Queued cloud request.

2025-11-23T16:58:03.727 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-23T16:58:03.727 [Cloud] Dequeued cloud request.

2025-11-23T16:58:03.727 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-23T16:58:04.200 [Cloud] End of cloud request.

2025-11-23T16:58:04.712 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-23T16:58:12.846 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-23T16:58:12.847 Process scan (postsignatureupdatescan) completed.

2025-11-23T17:02:56.416 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-23T17:03:37.530 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #233598, FileId: 0x1800000001a94f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T17:12:33.727 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T17:18:38.848 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #234023, FileId: 0x1cc00000001504e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T17:27:38.709 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T17:33:38.941 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #234524, FileId: 0x91000000029a3b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T17:39:44.501 Bm signature throttled:0x00002db31bed458f

2025-11-23T17:42:43.710 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T17:48:40.401 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #236197, FileId: 0x27c000000007243, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T17:52:06.401 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #236301, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T17:52:06.406 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #236302, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T17:52:16.399 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #236309, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T17:52:16.402 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #236310, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T17:52:16.416 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #236311, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T17:52:16.420 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #236312, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T17:57:48.701 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T18:01:37.875 Bm signature throttled:0x00002db31bed458f

2025-11-23T18:03:40.628 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #236934, FileId: 0x6a00000000d251, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T18:12:53.705 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T18:18:41.020 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #237121, FileId: 0x2f8000000018bc8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T18:27:58.693 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T18:28:43.553 Bm signature throttled:0x0000fab3228bcd4d

2025-11-23T18:33:41.081 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #237676, FileId: 0x44000000018813, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T18:43:03.685 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T18:48:41.261 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #237914, FileId: 0x51000000018813, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T18:52:06.894 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #237933, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T18:52:06.898 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #237934, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T18:52:16.899 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #237939, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T18:52:16.905 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #237940, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T18:52:16.906 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #237941, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T18:52:16.910 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #237942, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T18:57:56.339 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1519, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 84%

2025-11-23T18:57:56.339 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1420, Count: 145, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\SAW\5. Saw V (2008) Unrated 1080p HighCode.mkv, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 1243, Count: 87, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\62cd0332-1d46-4153-b98b-9278741af45c.tmp, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1215, Count: 200, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 1063, Count: 66, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\3958829a-ddc8-4ac6-ad0a-1e0445fbb4b3.tmp, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: RuntimeBroker.exe, Pid: 22236, TotalTime: 482, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-23T18:57:56.339 ProcessImageName: WmiPrvSE.exe, Pid: 23556, TotalTime: 289, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 74%

2025-11-23T18:57:56.339 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 225, Count: 48, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 165, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Data\b5\b51ab91a9119bc5c033542ca1dfe27f19ebf1073.file, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 152, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: taskhostw.exe, Pid: 5508, TotalTime: 120, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\TroubleshootingSvc.json, EstimatedImpact: 7%

2025-11-23T18:57:56.339 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\NvConfig\LocalizedConfig.json, EstimatedImpact: 1%

2025-11-23T18:57:56.339 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\6cea24f2-5468-4a27-9ae6-926e3a3072b0.tmp, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdatePolicy$, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 28%

2025-11-23T18:57:56.339 ProcessImageName: StoreDesktopExtension.exe, Pid: 10204, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 2%

2025-11-23T18:57:56.339 ProcessImageName: taskhostw.exe, Pid: 22152, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 4%

2025-11-23T18:57:56.339 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: nvngx_update.exe, Pid: 8020, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\1\files\nvngx_mapping.json, EstimatedImpact: 2%

2025-11-23T18:57:56.339 ProcessImageName: nvngx_update.exe, Pid: 14396, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NvProfileUpdaterPlugin\optimus\metadata.json, EstimatedImpact: 0%

2025-11-23T18:57:56.339 ProcessImageName: updater.exe, Pid: 21892, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-23T18:58:08.689 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T19:03:41.445 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #238062, FileId: 0x1f9000000002211, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T19:13:13.681 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T19:18:42.931 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #238342, FileId: 0x31d000000007236, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T19:28:18.678 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T19:33:42.931 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #238432, FileId: 0xcd00000001917c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T19:43:23.667 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T19:48:42.936 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #238701, FileId: 0x27f00000000947f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T19:52:07.616 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #238737, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T19:52:07.619 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #238738, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T19:52:17.626 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #238745, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T19:52:17.630 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #238746, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T19:58:28.671 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T20:01:25.166 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #238884, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T20:03:43.002 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #238895, FileId: 0x49500000000206f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T20:13:33.671 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T20:17:35.825 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\setup\logs\Install_2025-11-22_202808_18668-4376.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #239178, FileId: 0x4d000000028fd5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T20:17:35.899 Bm signature throttled:0x0000fab3228bcd4d

2025-11-23T20:18:43.466 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #239273, FileId: 0x68000000018813, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T20:28:38.659 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T20:33:43.471 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #239360, FileId: 0x99000000029a41, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T20:43:43.658 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T20:48:43.548 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #239491, FileId: 0x5a000000008f15, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T20:52:05.844 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #239510, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T20:52:05.855 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #239511, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T20:52:15.852 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #239516, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T20:52:15.853 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #239517, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T20:52:15.855 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #239518, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T20:52:15.857 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #239519, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T20:57:56.320 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 2842, Count: 174, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\de8bf2f3-58f9-4e3d-a912-7daa6479bae0.tmp, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 2070, Count: 119, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\adae8635-fb84-47c2-a393-de7f9c0d90fa.tmp, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1692, Count: 165, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\SAW\5. Saw V (2008) Unrated 1080p HighCode.mkv, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1519, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 84%

2025-11-23T20:57:56.320 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1230, Count: 201, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: RuntimeBroker.exe, Pid: 22236, TotalTime: 482, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-23T20:57:56.320 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 304, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: WmiPrvSE.exe, Pid: 23556, TotalTime: 289, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 74%

2025-11-23T20:57:56.320 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 225, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 211, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\d9e2d342-e2b9-419f-8a0e-d0b55ebe16c1.tmp, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 180, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 151, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 122, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: taskhostw.exe, Pid: 5508, TotalTime: 120, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\TroubleshootingSvc.json, EstimatedImpact: 7%

2025-11-23T20:57:56.320 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 120, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\9e84b86d-fb7d-48a2-ad11-1474979e6f81.tmp, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\NvConfig\LocalizedConfig.json, EstimatedImpact: 1%

2025-11-23T20:57:56.320 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 26264, TotalTime: 75, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Music\desktop.ini->(UTF-16LE), EstimatedImpact: 1%

2025-11-23T20:57:56.320 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 75, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdatePolicy$, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: taskhostw.exe, Pid: 18864, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 10%

2025-11-23T20:57:56.320 ProcessImageName: updater.exe, Pid: 14172, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\2ebe20bc-aa57-4db7-9253-0b4f70a232f2.tmp, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 45, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 28%

2025-11-23T20:57:56.320 ProcessImageName: StoreDesktopExtension.exe, Pid: 10204, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: svchost.exe, Pid: 23292, TotalTime: 31, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT502F.tmp, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: taskhostw.exe, Pid: 22152, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 4%

2025-11-23T20:57:56.320 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: nvngx_update.exe, Pid: 8020, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\1\files\nvngx_mapping.json, EstimatedImpact: 2%

2025-11-23T20:57:56.320 ProcessImageName: nvngx_update.exe, Pid: 14396, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NvProfileUpdaterPlugin\optimus\metadata.json, EstimatedImpact: 0%

2025-11-23T20:57:56.320 ProcessImageName: updater.exe, Pid: 21892, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-23T20:58:48.647 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T21:03:44.894 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #239688, FileId: 0x6000000000b8ed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T21:13:53.651 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T21:17:49.439 Bm signature throttled:0x0000fab3228bcd4d

2025-11-23T21:18:45.013 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #239893, FileId: 0xd900000001a1ef, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T21:28:58.647 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T21:33:45.550 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #239959, FileId: 0x6d00000000e080, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T21:44:03.639 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T21:48:45.892 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #240130, FileId: 0x4b200000000206f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T21:52:06.859 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #240242, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T21:52:06.862 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #240243, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T21:52:16.867 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #240258, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T21:52:16.870 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #240259, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T21:59:08.625 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T22:03:46.109 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #240418, FileId: 0xa60000000198d8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T22:14:13.621 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T22:18:46.197 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #240969, FileId: 0x83000000019e40, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T22:29:18.621 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T22:33:46.497 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #241167, FileId: 0x5700000000d845, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T22:44:23.618 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T22:48:47.736 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #241335, FileId: 0x14900000001cd9b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T22:52:05.345 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #241346, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T22:52:05.349 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #241347, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T22:52:15.356 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #241352, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T22:52:15.360 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #241353, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T22:57:56.290 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 4192, Count: 261, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\de8bf2f3-58f9-4e3d-a912-7daa6479bae0.tmp, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 2859, Count: 171, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\adae8635-fb84-47c2-a393-de7f9c0d90fa.tmp, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1692, Count: 165, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\SAW\5. Saw V (2008) Unrated 1080p HighCode.mkv, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1519, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 84%

2025-11-23T22:57:56.290 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1230, Count: 201, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: RuntimeBroker.exe, Pid: 22236, TotalTime: 482, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-23T22:57:56.290 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 425, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: WmiPrvSE.exe, Pid: 23556, TotalTime: 289, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 74%

2025-11-23T22:57:56.290 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 257, Count: 33, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\d9e2d342-e2b9-419f-8a0e-d0b55ebe16c1.tmp, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 256, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 225, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 225, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 165, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 122, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: taskhostw.exe, Pid: 5508, TotalTime: 120, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\TroubleshootingSvc.json, EstimatedImpact: 7%

2025-11-23T22:57:56.290 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\9e84b86d-fb7d-48a2-ad11-1474979e6f81.tmp, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 105, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdatePolicy$, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: backgroundTaskHost.exe, Pid: 10896, TotalTime: 105, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446->(UTF-16LE), EstimatedImpact: 23%

2025-11-23T22:57:56.290 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\NvConfig\LocalizedConfig.json, EstimatedImpact: 1%

2025-11-23T22:57:56.290 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 26264, TotalTime: 75, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Music\desktop.ini->(UTF-16LE), EstimatedImpact: 1%

2025-11-23T22:57:56.290 ProcessImageName: taskhostw.exe, Pid: 18864, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 10%

2025-11-23T22:57:56.290 ProcessImageName: taskhostw.exe, Pid: 23820, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 5%

2025-11-23T22:57:56.290 ProcessImageName: updater.exe, Pid: 14172, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\2ebe20bc-aa57-4db7-9253-0b4f70a232f2.tmp, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 45, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 28%

2025-11-23T22:57:56.290 ProcessImageName: StoreDesktopExtension.exe, Pid: 10204, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: svchost.exe, Pid: 23292, TotalTime: 31, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT502F.tmp, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: taskhostw.exe, Pid: 22152, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 4%

2025-11-23T22:57:56.290 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: taskhostw.exe, Pid: 13008, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-23T22:57:56.290 ProcessImageName: nvngx_update.exe, Pid: 8020, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\1\files\nvngx_mapping.json, EstimatedImpact: 2%

2025-11-23T22:57:56.290 ProcessImageName: updater.exe, Pid: 21892, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NvProfileUpdaterPlugin\optimus\metadata.json, EstimatedImpact: 0%

2025-11-23T22:57:56.290 ProcessImageName: nvngx_update.exe, Pid: 14396, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-23T22:59:28.612 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T23:03:49.041 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #241483, FileId: 0xa3000000000101, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T23:14:33.611 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T23:17:51.495 Bm signature throttled:0x0000fab3228bcd4d

2025-11-23T23:18:49.318 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #241759, FileId: 0x1a000000029b1d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T23:29:38.608 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T23:33:49.754 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #241872, FileId: 0x75000000029b1c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T23:44:43.599 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-23T23:48:50.138 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #242050, FileId: 0x6800000001d492, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T23:52:05.947 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #242078, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T23:52:05.951 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #242079, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T23:52:15.949 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #242086, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T23:52:15.956 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #242087, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T23:52:15.964 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #242088, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T23:52:15.970 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #242089, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-23T23:59:48.591 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T00:03:50.270 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #242202, FileId: 0x21000000029b1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T00:14:53.587 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T00:17:08.592 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3

2025-11-24T00:17:08.595 Job Notification: New process added to job (12552)

2025-11-24T00:17:08.600 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched

2025-11-24T00:17:08.601 Aggressive catchup quick scan threshold: 5183961991576 / 25920000000000

2025-11-24T00:17:08.603 Job Notification: New process added to job (10468)

2025-11-24T00:17:08.610 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:12552] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:10468]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-24T00:17:08.656 Job Notification: New process added to job (13288)

2025-11-24T00:17:08.659 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched

2025-11-24T00:17:08.660 Job Notification: New process added to job (25548)

2025-11-24T00:17:08.667 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:13288] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:25548]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-24T00:17:08.702 Job Notification: New process added to job (12704)

2025-11-24T00:17:08.705 Task(GetDeviceTicket -AccessKey B77F0AA2-BFA2-98DD-9AB2-55711A89CFD3 ) launched as network service

2025-11-24T00:17:09.122 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-24T00:17:09.122 [RTP] Duplicating the current plugin configuration object...

2025-11-24T00:17:09.122 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-24T00:17:09.122 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-24T00:17:09.122 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-24T00:17:09.122 [RTP] No config change detected. Not updating plugin configuration.

2025-11-24T00:17:09.122 [RTP] No config changes found. No configuration switch.

2025-11-24T00:17:09.122 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-24T00:17:09.196 Job Notification: Process exited from job (12704)

2025-11-24T00:17:09.401 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-24T00:17:09.401 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T00:17:09.401 [Cloud] Queued cloud request.

2025-11-24T00:17:09.401 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-24T00:17:09.401 [Cloud] Dequeued cloud request.

2025-11-24T00:17:09.401 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T00:17:09.402 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0

2025-11-24T00:17:09.402 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T00:17:09.402 [Cloud] Queued cloud request.

2025-11-24T00:17:09.402 [Cloud] Dequeued cloud request.

2025-11-24T00:17:09.403 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T00:17:09.532 [Cloud] End of cloud request.

2025-11-24T00:17:09.577 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-24T00:17:09.578 [Cloud] End of cloud request.

2025-11-24T00:17:09.927 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T00:17:22.274 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\3CB2F8C6-23F8-4961-A7CC-00836B67FEA628f4.1dc5cd7b32cc8d8

2025-11-24T00:17:22.305 Verifying engine and signature files (source: 0) ...

2025-11-24T00:17:22.305 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8AD3FCA9-A11B-4FA5-B16E-882A0D1E5765}\mpengine.dll] due to PPL.

2025-11-24T00:17:22.305 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8AD3FCA9-A11B-4FA5-B16E-882A0D1E5765}\mpasbase.vdm] (file in cache)

2025-11-24T00:17:22.305 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8AD3FCA9-A11B-4FA5-B16E-882A0D1E5765}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-24T00:17:22.314 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8AD3FCA9-A11B-4FA5-B16E-882A0D1E5765}\mpasdlta.vdm]

2025-11-24T00:17:22.314 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8AD3FCA9-A11B-4FA5-B16E-882A0D1E5765}\mpavbase.vdm] (file in cache)

2025-11-24T00:17:22.314 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8AD3FCA9-A11B-4FA5-B16E-882A0D1E5765}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-24T00:17:22.322 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8AD3FCA9-A11B-4FA5-B16E-882A0D1E5765}\mpavdlta.vdm]

2025-11-24T00:17:22.400 [Engine] IsHybridMode: 0

2025-11-24T00:17:22.401 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-24T00:17:22.411 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-19670A5F375419FD1352E79A95CD576E97E2B108.bin): 0x00000002

2025-11-24T00:17:22.412 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-19670A5F375419FD1352E79A95CD576E97E2B108.bin)

2025-11-24T00:17:22.412 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-24T00:17:22.412 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-24T00:17:22.412 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-24T00:17:22.412 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-24T00:17:27.730 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-24T00:17:27.731 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-24T00:17:27.735 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7A9CA660, lRefCount: 5, hr=0

2025-11-24T00:17:27.735 [Engine] New active engine 00007FFE7F1CA660 replacing engine 00007FFE7A9CA660. Number of active engines: 2

2025-11-24T00:17:27.737 EngineInit:Global ASOC is enabled

2025-11-24T00:17:27.737 EngineInit:ASOO is enabled for developer volumes

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.766 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T00:17:27.767 MpWriteUupSignatureVersion 1.441.442.0, hr = 0

2025-11-24T00:17:27.768 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-24T00:17:27.780 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-24T00:17:27.781 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-24T00:17:27.781 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-24T00:17:27.781 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-24T00:17:27.781 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-24T00:17:27.795 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-24T00:17:27.795 [Plugin] Initializing RTP plugin state...

2025-11-24T00:17:27.796 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-24T00:17:27.796 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 23 - 2025 17:57:56

Last Perf: 11 - 23 - 2025 17:57:56

First RTP Scan: 11 - 23 - 2025 17:57:57

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:807

  Misses:6245

BM Queue:0,37,0

  Proc:0,36,0

  File:0,14,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:242521

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1272289248

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:21

  TotalStreamCon:15000

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:1070564

   TotalHits:1791868

   InstanceCacheInserts:79952

   InstanceCacheUpdates:0

   InstanceCacheDeletes:60866

   InstanceCacheHits:4624

   InstanceCacheMisses:304222

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (703/706)

   Success: 706, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-24T00:17:27.796 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8AD3FCA9-A11B-4FA5-B16E-882A0D1E5765}

2025-11-24T00:17:27.796 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9998FD2-F6BB-4E88-A55D-5B9B576C6CA2}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9998FD2-F6BB-4E88-A55D-5B9B576C6CA2}\mpasbase.vdm in use, hr=0x80070020

2025-11-24T00:17:27.796 [SCC][CID=628676437_14992] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-24T00:17:27.797 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-24T00:17:27.797 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-24T00:17:27.797 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-24T00:17:27.797 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-24T00:17:27.797 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-24T00:17:27.797 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-24-2025 00:17:27

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-24-2025 00:17:27

2025-11-24T00:17:27.800 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-24T00:17:27.800 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-24T00:17:27.800 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-24T00:17:27.800 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-24-2025 00:17:27

END TDT(U) telemetry



2025-11-24T00:17:27.802 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T00:17:27.803 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-24T00:17:27.803 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-24T00:17:27.803 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-24T00:17:27.803 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-24T00:17:27.803 MdCoreSvc is supported in this platform and OS

Signature updated on 11-24-2025 00:17:27

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.442.0

AV Signature Version: 1.441.442.0

************************************************************

2025-11-24T00:17:27.804 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-24T00:17:27.804 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\3CB2F8C6-23F8-4961-A7CC-00836B67FEA628f4.1dc5cd7b32cc8d8

2025-11-24T00:17:27.822 Process scan (postsignatureupdatescan) started.

2025-11-24T00:17:27.839 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-24T00:17:27.841 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

Signature updated via MicrosoftUpdateServer on 11-24-2025 00:17:27

************************************************************

2025-11-24T00:17:27.882 Job Notification: Process exited from job (13288)

2025-11-24T00:17:27.883 Job Notification: Process exited from job (25548)

2025-11-24T00:17:27.916 Job Notification: Process exited from job (12552)

2025-11-24T00:17:27.917 Job Notification: Process exited from job (10468)

2025-11-24T00:17:27.975 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-24T00:17:27.975 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-24T00:17:27.975 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-24T00:17:27.975 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-24T00:17:27.975 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-24T00:17:27.977 [Engine] Engine 00007FFE7A9CA660 no longer in use. Number of active engines: 1

2025-11-24T00:17:27.977 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-24T00:17:27.977 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-24T00:17:28.113 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 4997, Count: 318, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\de8bf2f3-58f9-4e3d-a912-7daa6479bae0.tmp, EstimatedImpact: 0%

2025-11-24T00:17:28.113 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 3343, Count: 207, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\adae8635-fb84-47c2-a393-de7f9c0d90fa.tmp, EstimatedImpact: 0%

2025-11-24T00:17:28.113 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1769, Count: 167, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\cache\httpclient\0fb243ded9649ae6d18059c674a4ae00, EstimatedImpact: 0%

2025-11-24T00:17:28.113 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1519, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 84%

2025-11-24T00:17:28.113 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1230, Count: 201, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-24T00:17:28.113 ProcessImageName: RuntimeBroker.exe, Pid: 22236, TotalTime: 482, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-24T00:17:28.113 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 470, Count: 30, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T00:17:28.113 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 300, Count: 44, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-24T00:17:28.113 ProcessImageName: WmiPrvSE.exe, Pid: 23556, TotalTime: 289, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 74%

2025-11-24T00:17:28.113 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 286, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-24T00:17:28.113 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 257, Count: 33, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\d9e2d342-e2b9-419f-8a0e-d0b55ebe16c1.tmp, EstimatedImpact: 0%

2025-11-24T00:17:28.113 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 18668, TotalTime: 225, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-24T00:17:28.113 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 180, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdatePolicy$, EstimatedImpact: 0%

2025-11-24T00:17:28.113 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 165, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 0%

2025-11-24T00:17:28.113 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 136, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-11-24T00:17:28.113 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 122, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context, EstimatedImpact: 0%

2025-11-24T00:17:28.128 [Engine] RSIG_UNLOADENGINE, 00007FFE7A9CA660, err=0x0

2025-11-24T00:17:28.144 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9998FD2-F6BB-4E88-A55D-5B9B576C6CA2} removed

2025-11-24T00:17:28.281 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-24T00:17:28.288 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-24T00:17:28.288 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-24T00:17:28.288 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-24T00:17:28.288 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-24T00:17:28.288 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-24T00:17:28.288 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-24T00:17:28.291 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-24T00:17:28.291 [RTP] Duplicating the current plugin configuration object...

2025-11-24T00:17:28.291 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-24T00:17:28.291 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-24T00:17:28.291 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-24T00:17:28.291 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-24T00:17:28.291 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-24T00:17:28.291 [RTP] No config change detected. Not updating plugin configuration.

2025-11-24T00:17:28.291 [RTP] No config changes found. No configuration switch.

2025-11-24T00:17:28.291 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-24T00:17:28.292 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-24T00:17:28.292 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-24T00:17:28.292 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-24T00:17:28.292 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-24T00:17:28.292 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-24T00:17:28.292 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-24T00:17:28.292 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-24T00:17:28.292 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-24T00:17:28.292 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-24T00:17:28.292 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-24T00:17:28.292 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-24T00:17:28.292 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-24T00:17:28.292 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-24T00:17:28.292 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-24T00:17:28.292 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-24T00:17:28.292 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T00:17:28.294 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T00:17:28.295 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T00:17:28.297 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T00:17:28.298 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T00:17:28.300 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 7813748(ms) from now at 03:27 (02:27 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-24T00:17:29.820 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-24T00:17:29.823 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-24T00:17:29.824 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-24T00:17:30.846 [RTP] Duplicating the current plugin configuration object...

2025-11-24T00:17:30.846 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-24T00:17:30.846 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-24T00:17:30.846 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-24T00:17:30.846 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-24T00:17:33.195 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-24T00:17:33.195 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T00:17:33.195 [Cloud] Queued cloud request.

2025-11-24T00:17:33.195 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-24T00:17:33.196 [Cloud] Dequeued cloud request.

2025-11-24T00:17:33.196 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T00:17:33.510 [Cloud] End of cloud request.

2025-11-24T00:17:34.027 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T00:17:41.926 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-24T00:17:41.927 Process scan (postsignatureupdatescan) completed.

2025-11-24T00:18:50.358 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #242659, FileId: 0x2700000001a959, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T00:22:27.778 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-24T00:29:58.579 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T00:33:50.737 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #242895, FileId: 0x1e000000008c74, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T00:45:03.578 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T00:48:50.975 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #243380, FileId: 0x41000000023e6e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T00:52:07.438 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #243397, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T00:52:07.441 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #243398, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T00:52:17.454 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #243403, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T00:52:17.462 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #243404, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T01:00:08.582 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T01:03:51.230 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #243530, FileId: 0x22000000029ac6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T01:15:13.574 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T01:17:53.520 Bm signature throttled:0x0000fab3228bcd4d

2025-11-24T01:18:51.277 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #243957, FileId: 0x2550000000132c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T01:30:18.571 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T01:33:51.440 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #244019, FileId: 0xa50000000105f6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T01:39:44.976 [AutoPurge] Verification Routine tasks have started.

2025-11-24T01:39:44.977 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-24T01:39:44.985 [AutoPurge] Routine task for Cache Maintenance has started.

2025-11-24T01:39:44.985 [AutoPurge] Routine task for Cache Maintenance ...

2025-11-24T01:39:44.985 [AutoPurge] Routine task for MpSFCBuild ...

2025-11-24T01:39:44.985 [AutoPurge] MpCmIsBuildCompleted() - S_OK

2025-11-24T01:39:44.985 [AutoPurge] MpSignalMaintenanceMode ...

2025-11-24T01:39:44.987 [AutoPurge] Cleanup Routine tasks have started.

2025-11-24T01:39:44.989 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0)

2025-11-24T01:39:44.989 [AutoPurge] Purged 0 expired detection item(s) from a total of 0.

2025-11-24T01:39:44.989 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds)

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:65538

Start time:11-24-2025 01:39:44

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-24-2025 01:39:44

2025-11-24T01:39:44.991 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ...

2025-11-24T01:39:44.991 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0 ...

2025-11-24T01:39:44.991 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0 ...

2025-11-24T01:39:44.991 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ...

2025-11-24T01:39:44.991 [AutoPurge] Cleanup Routine tasks have ended.

2025-11-24T01:39:44.992 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:9478E89F-6708-42FB-ACBD-CE142CC0152D, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1)

2025-11-24T01:39:44.992 Scheduled scan with Id 9478E89F-6708-42FB-ACBD-CE142CC0152D configured CPU priority: normal (LowCpuPriority: 0)

2025-11-24T01:39:44.993 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build.

2025-11-24T01:39:44.993 [SFC] System file cache build is not needed (already completed)

2025-11-24T01:39:44.993 QuickScan:ScanID:9478E89F-6708-42FB-ACBD-CE142CC0152D: Quick Scan skipped since it already ran during the past 7 days

2025-11-24T01:39:44.993 QuickScan:ScanID:9478E89F-6708-42FB-ACBD-CE142CC0152D: Quick scan finished with error 1223

2025-11-24T01:39:44.993 OnDemandScanWorker: Scan Cancelled! scanId:9478E89F-6708-42FB-ACBD-CE142CC0152D, hr = 0x80508018

!ERROR

Begin Quick Scan

Scan ID:{9478E89F-6708-42FB-ACBD-CE142CC0152D}

Scan Source:1

Start Time:11-24-2025 01:39:44

Unsuccessful Scan

Return Code:1223

************************************************************



2025-11-24T01:39:45.041 EnsureProtectedFolderAcls(), hr = 0x0

2025-11-24T01:39:45.043 [AutoPurge] MpReinforceServiceAcls: 0

2025-11-24T01:39:45.048 Engine:Setting original file name "WIARPC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiarpc.dll.mui_0c913b87", hr=0x0

2025-11-24T01:39:45.054 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0

2025-11-24T01:39:45.057 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed.

2025-11-24T01:39:45.058 [AutoPurge] Verification Routine tasks have ended.

2025-11-24T01:39:45.071 Engine:Setting original file name "nlsbres.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..ocale-nls.resources_31bf3856ad364e35_10.0.26100.4484_nb-no_339b02f7f61c146e\winnlsres.dll.mui", hr=0x0

2025-11-24T01:39:45.313 Engine:Setting original file name "IEXPLORE.EXE" for "c:\program files (x86)\internet explorer\en-us\iexplore.exe.mui", hr=0x0

2025-11-24T01:39:45.337 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_en-us_1258b52c940aadb7_winload.efi.mui_35ee487d", hr=0x0

2025-11-24T01:39:45.770 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sr-..-rs_d1943ecc8317ab66_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-24T01:39:45.903 Engine:Setting original file name " " for "c:\program files (x86)\steam\bin\cef\cef.win7x64\dxcompiler.dll", hr=0x0

2025-11-24T01:39:45.945 Engine:Setting original file name "dual_engine_adapter.dll" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\dual_engine_adapter_x64.dll", hr=0x0

2025-11-24T01:39:46.073 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\winsxs\wow64_microsoft-windows-bcp47languages_31bf3856ad364e35_10.0.26100.7019_none_40ac55a9bb1ab239\bcp47langs.dll", hr=0x0

2025-11-24T01:39:46.084 Engine:Setting original file name "MAPI32.DLL.MUI" for "c:\windows\system32\nb-no\mapistub.dll.mui", hr=0x0

2025-11-24T01:39:46.224 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-24T01:39:46.260 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_ar-sa_af75f4ef024a79a1_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-24T01:39:46.320 Engine:Setting original file name "Apphelp" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a4bb088d5aa4193f97a4bdef0c1f8c71\apphelp.dll.mui", hr=0x0

2025-11-24T01:39:46.363 Engine:Setting original file name "F12Chooser.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-ie-iechooser.resources_31bf3856ad364e35_11.0.26100.1_nb-no_a7630c027f26ac69\iechooser.exe.mui", hr=0x0

2025-11-24T01:39:46.394 Engine:Setting original file name "THEMESERVICE.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-themeservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_5e5bf64d5b3ca824_themeservice.dll.mui_9e71f1ab", hr=0x0

2025-11-24T01:39:46.427 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_ad141a64b8fd6038_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:46.501 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\wow64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.26100.712_none_5cfec91758ee0662\windows.security.credentials.ui.credentialpicker.dll", hr=0x0

2025-11-24T01:39:46.553 Engine:Setting original file name "mavinject32.exe" for "c:\windows\winsxs\wow64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_592d553ad6e77100\mavinject.exe", hr=0x0

2025-11-24T01:39:46.680 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_bfcde09794ad7074_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-24T01:39:46.686 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\zh-cn\memtest.efi.mui", hr=0x0

2025-11-24T01:39:46.785 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_nb-no_022ea2e874b2cab6_winresume.efi.mui_f412814e", hr=0x0

2025-11-24T01:39:46.840 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lt-lt_11cd7cc1c62eb609_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:47.000 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-24T01:39:47.003 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-24T01:39:47.004 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-24T01:39:47.103 Engine:Setting original file name "WmiApSrv.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiapsrv.exe.mui_b1567840", hr=0x0

2025-11-24T01:39:47.152 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kk-kz_bb9a512b689c9b87_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:47.177 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_b5793645604cae79_memtest.efi.mui_71e15c22", hr=0x0

2025-11-24T01:39:47.192 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_he-il_3abd6f82e93c03e5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:47.199 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.26100.1_en-us_c3d82ef5c0380efa_wudfpf.sys.mui_f61e9e86", hr=0x0

2025-11-24T01:39:47.440 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaihdrx.dll", hr=0x0

2025-11-24T01:39:47.571 Engine:Setting original file name "l3codec.acm.mui" for "c:\windows\system32\nb-no\l3codeca.acm.mui", hr=0x0

2025-11-24T01:39:47.675 Engine:Setting original file name "w32topl.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_10.0.26100.1_none_cbd0eec659c2eb5c_w32topl.dll_1a0f388b", hr=0x0

2025-11-24T01:39:47.687 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ms-my_6f80e6fda2cebe8f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:47.951 Engine:Setting original file name "NVPTXJITCOMPILER32.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvptxjitcompiler64.dll", hr=0x0

2025-11-24T01:39:47.988 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5de87d4a39ffc584310f0b06dff9fcd0\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-24T01:39:48.059 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_38f499759ea365c4_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:48.106 Engine:Setting original file name "ddputils.lib.mui" for "c:\windows\system32\nb-no\ddputils.dll.mui", hr=0x0

2025-11-24T01:39:48.206 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kn-in_6e7a81f857a45cbe_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:48.235 Engine:Setting original file name "officeimm.odf" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\office.odf", hr=0x0

2025-11-24T01:39:48.420 Engine:Setting original file name ""AcGenral.dll"" for "c:\windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_10.0.26100.7019_none_a8119654a230db44\acgenral.dll", hr=0x0

2025-11-24T01:39:48.494 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sr-..-rs_7327597d7718c882_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:48.507 Engine:Setting original file name "Hyper-V Host Compute Service Diagnostics Tool" for "c:\windows\winsxs\amd64_hyperv-compute-cont..sticstool.resources_31bf3856ad364e35_10.0.26100.1_en-us_61074b8c7d2f38cf\hcsdiag.exe.mui", hr=0x0

2025-11-24T01:39:48.521 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.32530.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-24T01:39:48.555 Engine:Setting original file name "davsvc.dll.mui" for "c:\windows\system32\nb-no\webclnt.dll.mui", hr=0x0

2025-11-24T01:39:48.584 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\nb-no\wsepno.dll.mui", hr=0x0

2025-11-24T01:39:48.595 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x0

2025-11-24T01:39:48.627 Engine:Setting original file name "bootstr.exe.mui" for "c:\windows\system32\nb-no\bootstr.dll.mui", hr=0x0

2025-11-24T01:39:48.643 Engine:Setting original file name "msvcp140_2_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_2_app.dll", hr=0x0

2025-11-24T01:39:48.852 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-libraryloader-l1-1-0.dll", hr=0x0

2025-11-24T01:39:48.857 Engine:Setting original file name "dvsvc.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..rationsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_5c873aff49ea76e6\dcsvc.dll.mui", hr=0x0

2025-11-24T01:39:48.885 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_qps-ploc_5c9773f9ea1ce396_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:48.887 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_cs-cz_7086b4650c9e547c_memtest.efi.mui_71e15c22", hr=0x0

2025-11-24T01:39:48.976 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa78d0db4729269ff4beb393d45ca94a\dnsapi.dll.mui", hr=0x0

2025-11-24T01:39:48.992 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hr-hr_86baa9ad7eed6d52_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:49.011 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-24T01:39:49.014 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-24T01:39:49.014 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-24T01:39:49.036 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ja-jp_ed01f249e53f7235_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-24T01:39:49.041 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-file-l1-1-0.dll", hr=0x0

2025-11-24T01:39:49.066 Engine:Setting original file name "D3DX10.dll" for "c:\windows\system32\d3dx10_43.dll", hr=0x0

2025-11-24T01:39:49.134 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_da-dk_f5abc0a0339bc397_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:49.221 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-conio-l1-1-0.dll", hr=0x0

2025-11-24T01:39:49.340 Engine:Setting original file name "Auto Enrollment DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..utoenroll.resources_31bf3856ad364e35_10.0.26100.1_en-us_b82b35a9c2228d6b\pautoenr.dll.mui", hr=0x0

2025-11-24T01:39:49.423 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\windows\winsxs\amd64_microsoft-textinput-helpers.resources_31bf3856ad364e35_10.0.26100.1_nb-no_2c9a52bac4b766e3\ime_textinputhelpers.dll.mui", hr=0x0

2025-11-24T01:39:49.436 Engine:Setting original file name "Ribbons" for "c:\windows\winsxs\amd64_microsoft-windows-ribbons.resources_31bf3856ad364e35_10.0.26100.1_en-us_f85e1124efc279b5\ribbons.scr.mui", hr=0x0

2025-11-24T01:39:49.475 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_18153ede37451276\memtest.exe.mui", hr=0x0

2025-11-24T01:39:49.521 Engine:Setting original file name "scecli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\978b70ff94ed14c641fe52c5237facec\scecli.dll.mui", hr=0x0

2025-11-24T01:39:49.539 Engine:Setting original file name "mpsdrv.sys.mui" for "c:\windows\winsxs\backup\amd64_networking-mpssvc-drv.resources_31bf3856ad364e35_10.0.26100.1_nb-no_05849dc2762f9d2d_mpsdrv.sys.mui_b2aea3b6", hr=0x0

2025-11-24T01:39:49.557 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-tw_21b451d70c8c2957_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-24T01:39:49.710 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_2b309b875a6f3e1e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:49.774 Engine:Setting original file name "Vulkan Runtime" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\vulkan-1.dll", hr=0x0

2025-11-24T01:39:49.813 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-p..i-ntprint.resources_31bf3856ad364e35_10.0.26100.1_en-us_6ff199c21e8ad886\ntprint.dll.mui", hr=0x0

2025-11-24T01:39:49.870 Engine:Setting original file name "bootstr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..environment-strings_31bf3856ad364e35_10.0.26100.1_none_f575b80d757af501\bootstr.dll", hr=0x0

2025-11-24T01:39:49.896 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_zh-cn_fd81e6b68df3d1a9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:50.066 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-24T01:39:50.143 Engine:Setting original file name "liblzma.dll" for "c:\program files\windowsapps\microsoft.6365217ce6eb4_102.2509.19002.0_x64__8wekyb3d8bbwe\lzma.dll", hr=0x0

2025-11-24T01:39:50.232 Engine:Setting original file name "wuapi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\uus\x86\nb-no\c120e79170c204b0e5f1ece795e86e83\wuapicore.dll.mui", hr=0x0

2025-11-24T01:39:50.294 Engine:Setting original file name "Ontology.dll" for "c:\users\serverpc\appdata\local\nvidia corporation\nvidia app\nvbackend\applicationontology\ontology64.dll", hr=0x0

2025-11-24T01:39:50.427 Engine:Setting original file name "VpnSohDesktop.dll" for "c:\windows\system32\windows.perception.stub.dll", hr=0x0

2025-11-24T01:39:50.512 Engine:Setting original file name "kernel32" for "c:\windows\syswow64\kernel32.dll", hr=0x0

2025-11-24T01:39:50.543 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.549981c3f5f10_4.2308.1005.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-24T01:39:50.735 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_b38289243d899c4c_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:50.797 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_82eb3d34cd19fa50_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:50.937 Engine:Setting original file name "Steamclient.dll" for "c:\program files (x86)\steam\steamclient64.dll", hr=0x0

2025-11-24T01:39:51.003 Engine:Setting original file name "VrdUmde.dll" for "c:\windows\winsxs\amd64_gpuvirtualizationumed_31bf3856ad364e35_10.0.26100.1150_none_17421023ba072774\vrdumed.dll", hr=0x0

2025-11-24T01:39:51.015 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.efi.mui", hr=0x0

2025-11-24T01:39:51.144 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.winmd", hr=0x0

2025-11-24T01:39:51.447 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_lt-lt_ba1ae95b692b9594_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-24T01:39:51.549 Engine:Setting original file name "windows.ui.xaml.resources.win81.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ctui-resourceswin81_31bf3856ad364e35_10.0.26100.1301_none_b7b52abe3d381205_windows.ui.xaml.resources.win81.dll_d426e245", hr=0x0

2025-11-24T01:39:51.676 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-timezone-l1-1-0.dll", hr=0x0

2025-11-24T01:39:51.715 Engine:Setting original file name "jscript9.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\c3275836e276aea69afa458336037853\jscript9legacy.dll.mui", hr=0x0

2025-11-24T01:39:52.009 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x0

2025-11-24T01:39:52.061 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-profile-l1-1-0.dll", hr=0x0

2025-11-24T01:39:52.284 Engine:Setting original file name "Windows.FileExplorer.Common.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\84c8a2171c12d91e854ffb6a27b39453\windows.fileexplorer.common.dll.mui", hr=0x0

2025-11-24T01:39:52.483 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.26100.1_en-us_99a73e6649d69102\ndisimplatcim.dll.mui", hr=0x0

2025-11-24T01:39:52.529 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-24T01:39:52.597 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-localization-l1-2-0.dll", hr=0x0

2025-11-24T01:39:52.654 Engine:Setting original file name "Placeholder.dll" for "c:\windows\winsxs\x86_netfx4-penimc_v0400_b03f5f7f11d50a3a_4.0.15920.102_none_21046749883d249b\penimc_v0400.dll", hr=0x0

2025-11-24T01:39:52.676 Engine:Setting original file name "NvCamera.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\nvcameraallowlisting32.dll", hr=0x0

2025-11-24T01:39:52.928 Engine:Setting original file name ".NET Host Policy -" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\hostpolicy.dll", hr=0x0

2025-11-24T01:39:53.307 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sv-se_cac4b549037c269f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:53.311 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-24T01:39:53.342 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-24T01:39:53.365 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\winsxs\amd64_microsoft-windows-appx-deployment-server_31bf3856ad364e35_10.0.26100.7171_none_fd3893d466902045\applytrustoffline.exe", hr=0x0

2025-11-24T01:39:53.499 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\wow64_microsoft-windows-a..on-logger.resources_31bf3856ad364e35_10.0.26100.1_en-us_a0e09b8ec526451d\aeevts.dll.mui", hr=0x0

2025-11-24T01:39:53.589 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-24T01:39:53.763 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\4f8d3bb436c7\apex_particleschecked_x86.dll", hr=0x0

2025-11-24T01:39:53.834 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_it-it_72537c4985790e22_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:53.950 Engine:Setting original file name "EsclWiaDriver.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_esclwiadriver.dll.mui_d4a5b959", hr=0x0

2025-11-24T01:39:54.063 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_da-dk_be356ba870c91e76\msprivs.dll.mui", hr=0x0

2025-11-24T01:39:54.065 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-24T01:39:54.077 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_es-es_bdfd06f72820647a_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-24T01:39:54.179 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pl-pl\msprivs.dll.mui", hr=0x0

2025-11-24T01:39:54.195 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-24T01:39:54.214 Engine:Setting original file name "rmactivate.exe.mui" for "c:\windows\syswow64\en-us\rmactivate_isv.exe.mui", hr=0x0

2025-11-24T01:39:54.430 Engine:Setting original file name "apex.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\73be2921551d\apex_turbulencefschecked_x86.dll", hr=0x0

2025-11-24T01:39:54.455 Engine:Setting original file name "ScrCons" for "c:\windows\winsxs\amd64_microsoft-windows-w..consumers.resources_31bf3856ad364e35_10.0.26100.1_en-us_5d0e2df387a86d5d\scrcons.exe.mui", hr=0x0

2025-11-24T01:39:54.462 Engine:Setting original file name "PtpProv" for "c:\windows\winsxs\amd64_microsoft-windows-t..-provider.resources_31bf3856ad364e35_10.0.26100.1_en-us_eec70481b215edf0\ptpprov.dll.mui", hr=0x0

2025-11-24T01:39:54.467 Engine:Setting original file name "GbrtClient.dll" for "c:\program files\windowsapps\spotifyab.spotifymusic_1.276.298.0_x64__zpdnekdrzrea0\microsoft.gaming.xboxgamebar.dll", hr=0x0

2025-11-24T01:39:54.505 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\resources\themes\aero\nb-no\aerolite.msstyles.mui", hr=0x0

2025-11-24T01:39:54.668 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_cd255b4d1be69fe9_winload.efi.mui_35ee487d", hr=0x0

2025-11-24T01:39:54.701 Engine:Setting original file name "pegi.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_en-us_58f534214187451c\pegi.rs.mui", hr=0x0

2025-11-24T01:39:54.706 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-iexpress.resources_31bf3856ad364e35_11.0.26100.1_en-us_f84c0d683fdc407b\wextract.exe.mui", hr=0x0

2025-11-24T01:39:55.145 Engine:Setting original file name "updater.exe" for "c:\program files (x86)\google\update\googleupdate.exe", hr=0x0

2025-11-24T01:39:55.286 Engine:Setting original file name "ServicingBase.dll" for "c:\windows\system32\servicingcommon.dll", hr=0x0

2025-11-24T01:39:55.306 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.exe.mui", hr=0x0

2025-11-24T01:39:55.486 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\vulkan-1.dll", hr=0x0

2025-11-24T01:39:55.532 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_c77eb7b609c47f12\diagpackage.dll.mui", hr=0x0

2025-11-24T01:39:55.645 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\system32\wbem\en-us\netadaptercim.dll.mui", hr=0x0

2025-11-24T01:39:55.668 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\syswow64\nb-no\wextract.exe.mui", hr=0x0

2025-11-24T01:39:55.777 Engine:Setting original file name "NvTelemetry.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvinstallerutil.dll", hr=0x0

2025-11-24T01:39:55.823 Engine:Setting original file name "NvMessageBusBroadcast.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\localsystem\_nvmsgbusbroadcast.dll", hr=0x0

2025-11-24T01:39:56.027 Engine:Setting original file name "NVOPENCL.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvopencl64.dll", hr=0x0

2025-11-24T01:39:56.034 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x0

2025-11-24T01:39:56.105 Engine:Setting original file name "Ribbons" for "c:\windows\system32\nb-no\ribbons.scr.mui", hr=0x0

2025-11-24T01:39:56.250 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_de-de_bb6100e4729f7310\msprivs.dll.mui", hr=0x0

2025-11-24T01:39:56.403 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_en-gb_943f70b729277031_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:56.430 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570\dnsapi.dll.mui", hr=0x0

2025-11-24T01:39:56.432 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x0

2025-11-24T01:39:56.517 Engine:Setting original file name "expediteupdater" for "c:\program files\microsoft update health tools\expediteupdater.exe", hr=0x0

2025-11-24T01:39:56.563 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5fc58c6fab06ca1651cc2f24f6b3294e\dnsapi.dll.mui", hr=0x0

2025-11-24T01:39:56.677 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-24T01:39:56.715 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-24T01:39:56.780 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pt-br\msprivs.dll.mui", hr=0x0

2025-11-24T01:39:56.835 Engine:Setting original file name "vcomp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-24T01:39:56.881 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_pt-br_45b1cef334010120_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-24T01:39:56.925 Engine:Setting original file name "DismProvPS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..ing-management-core_31bf3856ad364e35_10.0.26100.7019_none_c721839bdaa557fd\dismcoreps.dll", hr=0x0

2025-11-24T01:39:57.028 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x0

2025-11-24T01:39:57.061 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.efi", hr=0x0

2025-11-24T01:39:57.064 Engine:Setting original file name "ProfSvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-profsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_63afbc426d007f3f_profsvc.dll.mui_32482e9e", hr=0x0

2025-11-24T01:39:57.167 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2cfe4c864d785675f415b7e6aa962e4\msinfo32.exe.mui", hr=0x0

2025-11-24T01:39:57.368 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\6dfad87d7e49db84e1a96c1c1b32fef6\msidntld.dll.mui", hr=0x0

2025-11-24T01:39:57.383 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7\memtest.exe.mui", hr=0x0

2025-11-24T01:39:57.484 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pa-in_9c6b14ad918eaffd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:57.506 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ar-sa_51090f9ff64b96bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:57.552 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.26100.1_en-us_c94c280205b42295\bubbles.scr.mui", hr=0x0

2025-11-24T01:39:57.767 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\nb-no\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x0

2025-11-24T01:39:57.788 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-console-l1-2-0.dll", hr=0x0

2025-11-24T01:39:57.801 Engine:Setting original file name "SETUP.EXE.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-wow64-legacy.resources_31bf3856ad364e35_10.0.26100.1_nb-no_735ab890ce560efa\setup16.exe.mui", hr=0x0

2025-11-24T01:39:57.947 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x0

2025-11-24T01:39:57.979 Engine:Setting original file name "RarExt.dll" for "c:\program files\winrar\rarext32.dll", hr=0x0

2025-11-24T01:39:58.024 Engine:Setting original file name "pcw.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-pcw_31bf3856ad364e35_10.0.26100.1150_none_4bf8e6d5066a4f9f_pcw.sys_dbeb0bbd", hr=0x0

2025-11-24T01:39:58.113 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\syswow64\nb-no\ieadvpack.dll.mui", hr=0x0

2025-11-24T01:39:58.144 Engine:Setting original file name "EmbyServer.dll" for "c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe", hr=0x0

2025-11-24T01:39:58.249 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-environment-l1-1-0.dll", hr=0x0

2025-11-24T01:39:58.382 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2535f07be6867822893c0bd7f299affd\dwmcore.dll.mui", hr=0x0

2025-11-24T01:39:58.394 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_am-et_12002fbedc3ad139_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:58.433 Engine:Setting original file name "mavinject64.exe" for "c:\windows\winsxs\amd64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_4ed8aae8a286af05\mavinject.exe", hr=0x0

2025-11-24T01:39:58.583 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_b1cb38b404e84204\seclogon.dll.mui", hr=0x0

2025-11-24T01:39:58.622 Engine:Setting original file name "AuditPolicyGP.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\1e37baae98dce76981781b53776e70b9\auditpolicygpinterop.dll.mui", hr=0x0

2025-11-24T01:39:58.697 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9c4e95300400790b8d8a05d9bf7e1f5c\winnlsres.dll.mui", hr=0x0

2025-11-24T01:39:58.709 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e981bfd75ae177a858ec5c78a5cfda25\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-24T01:39:58.764 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-24T01:39:58.944 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ru-ru_e71c93fcf7d6f33e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:58.993 Engine:Setting original file name "qualityupdateassistant" for "c:\windows\system32\qualityupdateassistant.dll", hr=0x0

2025-11-24T01:39:59.003 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ro-ro_2c617f480dd85974_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:59.125 Engine:Setting original file name "wersvc" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2f884580919ab799dbe1ecd0f275799\wersvc.dll.mui", hr=0x0

2025-11-24T01:39:59.207 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_fa-ir_f7555235024374d9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:59.234 Engine:Setting original file name "ClrCompression" for "c:\program files\windowsapps\microsoft.net.native.runtime.1.7_1.7.25531.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-24T01:39:59.266 Engine:Setting original file name "WIASERVC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiaservc.dll.mui_54051b53", hr=0x0

2025-11-24T01:39:59.269 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-24T01:39:59.298 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ru-ru_0752c1c778fe6e7c_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-24T01:39:59.392 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-24T01:39:59.755 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_id-id_6be80829898706a2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:39:59.760 Engine:Setting original file name "STI.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_en-us_d64b3cbf22b2a8d1_sti.dll.mui_00a4f15b", hr=0x0

2025-11-24T01:39:59.767 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9035fe481934c33719e75dea902d1698\bcastdvruserservice.dll.mui", hr=0x0

2025-11-24T01:39:59.804 Engine:Setting original file name "NVIDIA Debug Dump" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvdebugdump.exe", hr=0x0

2025-11-24T01:39:59.820 Engine:Setting original file name "acpiex.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-acpiex_31bf3856ad364e35_10.0.26100.1150_none_d0b1f61a88e2f0e9_acpiex.sys_6a8b9aed", hr=0x0

2025-11-24T01:39:59.836 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_60b47cf61af27adc_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-24T01:39:59.850 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x0

2025-11-24T01:40:00.041 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sv-se_29319a980f7b0983_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-24T01:40:00.141 Engine:Setting original file name "pshed.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-pshed_31bf3856ad364e35_10.0.26100.1_none_633b3602ca01eb94_pshed.dll_f6ac239e", hr=0x0

2025-11-24T01:40:00.232 Engine:Setting original file name "ClipSVC.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-client-li..m-service.resources_31bf3856ad364e35_10.0.26100.1_en-us_3f436cbd520195fd_clipsvc.dll.mui_18823613", hr=0x0

2025-11-24T01:40:00.257 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_cy-gb_976c80cbdb5c65c1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:00.461 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_uk-ua_c5d15aec526b5235_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:00.520 Engine:Setting original file name "msfltr32.acm" for "c:\windows\winsxs\wow64_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_10.0.26100.1_none_e82ddbd17df6cb5b\msacm32.dll", hr=0x0

2025-11-24T01:40:00.571 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-24T01:40:00.586 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-24T01:40:00.641 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_6dcfa7c5391fe7a2_dnsapi.dll.mui_97465f8a", hr=0x0

2025-11-24T01:40:00.769 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_3cda2262e7ef70ab_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:00.863 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_10.0.26100.7171_none_f70fffd91c8f0404\winload.exe", hr=0x0

2025-11-24T01:40:01.018 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_et-ee_9786a4bcaafec5cb_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:01.281 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files\mozilla firefox\dxcompiler.dll", hr=0x0

2025-11-24T01:40:01.344 Engine:Setting original file name "Device_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\device\nb-no\edb83efa185c0a23d97fafe6a71cd608\diagpackage.dll.mui", hr=0x0

2025-11-24T01:40:01.363 Engine:Setting original file name "rtutils.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasrtutils_31bf3856ad364e35_10.0.26100.3037_none_a90518339a5ed736_rtutils.dll_243724ab", hr=0x0

2025-11-24T01:40:01.474 Engine:Setting original file name "udiapi.dll" for "c:\windows\system32\udiapiclient.dll", hr=0x0

2025-11-24T01:40:01.493 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-24T01:40:01.551 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaidvc.dll", hr=0x0

2025-11-24T01:40:01.556 Engine:Setting original file name "DWrite" for "c:\windows\winsxs\amd64_microsoft-windows-directwrite.resources_31bf3856ad364e35_10.0.26100.1_en-us_8e75f00536c95f8c\dwrite.dll.mui", hr=0x0

2025-11-24T01:40:01.563 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\windows\syswow64\nb-no\mfc40u.dll.mui", hr=0x0

2025-11-24T01:40:01.671 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.26100.1_en-us_12a038f1fa40c367_wlrmdr.exe.mui_ee563c83", hr=0x0

2025-11-24T01:40:01.756 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.xaml.winmd", hr=0x0

2025-11-24T01:40:01.829 Engine:Setting original file name "raspptp.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasbase-raspptp_31bf3856ad364e35_10.0.26100.1882_none_358d932997f7087d_raspptp.sys_25e89db1", hr=0x0

2025-11-24T01:40:01.915 Engine:Setting original file name "l3codec.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\17e7113a56f3171dc40844c9d3ee9e47\l3codeca.acm.mui", hr=0x0

2025-11-24T01:40:01.945 Engine:Setting original file name "bridgeres.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-networkbridge_31bf3856ad364e35_10.0.26100.2454_none_a3b07853b6183928_bridgeres.dll_55e40455", hr=0x0

2025-11-24T01:40:02.171 Engine:Setting original file name "mf.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..oundation.resources_31bf3856ad364e35_10.0.26100.1_en-us_8b9cc1ab2476fea1\mfpmp.exe.mui", hr=0x0

2025-11-24T01:40:02.261 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-processthreads-l1-1-1.dll", hr=0x0

2025-11-24T01:40:02.324 Engine:Setting original file name "FreeImage.dll" for "c:\program files (x86)\steam\steamapps\common\wallpaper_engine\bin\freeimage64.dll", hr=0x0

2025-11-24T01:40:02.329 Engine:Setting original file name "tier0_s.dll" for "c:\program files (x86)\steam\tier0_s64.dll", hr=0x0

2025-11-24T01:40:02.343 Engine:Setting original file name "nvaudcap.dll" for "c:\windows\syswow64\nvaudcap32v.dll", hr=0x0

2025-11-24T01:40:02.514 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mi-nz_b80bad72b6b0ee53_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:02.540 Engine:Setting original file name "CertCli" for "c:\windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_10.0.26100.1_en-us_61b2ff4b086153b8\certcli.dll.mui", hr=0x0

2025-11-24T01:40:02.544 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\en-us\wsepno.dll.mui", hr=0x0

2025-11-24T01:40:02.566 Engine:Setting original file name "ConfigurationRemotingServer.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\configurationremotingserver.exe", hr=0x0

2025-11-24T01:40:02.576 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_sr-..-rs_e67ffd847af5d250_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:02.579 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\power\en-us\diagpackage.dll.mui", hr=0x0

2025-11-24T01:40:02.602 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay8-payload_31bf3856ad364e35_1.0.26100.4202_none_bb7ce817a226517c\dpnaddr.dll", hr=0x0

2025-11-24T01:40:02.835 Engine:Setting original file name "msfltr32.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8836c193640d589410b5cc3dbe67e146\msacm32.dll.mui", hr=0x0

2025-11-24T01:40:02.915 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_6a24110114ad15ad_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-24T01:40:02.938 Engine:Setting original file name "usk.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\7c8e526d244ad657f882f8bbba0149ec\usk.rs.mui", hr=0x0

2025-11-24T01:40:02.949 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-24T01:40:02.968 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay4-payload_31bf3856ad364e35_1.0.26100.4202_none_186a372066698d60\dpmodemx.dll", hr=0x0

2025-11-24T01:40:03.145 Engine:Setting original file name "Register-CimProvider2.exe.mui" for "c:\windows\syswow64\en-us\register-cimprovider.exe.mui", hr=0x0

2025-11-24T01:40:03.237 Engine:Setting original file name "metabase.dll.mui" for "c:\windows\winsxs\wow64_microsoft-windows-iis-metabase.resources_31bf3856ad364e35_10.0.26100.1_en-us_8ff50fedc8451a7b\metadata.dll.mui", hr=0x0

2025-11-24T01:40:03.241 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x0

2025-11-24T01:40:03.314 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_de-de_ab2a1f0520f5ef2b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:03.376 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_6fced6fbf4c0e3e0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:03.498 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\en-us\diagpackage.dll.mui", hr=0x0

2025-11-24T01:40:03.518 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_7478bb53490dd7a8_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-24T01:40:03.567 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\windows\system32\nb-no\msidntld.dll.mui", hr=0x0

2025-11-24T01:40:03.571 Engine:Setting original file name "glu32" for "c:\windows\winsxs\amd64_microsoft-windows-opengl.resources_31bf3856ad364e35_10.0.26100.1_en-us_9c3b296d3d668ac3\glu32.dll.mui", hr=0x0

2025-11-24T01:40:03.590 Engine:Setting original file name "mf.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mediafoundation_31bf3856ad364e35_10.0.26100.7171_none_384874e2bca9ce3f\mfpmp.exe", hr=0x0

2025-11-24T01:40:03.621 Engine:Setting original file name "scesrv" for "c:\windows\system32\nb-no\scesrv.dll.mui", hr=0x0

2025-11-24T01:40:03.633 Engine:Setting original file name "DWWIN" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ae2b7dc24859d1fa2a509d5b642451b4\dwwin.exe.mui", hr=0x0

2025-11-24T01:40:03.772 Engine:Setting original file name "nvcuvid.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcuvid64.dll", hr=0x0

2025-11-24T01:40:03.808 Engine:Setting original file name "AppHostNameRegistrationVerifier.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\baf91a75f57ca8730dd9a6f926a58dd0\apphostregistrationverifier.exe.mui", hr=0x0

2025-11-24T01:40:03.819 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_en-gb_9672c12aaba943d2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:03.925 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-rtlsupport-l1-1-0.dll", hr=0x0

2025-11-24T01:40:03.944 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-24T01:40:03.970 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_gu-in_97d53b15f69aaeca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:04.013 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_84875939fc6b99b1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:04.038 Engine:Setting original file name "ServDeps.exe.mui" for "c:\windows\syswow64\wbem\nb-no\servdeps.dll.mui", hr=0x0

2025-11-24T01:40:04.066 Engine:Setting original file name "schtasks.exe" for "c:\windows\winsxs\amd64_microsoft-windows-sctasks_31bf3856ad364e35_10.0.26100.6725_none_25e27f3a6574108c\schtasks.exe", hr=0x0

2025-11-24T01:40:04.077 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_e38364b045f31518_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:04.124 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_el-gr_b382575af3d00da3_memtest.efi.mui_71e15c22", hr=0x0

2025-11-24T01:40:04.286 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.26100.1_en-us_0e875971ea5fda56\ieadvpack.dll.mui", hr=0x0

2025-11-24T01:40:04.326 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-datetime-l1-1-0.dll", hr=0x0

2025-11-24T01:40:04.348 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-24T01:40:04.384 Engine:Setting original file name "user32" for "c:\windows\system32\user32.dll", hr=0x0

2025-11-24T01:40:04.453 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.642.119.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-24T01:40:04.463 Engine:Setting original file name "shutdownui" for "c:\windows\winsxs\amd64_microsoft-windows-shutdownext.resources_31bf3856ad364e35_10.0.26100.1_en-us_9bd0f22e3578c871\shutdownext.dll.mui", hr=0x0

2025-11-24T01:40:04.607 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4\memtest.exe.mui", hr=0x0

2025-11-24T01:40:04.648 Engine:Setting original file name ".NET Host Resolver - 8.0.20" for "c:\users\serverpc\appdata\local\temp\emby-server-updater\hostfxr.dll", hr=0x0

2025-11-24T01:40:04.665 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_bs-..-ba_3017f7e2648d7e73_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:04.743 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_quz-pe_0266e81632046792_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:04.841 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lb-lu_cb546bb0b0d79a98_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:04.874 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\amd64_microsoft-windows-a..perience-ait-static_31bf3856ad364e35_10.0.26100.7019_none_ccd1f49f5e2b3b28\aitstatic.exe", hr=0x0

2025-11-24T01:40:04.960 Engine:Setting original file name "UNPShared.dll" for "c:\windows\winsxs\amd64_microsoft-windows-update-upshared_31bf3856ad364e35_10.0.26100.5074_none_29764f36135e6d4c\upshared.dll", hr=0x0

2025-11-24T01:40:05.030 Engine:Setting original file name "messagin.dll" for "c:\program files\bitdefender agent\27.1.1.23\messaging.dll", hr=0x0

2025-11-24T01:40:05.095 Engine:Setting original file name "WindowsCodecs" for "c:\windows\syswow64\windowscodecs.dll", hr=0x0

2025-11-24T01:40:05.127 Engine:Setting original file name "WerMgr" for "c:\windows\system32\wermgr.exe", hr=0x0

2025-11-24T01:40:05.170 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d\memtest.exe.mui", hr=0x0

2025-11-24T01:40:05.173 Engine:Setting original file name "imapi.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bd7c223153b9576fe4c4e66ebf1c6ece\imapi.dll.mui", hr=0x0

2025-11-24T01:40:05.285 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hi-in_8555c5797fc8795e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:05.352 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\esrb.rs.mui", hr=0x0

2025-11-24T01:40:05.435 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-24T01:40:05.454 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_zh-tw_ff4ad39908e2da78_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:05.458 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-24T01:40:05.504 Engine:Setting original file name "microsoftedgedevtools.exe" for "c:\windows\system32\microsoftedgecp.exe", hr=0x0

2025-11-24T01:40:05.524 Engine:Setting original file name "la57setup.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ec428185df2994f7d7954c1efe1b2738\la57setup.exe.mui", hr=0x0

2025-11-24T01:40:05.530 Engine:Setting original file name "wuapi.dll" for "c:\windows\uus\x86\wuapicore.dll", hr=0x0

2025-11-24T01:40:05.599 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\system32\en-us\dsprop.dll.mui", hr=0x0

2025-11-24T01:40:05.710 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-24T01:40:05.731 Engine:Setting original file name "etweseproviderresources.dll" for "c:\windows\winsxs\backup\amd64_microsoft-etw-ese_31bf3856ad364e35_10.0.26100.1_none_cc4e7afeeee8d3b1_etweseproviderresources.dll_f21e8ea7", hr=0x0

2025-11-24T01:40:05.791 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_2821a024e044bada_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:05.793 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-24T01:40:05.828 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bf8ce2a53903d9e6d302aee07de95dd9\mfc40u.dll.mui", hr=0x0

2025-11-24T01:40:05.841 Engine:Setting original file name "TAPISRV.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-tapiservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_83c985f74a352be9\tapisrv.dll.mui", hr=0x0

2025-11-24T01:40:06.029 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lo-la_099683f3cb70d44f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:06.031 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x0

2025-11-24T01:40:06.117 Engine:Setting original file name "wininet.dll" for "c:\windows\systemresources\wininet.dll.mun", hr=0x0

2025-11-24T01:40:06.144 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\nb-no\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x0

2025-11-24T01:40:06.161 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_hu-hu_9dd052ebcaf187fd_memtest.efi.mui_71e15c22", hr=0x0

2025-11-24T01:40:06.164 Engine:Setting original file name "PrintBrmEng.exe.mui" for "c:\windows\system32\spool\tools\en-us\printbrmengine.exe.mui", hr=0x0

2025-11-24T01:40:06.165 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_it-it_4087c8eabdc39e5f_memtest.efi.mui_71e15c22", hr=0x0

2025-11-24T01:40:06.197 Engine:Setting original file name "audioadg.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f411807b0749e7d602e77baf3c1c4e60\audiodg.exe.mui", hr=0x0

2025-11-24T01:40:06.264 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x0

2025-11-24T01:40:06.334 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-t..iprovider.resources_31bf3856ad364e35_10.0.26100.1_en-us_41b711b4f2db4fe7\rdpsign.exe.mui", hr=0x0

2025-11-24T01:40:06.455 Engine:Setting original file name "Video_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\video\nb-no\2ca5a0690699da595bd35a22420a1c04\diagpackage.dll.mui", hr=0x0

2025-11-24T01:40:06.462 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-24T01:40:06.483 Engine:Setting original file name "FvSDKTestClientPublic" for "c:\program files\nvidia corporation\frameviewsdk\sdk\fvsdktestclient_public.exe", hr=0x0

2025-11-24T01:40:06.524 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\qps-ploc\msprivs.dll.mui", hr=0x0

2025-11-24T01:40:06.525 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-24T01:40:06.642 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\windows\system32\nb-no\pnpclean.dll.mui", hr=0x0

2025-11-24T01:40:06.652 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_or-in_f89501f89f876dc5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:06.683 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.26100.7171_none_4ad020869b677502\taskmgr.exe.mun", hr=0x0

2025-11-24T01:40:06.729 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_ca98740be1962356_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:06.780 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x0

2025-11-24T01:40:06.833 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_it-it_f0fca0072ba86c5a\msprivs.dll.mui", hr=0x0

2025-11-24T01:40:06.874 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps-ploc_7ccda1c46b445ed4\memtest.exe.mui", hr=0x0

2025-11-24T01:40:06.891 Engine:Setting original file name "NETBIOS.SYS" for "c:\windows\winsxs\backup\amd64_microsoft-windows-netbios_31bf3856ad364e35_10.0.26100.1_none_56d5608ad3abe945_netbios.sys_6f23c4df", hr=0x0

2025-11-24T01:40:06.944 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-process-l1-1-0.dll", hr=0x0

2025-11-24T01:40:07.073 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\systemresources\etwcoreuicomponentsresources.dll.mun", hr=0x0

2025-11-24T01:40:07.084 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pt-br_55b72b827c87f88f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:07.194 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_0dc0948c02e4507b_memtest.efi.mui_71e15c22", hr=0x0

2025-11-24T01:40:07.207 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mt-mt_b4ebaa02b8bfece3_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:07.237 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.devices.winmd", hr=0x0

2025-11-24T01:40:07.271 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_576ce8a1070e9744_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:07.282 Engine:Setting original file name "FileInfo.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-fileinfominifilter_31bf3856ad364e35_10.0.26100.1150_none_729c4b9be137bb96_fileinfo.sys_9be2dfcd", hr=0x0

2025-11-24T01:40:07.354 Engine:Setting original file name "aclui.dll" for "c:\windows\winsxs\amd64_microsoft-windows-aclui_31bf3856ad364e35_10.0.26100.7019_none_f0f7bbb4638cf785\aclui.dll.mun", hr=0x0

2025-11-24T01:40:07.358 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\73be2921551d\apex_fieldsamplerchecked_x86.dll", hr=0x0

2025-11-24T01:40:07.420 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.777.2143.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-24T01:40:07.476 Engine:Setting original file name "qualityupdateassistant" for "c:\program files\microsoft update health tools\qualityupdateassistant.dll", hr=0x0

2025-11-24T01:40:07.500 Engine:Setting original file name "NVPPE.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvppex.dll", hr=0x0

2025-11-24T01:40:07.570 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_en-us_4761fcc7ecd6d884_winresume.efi.mui_f412814e", hr=0x0

2025-11-24T01:40:07.742 Engine:Setting original file name "NVPrxy.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvprxy32.dll", hr=0x0

2025-11-24T01:40:07.842 Engine:Setting original file name "Mystify" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\589bec7339e102473dc7566c3b9b0f45\mystify.scr.mui", hr=0x0

2025-11-24T01:40:07.866 Engine:Setting original file name "volmgrx.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..memanager.resources_31bf3856ad364e35_10.0.26100.1_en-us_a18734abf077f9b4_volmgrx.sys.mui_b0c205d7", hr=0x0

2025-11-24T01:40:07.899 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-24T01:40:07.995 Engine:Setting original file name "libcrypto" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\libcrypto-3-x64.dll", hr=0x0

2025-11-24T01:40:08.017 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-string-l1-1-0.dll", hr=0x0

2025-11-24T01:40:08.049 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hi-in_83227505fd46a5bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:08.088 Engine:Setting original file name "CertCa" for "c:\windows\winsxs\amd64_microsoft-windows-c..ertca-dll.resources_31bf3856ad364e35_10.0.26100.1_nb-no_25e015431023bb9b\certca.dll.mui", hr=0x0

2025-11-24T01:40:08.186 Engine:Setting original file name "PCW_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_ddc581f4a364804b\diagpackage.dll.mui", hr=0x0

2025-11-24T01:40:08.267 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..subsystem.resources_31bf3856ad364e35_10.0.26100.1_nb-no_ab8620bc0ed41a36\scardsvr.dll.mui", hr=0x0

2025-11-24T01:40:08.283 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_6.0.3624.51421.dll", hr=0x0

2025-11-24T01:40:08.363 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-24T01:40:08.399 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_06d4a9c0547686dc\msprivs.dll.mui", hr=0x0

2025-11-24T01:40:08.546 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mapi_31bf3856ad364e35_10.0.26100.7019_none_473a9ee5c9a5ebee\mapistub.dll", hr=0x0

2025-11-24T01:40:08.662 Engine:Setting original file name "mofcomp.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_nb-no_8c87dcbbb8114be3_mofcomp.exe.mui_35badf56", hr=0x0

2025-11-24T01:40:08.667 Engine:Setting original file name "MspsProv.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..oning-wmi.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd6de3cbb42de1cb\mspsprov.dll.mui", hr=0x0

2025-11-24T01:40:08.710 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x0

2025-11-24T01:40:08.804 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.26100.7019_none_4a484d6501b73a17\wwanapi.dll", hr=0x0

2025-11-24T01:40:08.873 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ne-np_591939d32e7d4223_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:08.945 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.xboxidentityprovider_12.130.16001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-24T01:40:09.099 Engine:Setting original file name "Operativsystemet Microsoft� Windows�" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e2a170892be5347a116ae0806fb5309d\pcalua.exe.mui", hr=0x0

2025-11-24T01:40:09.168 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x0

2025-11-24T01:40:09.183 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x0

2025-11-24T01:40:09.454 Engine:Setting original file name "imageres.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-imageres_31bf3856ad364e35_10.0.26100.1_none_d9b14b936072a0bc\imageres.dll.mun", hr=0x0

2025-11-24T01:40:09.659 Engine:Setting original file name "vcruntime140.dll" for "c:\config.msi\1c742.rbf", hr=0x0

2025-11-24T01:40:09.698 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-24T01:40:09.742 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_kk-kz_71b9c9e0d19e9ee0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:09.927 Engine:Setting original file name "Apps_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\apps\nb-no\d2a92c7cfed83dc547a21508b5b0ea0f\diagpackage.dll.mui", hr=0x0

2025-11-24T01:40:09.944 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32.dll", hr=0x0

2025-11-24T01:40:09.999 Engine:Setting original file name "CertPKICmdlet" for "c:\windows\system32\en-us\certpkicmdlet.dll.mui", hr=0x0

2025-11-24T01:40:10.049 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ed4232cecc06e9efb72d2a7c142b63b4\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x0

2025-11-24T01:40:10.059 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.424.1611.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-24T01:40:10.119 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_0cb2119581e88ce0\diagpackage.dll.mui", hr=0x0

2025-11-24T01:40:10.272 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\system32\bcp47langs.dll", hr=0x0

2025-11-24T01:40:10.339 Engine:Setting original file name "gpapi.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-g..licy-base.resources_31bf3856ad364e35_10.0.26100.1_en-us_be2843fbd972ca37_gpapi.dll.mui_ef0a9748", hr=0x0

2025-11-24T01:40:10.341 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-math-l1-1-0.dll", hr=0x0

2025-11-24T01:40:10.393 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x0

2025-11-24T01:40:10.402 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\winsxs\amd64_microsoft-windows-aerolite.resources_31bf3856ad364e35_10.0.26100.1_en-us_bc993ceae8fc48bf\aerolite.msstyles.mui", hr=0x0

2025-11-24T01:40:10.665 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\en-us\utilman.exe.mui", hr=0x0

2025-11-24T01:40:10.794 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x0

2025-11-24T01:40:10.898 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-24T01:40:10.906 Engine:Setting original file name "sqlite3" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\sqlite3.dll", hr=0x0

2025-11-24T01:40:10.966 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x0

2025-11-24T01:40:11.013 Engine:Setting original file name "w32time.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-time-tool.resources_31bf3856ad364e35_10.0.26100.1_en-us_7b897a2738f484fc\w32tm.exe.mui", hr=0x0

2025-11-24T01:40:11.018 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd473133072db5bb\diagpackage.dll.mui", hr=0x0

2025-11-24T01:40:11.043 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_80a1d04cb31f8eca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:11.048 Engine:Setting original file name "ERC" for "c:\windows\system32\nb-no\wercplsupport.dll.mui", hr=0x0

2025-11-24T01:40:11.080 Engine:Setting original file name "vdsutil.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-v..skservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_59d12af3dce743c1_vdsutil.dll.mui_0caf9b0e", hr=0x0

2025-11-24T01:40:11.165 Engine:Setting original file name "AppLockerCSP.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appidcore.resources_31bf3856ad364e35_10.0.26100.1_en-us_564c6ad9b132641f_applockercsp.dll.mui_d2a0df70", hr=0x0

2025-11-24T01:40:11.218 Engine:Setting original file name "dnsrslvr.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570_dnsrslvr.dll.mui_1e1a1ed1", hr=0x0

2025-11-24T01:40:11.283 Engine:Setting original file name "PSAPI" for "c:\windows\winsxs\backup\wow64_microsoft-windows-basedependencies_31bf3856ad364e35_10.0.26100.1_none_09ea4476c5bcc4c0_psapi.dll_e8b5b4d1", hr=0x0

2025-11-24T01:40:11.307 Engine:Setting original file name "AcPlugin.dll" for "c:\program files\windowsapps\microsoft.applicationcompatibilityenhancements_1.2511.9.0_x64__8wekyb3d8bbwe\amd64\acplugin_test.dll", hr=0x0

2025-11-24T01:40:11.318 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\426c2b1101abec586136a4bbd67a716e\narrator.exe.mui", hr=0x0

2025-11-24T01:40:11.333 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..tiator_ui.resources_31bf3856ad364e35_10.0.26100.1_en-us_7967a83a130d426e\iscsicpl.dll.mui", hr=0x0

2025-11-24T01:40:11.420 Engine:Setting original file name "WindowsMediaPlayerPlayDVD_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_587c1f8aa98a4a71\diagpackage.dll.mui", hr=0x0

2025-11-24T01:40:11.600 Engine:Setting original file name "scecli" for "c:\windows\system32\nb-no\scecli.dll.mui", hr=0x0

2025-11-24T01:40:11.616 Engine:Setting original file name "scesrv" for "c:\windows\winsxs\amd64_microsoft-windows-s..ionengine.resources_31bf3856ad364e35_10.0.26100.1_en-us_e63bd45b831a32e3\scesrv.dll.mui", hr=0x0

2025-11-24T01:40:11.646 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_bg-bg_af9bba51d24fbf0e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:11.700 Engine:Setting original file name "nvhda.sys" for "c:\windows\system32\driverstore\filerepository\nvhda.inf_amd64_c32d8360d192a82e\nvhda64v.sys", hr=0x0

2025-11-24T01:40:11.710 Engine:Setting original file name "wmiutils.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiutils.dll.mui_42583eaf", hr=0x0

2025-11-24T01:40:11.723 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_te-in_e10bae4a47776b9f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:11.751 Engine:Setting original file name "BdncProxy.dll" for "c:\program files\bitdefender agent\27.1.1.23\crash_handler\bdnc.dll", hr=0x0

2025-11-24T01:40:11.823 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.26100.1_nb-no_e175a2f7bf27ee8d_ws2ifsl.sys.mui_b672c7b4", hr=0x0

2025-11-24T01:40:11.884 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_eu-es_e55e702bbb854a24_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:11.918 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-msinfo32-exe.resources_31bf3856ad364e35_10.0.26100.1_en-us_53ae64398a08feba\msinfo32.exe.mui", hr=0x0

2025-11-24T01:40:11.960 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-24T01:40:12.051 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x86__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-24T01:40:12.071 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x0

2025-11-24T01:40:12.163 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x0

2025-11-24T01:40:12.170 Engine:Setting original file name "NxCooking.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\v2.7.6\physxcooking.dll", hr=0x0

2025-11-24T01:40:12.198 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-24T01:40:12.330 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x0

2025-11-24T01:40:12.402 Engine:Setting original file name "filterLib.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\4fffc8576907b0b5da815790887fb244\fltlib.dll.mui", hr=0x0

2025-11-24T01:40:12.438 Engine:Setting original file name "srpuxgp.dll" for "c:\windows\systemresources\srpuxnativesnapin.dll.mun", hr=0x0

2025-11-24T01:40:12.441 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-24T01:40:12.624 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_nl-nl_0d26e65c98dbf6f7_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:12.635 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sl-si_8549ba61ed8af84b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:12.639 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x0

2025-11-24T01:40:12.802 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_pl-pl_9d43c82914fc6152_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:12.824 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.web.winmd", hr=0x0

2025-11-24T01:40:12.884 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-24T01:40:12.990 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ca-es_584cefb2c144b7d8_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:12.999 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\winsxs\amd64_microsoft-windows-qedwipes_31bf3856ad364e35_10.0.26100.1_none_5473011012d79dc1\qedwipes.dll.mun", hr=0x0

2025-11-24T01:40:13.154 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_et-ee_4da61d721400c924_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:13.190 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_fb2fbffb5205c552_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:13.396 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..xe-common.resources_31bf3856ad364e35_10.0.26100.1_en-us_58b62bf54b9ae38a\msinfo32.exe.mui", hr=0x0

2025-11-24T01:40:13.510 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.70.1338.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-24T01:40:13.514 Engine:Setting original file name "netcfgx.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-tcpip.resources_31bf3856ad364e35_10.0.26100.1_en-us_c93621b935b09922_tcpipcfg.dll.mui_a5479fc1", hr=0x0

2025-11-24T01:40:13.561 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_f4c1513bcd79893e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:13.605 Engine:Setting original file name "nvxdsync.exe" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\session\nvxdsyncplugin.dll", hr=0x0

2025-11-24T01:40:13.750 Engine:Setting original file name "ReShade" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\reshadefxc64.exe", hr=0x0

2025-11-24T01:40:13.792 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-24T01:40:13.844 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_0fbfb1c9f2926e3e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:13.873 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\power\nb-no\2803551e72f3605cc0b181750700647e\diagpackage.dll.mui", hr=0x0

2025-11-24T01:40:13.935 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_th-th_25ee4fb15dc2e739_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:13.940 Engine:Setting original file name "Umpo.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-u..erservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_a887c532823d0a08_umpo.dll.mui_cac12e54", hr=0x0

2025-11-24T01:40:13.943 Engine:Setting original file name "bootres" for "c:\windows\boot\resources\nb-no\bootres.dll.mui", hr=0x0

2025-11-24T01:40:13.967 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\b74f41bc269d13282681d018820fb031\ddores.dll.mui", hr=0x0

2025-11-24T01:40:13.986 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x0

2025-11-24T01:40:13.995 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\mscordaccore_amd64_amd64_8.0.2125.47513.dll", hr=0x0

2025-11-24T01:40:14.020 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-namedpipe-l1-1-0.dll", hr=0x0

2025-11-24T01:40:14.117 Engine:Setting original file name "dxmasf.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_10.0.26100.7019_none_b1abcb083360b859\msdxm.ocx", hr=0x0

2025-11-24T01:40:14.240 Engine:Setting original file name "Bubbles" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ee15dd2b573766654f76694ac2f468d4\bubbles.scr.mui", hr=0x0

2025-11-24T01:40:14.273 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_tr-tr_2c24c8b8ddbbff8a_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:14.296 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_es-mx_9dca765f230af946_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:14.317 Engine:Setting original file name "CUDART64_65_19.DLL" for "c:\program files (x86)\nvidia corporation\physx\common\cudart64_65.dll", hr=0x0

2025-11-24T01:40:14.335 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-errorhandling-l1-1-0.dll", hr=0x0

2025-11-24T01:40:14.459 Engine:Setting original file name "wcp.dll" for "c:\windows\system32\ssshim.dll", hr=0x0

2025-11-24T01:40:14.562 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.exe", hr=0x0

2025-11-24T01:40:14.607 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-time-l1-1-0.dll", hr=0x0

2025-11-24T01:40:14.613 Engine:Setting original file name "SCardDlg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.26100.3323_en-us_fe960d41ea77a2e8_scarddlg.dll.mui_300ae9df", hr=0x0

2025-11-24T01:40:14.648 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-memory-l1-1-0.dll", hr=0x0

2025-11-24T01:40:14.660 Engine:Setting original file name "reg.exe" for "c:\windows\winsxs\wow64_microsoft-windows-r..-commandline-editor_31bf3856ad364e35_10.0.26100.5074_none_d7dcabbe0ef09540\reg.exe", hr=0x0

2025-11-24T01:40:14.673 Engine:Setting original file name "TrustedSignalCredProv.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..-credprov.resources_31bf3856ad364e35_10.0.26100.1_en-us_080e5e17ad23b7b4_trustedsignalcredprov.dll.mui_5edc427b", hr=0x0

2025-11-24T01:40:14.718 Engine:Setting original file name "fpb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\fpb.rs.mui", hr=0x0

2025-11-24T01:40:14.868 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ta-in_72c4ac1bf2d12188_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-24T01:40:14.904 OriginalFileName Maintenance::11478 files in Moac, 0 skipped (cached), 435 filename set

2025-11-24T01:40:14.904 [AutoPurge] Routine task for Cache Maintenance has ended.

2025-11-24T01:45:23.563 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T01:48:51.762 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #244201, FileId: 0x5c000000009ed7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T01:52:08.169 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #244395, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T01:52:08.174 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #244396, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T01:52:18.178 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #244401, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T01:52:18.182 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #244402, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T02:00:28.560 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T02:03:52.112 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #244537, FileId: 0x1600000001a931, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T02:07:09.082 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

2025-11-24T02:07:09.091 [DLP] DlpEngineConfigStorage::OnConfigChange DlpDwordSettingsMap:

2025-11-24T02:07:09.092 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-24T02:07:09.092 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-24T02:07:09.092 [RTP] Duplicating the current plugin configuration object...

2025-11-24T02:07:09.092 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-24T02:07:09.092 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-24T02:07:09.092 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-24T02:07:09.092 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-24T02:07:09.092 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-24T02:07:09.092 [RTP] No config change detected. Not updating plugin configuration.

2025-11-24T02:07:09.092 [RTP] No config changes found. No configuration switch.

2025-11-24T02:07:09.092 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-24T02:07:09.092 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-24T02:07:09.092 [RTP] [RtpConfig] Config change detected, type: 16

2025-11-24T02:07:09.092 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-24T02:07:09.092 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-24T02:07:09.092 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-24T02:07:09.092 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-24T02:07:09.092 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-24T02:07:09.092 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-24T02:07:09.092 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-24T02:07:09.092 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-24T02:07:09.092 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-24T02:07:09.092 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-24T02:07:09.092 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-24T02:07:09.092 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-24T02:07:09.092 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-24T02:07:09.092 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-24T02:07:09.093 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T02:07:09.094 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T02:07:09.095 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T02:07:09.097 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T02:07:09.098 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T02:07:09.100 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 8445108(ms) from now at 05:27 (04:27 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-24T02:07:11.651 [RTP] Duplicating the current plugin configuration object...

2025-11-24T02:07:11.651 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-24T02:07:11.651 [RTP] Updating plugin configuration due to recent config changes (0x41e) ...

2025-11-24T02:07:11.651 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-24T02:07:11.652 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x218

2025-11-24T02:09:54.358 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #245083, FileId: 0xe8000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T02:15:33.551 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T02:17:27.713 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 1308, Count: 86, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d28dcb44-f04d-45e2-9c18-184818503255.tmp, EstimatedImpact: 0%

2025-11-24T02:17:27.713 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 943, Count: 54, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\78d5308b-9031-47af-86dd-8be0b52e4973.tmp, EstimatedImpact: 0%

2025-11-24T02:17:27.713 ProcessImageName: RuntimeBroker.exe, Pid: 26532, TotalTime: 557, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 37%

2025-11-24T02:17:27.714 ProcessImageName: RuntimeBroker.exe, Pid: 25760, TotalTime: 496, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-24T02:17:27.714 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 195, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\ID\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP.bin, EstimatedImpact: 0%

2025-11-24T02:17:27.714 ProcessImageName: taskhostw.exe, Pid: 20396, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-24T02:17:27.714 ProcessImageName: taskhostw.exe, Pid: 17820, TotalTime: 150, Count: 74, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 8%

2025-11-24T02:17:27.714 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 136, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T02:17:27.714 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-24T02:17:27.714 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 92, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-24T02:17:27.714 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\a1f4e5b9-2d30-49ef-92cf-ab527ff1776e.tmp, EstimatedImpact: 0%

2025-11-24T02:17:27.714 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\b0d5965a-268f-4c81-8d85-e7fc1f902d8b.tmp, EstimatedImpact: 0%

2025-11-24T02:17:27.714 ProcessImageName: taskhostw.exe, Pid: 24272, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-24T02:17:27.714 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-24T02:17:27.714 ProcessImageName: StoreDesktopExtension.exe, Pid: 24492, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-24T02:17:27.714 ProcessImageName: HxTsr.exe, Pid: 23596, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1822317515-1041744019-1682422708-1001-MergedResources-81.pri, EstimatedImpact: 18%

2025-11-24T02:17:27.714 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_691320.acf, EstimatedImpact: 0%

2025-11-24T02:17:27.714 ProcessImageName: updater.exe, Pid: 23956, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ae575a87-1e6d-4177-bfeb-60c4e1e02368.tmp, EstimatedImpact: 0%

2025-11-24T02:17:27.714 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-24T02:17:27.714 ProcessImageName: Spotify.exe, Pid: 17104, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-24T02:18:52.529 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #245327, FileId: 0xf100000001d28c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T02:30:38.550 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T02:33:52.581 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #245832, FileId: 0x1a300000000d8e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T02:45:43.544 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T02:48:52.705 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #246090, FileId: 0x193000000009566, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T02:52:07.236 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #246120, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T02:52:07.239 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #246121, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T02:52:17.239 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #246126, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T02:52:17.240 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #246127, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T02:52:17.243 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #246128, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T02:52:17.245 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #246129, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T03:00:48.540 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T03:03:53.102 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #246252, FileId: 0x7a000000009ed7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T03:15:53.542 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T03:17:55.622 Bm signature throttled:0x0000fab3228bcd4d

2025-11-24T03:18:53.256 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #246567, FileId: 0x49000000027fdf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T03:30:58.533 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T03:33:53.489 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #246636, FileId: 0x1a00000000d33f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T03:46:03.530 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T03:48:54.953 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #246814, FileId: 0xa7000000029bba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T03:52:07.778 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #246842, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T03:52:07.781 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #246843, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T03:52:17.788 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #246851, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T03:52:17.792 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #246852, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T04:01:08.521 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T04:03:55.146 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #246972, FileId: 0x2100000001a916, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T04:16:13.515 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T04:17:27.685 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 2661, Count: 173, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d28dcb44-f04d-45e2-9c18-184818503255.tmp, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 1759, Count: 108, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\78d5308b-9031-47af-86dd-8be0b52e4973.tmp, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1534, Count: 84, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 84%

2025-11-24T04:17:27.685 ProcessImageName: RuntimeBroker.exe, Pid: 26532, TotalTime: 557, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 37%

2025-11-24T04:17:27.685 ProcessImageName: RuntimeBroker.exe, Pid: 25760, TotalTime: 496, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-24T04:17:27.685 ProcessImageName: DeviceCensus.exe, Pid: 25932, TotalTime: 371, Count: 13, MaxTime: 296, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 11%

2025-11-24T04:17:27.685 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 241, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 225, Count: 58, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\ID\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP.bin, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: taskhostw.exe, Pid: 20396, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-24T04:17:27.685 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 165, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: taskhostw.exe, Pid: 17820, TotalTime: 150, Count: 74, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 8%

2025-11-24T04:17:27.685 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 137, Count: 16, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\a1f4e5b9-2d30-49ef-92cf-ab527ff1776e.tmp, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: Spotify.exe, Pid: 17084, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\b0d5965a-268f-4c81-8d85-e7fc1f902d8b.tmp, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: taskhostw.exe, Pid: 24272, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-24T04:17:27.685 ProcessImageName: taskhostw.exe, Pid: 3308, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 3%

2025-11-24T04:17:27.685 ProcessImageName: updater.exe, Pid: 2296, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: StoreDesktopExtension.exe, Pid: 24492, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: HxTsr.exe, Pid: 23596, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1822317515-1041744019-1682422708-1001-MergedResources-81.pri, EstimatedImpact: 18%

2025-11-24T04:17:27.685 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_691320.acf, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: updater.exe, Pid: 23956, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ae575a87-1e6d-4177-bfeb-60c4e1e02368.tmp, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: StoreDesktopExtension.exe, Pid: 1720, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-24T04:17:27.685 ProcessImageName: Spotify.exe, Pid: 17104, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-24T04:18:55.239 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #247205, FileId: 0x94000000008a91, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T04:31:18.508 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T04:33:55.713 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #247260, FileId: 0x23000000029a6d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T04:46:23.502 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T04:48:55.816 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #247371, FileId: 0x91000000029b97, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T04:52:05.779 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #247380, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T04:52:05.782 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #247381, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T04:52:15.782 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #247386, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T04:52:15.790 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #247387, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T04:58:15.070 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\05056B10-E74F-4B30-91C7-58FDDD554A684eec.1dc5cfef02dbe79

2025-11-24T04:58:15.097 Verifying engine and signature files (source: 0) ...

2025-11-24T04:58:15.097 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BD703DE-85C0-4890-96D2-607253C51FF7}\mpengine.dll] due to PPL.

2025-11-24T04:58:15.097 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BD703DE-85C0-4890-96D2-607253C51FF7}\mpasbase.vdm] (file in cache)

2025-11-24T04:58:15.102 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BD703DE-85C0-4890-96D2-607253C51FF7}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-24T04:58:15.111 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BD703DE-85C0-4890-96D2-607253C51FF7}\mpasdlta.vdm]

2025-11-24T04:58:15.111 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BD703DE-85C0-4890-96D2-607253C51FF7}\mpavbase.vdm] (file in cache)

2025-11-24T04:58:15.111 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BD703DE-85C0-4890-96D2-607253C51FF7}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-24T04:58:15.119 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BD703DE-85C0-4890-96D2-607253C51FF7}\mpavdlta.vdm]

2025-11-24T04:58:15.224 [Engine] IsHybridMode: 0

2025-11-24T04:58:15.224 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-24T04:58:15.235 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B40FFA31555DEACF5744145B0E502F432023380B.bin): 0x00000002

2025-11-24T04:58:15.239 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B40FFA31555DEACF5744145B0E502F432023380B.bin)

2025-11-24T04:58:15.239 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-24T04:58:15.239 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-24T04:58:15.239 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-24T04:58:15.239 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-24T04:58:21.472 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-24T04:58:21.472 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-24T04:58:21.478 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7F1CA660, lRefCount: 5, hr=0

2025-11-24T04:58:21.478 [Engine] New active engine 00007FFE717EA660 replacing engine 00007FFE7F1CA660. Number of active engines: 2

2025-11-24T04:58:21.482 EngineInit:Global ASOC is enabled

2025-11-24T04:58:21.482 EngineInit:ASOO is enabled for developer volumes

2025-11-24T04:58:21.515 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-24T04:58:21.516 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.516 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-24T04:58:21.516 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-24T04:58:21.517 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-24T04:58:21.517 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.518 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.518 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.518 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-24T04:58:21.519 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.519 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.519 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-24T04:58:21.520 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.520 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.520 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.520 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.521 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.521 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.521 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.522 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T04:58:21.522 Dynamic signature dropped

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5fc6fda8dcec63245787d0ecea66aa1d0af5fbef

Dynamic Signature Compilation Timestamp:11-23-2025 03:57:48

Persistence Type:Duration

Time remaining:864000000

2025-11-24T04:58:21.523 MpWriteUupSignatureVersion 1.441.448.0, hr = 0

2025-11-24T04:58:21.525 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-24T04:58:21.537 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-24T04:58:21.538 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-24T04:58:21.538 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-24T04:58:21.538 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-24T04:58:21.538 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-24T04:58:21.554 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-24T04:58:21.555 [Plugin] Initializing RTP plugin state...

2025-11-24T04:58:21.555 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-24T04:58:21.555 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 24 - 2025 01:17:27

Last Perf: 11 - 24 - 2025 01:17:27

First RTP Scan: 11 - 24 - 2025 01:17:28

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1399

  Misses:4558

BM Queue:0,128,0

  Proc:0,54,0

  File:0,74,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:249853

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1289544362

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:21

  TotalStreamCon:15628

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:1090630

   TotalHits:1826820

   InstanceCacheInserts:81305

   InstanceCacheUpdates:0

   InstanceCacheDeletes:63274

   InstanceCacheHits:4625

   InstanceCacheMisses:307986

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:1ms (490/451)

   Success: 451, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-24T04:58:21.555 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BD703DE-85C0-4890-96D2-607253C51FF7}

2025-11-24T04:58:21.556 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8AD3FCA9-A11B-4FA5-B16E-882A0D1E5765}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8AD3FCA9-A11B-4FA5-B16E-882A0D1E5765}\mpasbase.vdm in use, hr=0x80070020

2025-11-24T04:58:21.556 [SCC][CID=645530281_23296] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-24T04:58:21.557 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-24T04:58:21.557 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-24T04:58:21.557 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-24T04:58:21.557 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-24T04:58:21.557 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-24T04:58:21.558 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-24-2025 04:58:21

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-24-2025 04:58:21

2025-11-24T04:58:21.560 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-24T04:58:21.560 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-24-2025 04:58:21

END TDT(U) telemetry



2025-11-24T04:58:21.562 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-24T04:58:21.562 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0

2025-11-24T04:58:21.564 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T04:58:21.564 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-24T04:58:21.564 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-24T04:58:21.564 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-24T04:58:21.564 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-24T04:58:21.565 MdCoreSvc is supported in this platform and OS

Signature updated on 11-24-2025 04:58:21

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.448.0

AV Signature Version: 1.441.448.0

************************************************************

2025-11-24T04:58:21.566 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-24T04:58:21.566 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\05056B10-E74F-4B30-91C7-58FDDD554A684eec.1dc5cfef02dbe79

2025-11-24T04:58:21.577 Process scan (postsignatureupdatescan) started.

2025-11-24T04:58:21.612 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-24T04:58:21.613 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-24T04:58:21.775 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-24T04:58:21.775 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-24T04:58:21.775 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-24T04:58:21.776 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-24T04:58:21.776 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-24T04:58:21.778 [Engine] Engine 00007FFE7F1CA660 no longer in use. Number of active engines: 1

2025-11-24T04:58:21.778 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-24T04:58:21.778 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-24T04:58:21.918 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 3078, Count: 574, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\PrivacySandboxAttestationsPreloaded\2025.6.16.0\privacy-sandbox-attestations.dat, EstimatedImpact: 38%

2025-11-24T04:58:21.918 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 3024, Count: 200, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d28dcb44-f04d-45e2-9c18-184818503255.tmp, EstimatedImpact: 0%

2025-11-24T04:58:21.918 ProcessImageName: Spotify.exe, Pid: 17324, TotalTime: 2078, Count: 127, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\78d5308b-9031-47af-86dd-8be0b52e4973.tmp, EstimatedImpact: 0%

2025-11-24T04:58:21.918 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1534, Count: 84, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 84%

2025-11-24T04:58:21.918 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 735, Count: 98, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 0%

2025-11-24T04:58:21.918 ProcessImageName: RuntimeBroker.exe, Pid: 26532, TotalTime: 557, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 37%

2025-11-24T04:58:21.918 ProcessImageName: RuntimeBroker.exe, Pid: 25760, TotalTime: 496, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-24T04:58:21.918 ProcessImageName: DeviceCensus.exe, Pid: 25932, TotalTime: 371, Count: 13, MaxTime: 296, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 11%

2025-11-24T04:58:21.918 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 317, Count: 46, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Shared Dictionary\cache\159301556a8d4834_0, EstimatedImpact: 5%

2025-11-24T04:58:21.919 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 286, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T04:58:21.919 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 240, Count: 60, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\ID\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP.bin, EstimatedImpact: 0%

2025-11-24T04:58:21.919 ProcessImageName: taskhostw.exe, Pid: 20396, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-24T04:58:21.919 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 180, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-24T04:58:21.919 ProcessImageName: taskhostw.exe, Pid: 17820, TotalTime: 150, Count: 74, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 8%

2025-11-24T04:58:21.919 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 137, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-24T04:58:21.919 ProcessImageName: svchost.exe, Pid: 5804, TotalTime: 136, Count: 16, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 96%

2025-11-24T04:58:21.936 [Engine] RSIG_UNLOADENGINE, 00007FFE7F1CA660, err=0x0

2025-11-24T04:58:21.955 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8AD3FCA9-A11B-4FA5-B16E-882A0D1E5765} removed

2025-11-24T04:58:22.046 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-24T04:58:22.052 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-24T04:58:22.052 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-24T04:58:22.052 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-24T04:58:22.053 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-24T04:58:22.053 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-24T04:58:22.053 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-24T04:58:22.056 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-24T04:58:22.056 [RTP] Duplicating the current plugin configuration object...

2025-11-24T04:58:22.056 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-24T04:58:22.056 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-24T04:58:22.056 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-24T04:58:22.056 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-24T04:58:22.056 [RTP] No config change detected. Not updating plugin configuration.

2025-11-24T04:58:22.056 [RTP] No config changes found. No configuration switch.

2025-11-24T04:58:22.056 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-24T04:58:22.056 [RTP] Duplicating the current plugin configuration object...

2025-11-24T04:58:22.056 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-24T04:58:22.056 [RTP] Updating plugin configuration due to recent config changes (0x2) ...

2025-11-24T04:58:22.056 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-24T04:58:22.056 [RTP] No config change detected. Not updating plugin configuration.

2025-11-24T04:58:22.056 [RTP] No config changes found. No configuration switch.

2025-11-24T04:58:22.056 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0

2025-11-24T04:58:22.056 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-24T04:58:22.056 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-24T04:58:22.056 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-24T04:58:22.056 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-24T04:58:22.056 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-24T04:58:22.056 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-24T04:58:22.056 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-24T04:58:22.056 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-24T04:58:22.056 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-24T04:58:22.056 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-24T04:58:22.056 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-24T04:58:22.056 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-24T04:58:22.057 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-24T04:58:22.057 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-24T04:58:22.057 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-24T04:58:22.057 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T04:58:22.058 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T04:58:22.060 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T04:58:22.062 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T04:58:22.064 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T04:58:22.065 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 81575131(ms) from now at 04:37 (03:37 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-24T04:58:23.573 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-24T04:58:23.578 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-24T04:58:23.580 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-24T04:58:24.594 [RTP] Duplicating the current plugin configuration object...

2025-11-24T04:58:24.594 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-24T04:58:24.594 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-24T04:58:24.594 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-24T04:58:24.594 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157ED7C270CE, sigsha=5eded354160aa060b3f2a16db0725661264de9cd, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF9518016, sigsha=8fa60ffaf004b3696b5767c35f78f1425d04eb09, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0xa85b3f00

2025-11-24T04:58:27.491 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-24T04:58:27.491 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T04:58:27.491 [Cloud] Queued cloud request.

2025-11-24T04:58:27.491 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-24T04:58:27.491 [Cloud] Dequeued cloud request.

2025-11-24T04:58:27.491 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8ca8e74d319b26fe9c0901b2ed05c72ff6f6a67f

Dynamic Signature Compilation Timestamp:11-24-2025 04:58:27

Persistence Type:Duration

Time remaining:864000000

2025-11-24T04:58:27.717 Dynamic signature received

2025-11-24T04:58:27.717 [Cloud] End of cloud request.

2025-11-24T04:58:27.718 RTSD:RTSD recieved, rescanning impacted resources

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-24T04:58:28.227 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T04:58:29.112 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-24T04:58:29.112 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T04:58:29.112 [Cloud] Queued cloud request.

2025-11-24T04:58:29.112 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-24T04:58:29.112 [Cloud] Dequeued cloud request.

2025-11-24T04:58:29.112 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T04:58:29.412 [Cloud] End of cloud request.

2025-11-24T04:58:29.919 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T04:58:37.634 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-24T04:58:37.635 Process scan (postsignatureupdatescan) completed.

2025-11-24T05:01:28.510 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T05:03:21.495 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-24T05:03:57.274 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #250929, FileId: 0xb50000000097d4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T05:16:33.500 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T05:18:58.725 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #251310, FileId: 0x165000000004363, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T05:31:38.494 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T05:33:59.195 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #251476, FileId: 0x243000000007805, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T05:46:43.498 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T05:48:59.304 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #251782, FileId: 0xa0000000091a1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T05:52:05.572 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #252081, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T05:52:05.576 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #252082, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T05:52:15.580 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #252098, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T05:52:15.583 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #252100, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T06:01:48.480 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T06:04:00.547 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #252257, FileId: 0x260000000159be, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T06:16:53.476 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T06:17:58.551 Bm signature throttled:0x0000fab3228bcd4d

2025-11-24T06:19:00.626 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #252513, FileId: 0x340000000159be, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T06:31:58.484 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T06:34:00.877 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #252595, FileId: 0x176000000004363, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T06:47:03.474 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T06:49:00.989 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #252707, FileId: 0xdb000000001be4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T06:52:07.651 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #252717, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T06:52:07.654 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #252718, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T06:52:17.660 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #252723, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T06:52:17.663 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #252724, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T06:58:21.444 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 1837, Count: 187, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\drivers\afd.sys, EstimatedImpact: 0%

2025-11-24T06:58:21.444 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1280, Count: 32, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 100%

2025-11-24T06:58:21.444 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 1258, Count: 86, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d6dd52b3-457d-4bce-8b43-7e7e607f5274.tmp, EstimatedImpact: 0%

2025-11-24T06:58:21.444 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 992, Count: 55, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\6aa7750d-0145-4c47-992c-80abb73175e6.tmp, EstimatedImpact: 0%

2025-11-24T06:58:21.445 ProcessImageName: RuntimeBroker.exe, Pid: 9976, TotalTime: 511, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-24T06:58:21.445 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 210, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-24T06:58:21.445 ProcessImageName: taskhostw.exe, Pid: 6636, TotalTime: 150, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-24T06:58:21.445 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T06:58:21.445 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-24T06:58:21.445 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-24T06:58:21.445 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 32%

2025-11-24T06:58:21.445 ProcessImageName: Spotify.exe, Pid: 24768, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\apppatch\DirectXApps.sdb, EstimatedImpact: 10%

2025-11-24T06:58:21.445 ProcessImageName: StoreDesktopExtension.exe, Pid: 7372, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-24T06:58:21.445 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-24T06:58:21.445 ProcessImageName: taskhostw.exe, Pid: 5904, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 17%

2025-11-24T06:58:21.445 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvdrsdb1.bin, EstimatedImpact: 0%

2025-11-24T06:58:21.445 ProcessImageName: taskhostw.exe, Pid: 18508, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-24T06:58:21.445 ProcessImageName: updater.exe, Pid: 26328, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-24T07:02:08.464 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T07:04:01.232 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #253304, FileId: 0xeb00000001561f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T07:17:13.470 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T07:19:02.667 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #253551, FileId: 0xde000000021244, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T07:32:18.452 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T07:34:03.980 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #253670, FileId: 0xb5000000023464, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T07:47:23.448 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T07:49:04.599 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #253775, FileId: 0xc3000000023464, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T07:52:04.989 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #253805, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T07:52:04.992 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #253806, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T07:52:14.990 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #253813, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T07:52:14.991 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #253814, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T07:52:14.994 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #253815, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T07:52:14.995 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #253816, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T08:01:26.725 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #254018, FileId: 0x1fb00000000f44a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T08:02:28.455 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T08:04:05.056 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #254036, FileId: 0x2da0000000231f9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T08:17:33.438 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T08:18:00.658 Bm signature throttled:0x0000fab3228bcd4d

2025-11-24T08:19:05.336 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #254215, FileId: 0x4b000000023323, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T08:32:38.444 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T08:34:05.475 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #254281, FileId: 0x4f000000027fdf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T08:47:43.429 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T08:49:05.785 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #254786, FileId: 0x1a200000001a13f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T08:52:06.469 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #254796, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T08:52:06.478 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #254797, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T08:52:16.474 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #254802, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T08:52:16.486 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #254803, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T08:58:21.408 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 2673, Count: 172, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d6dd52b3-457d-4bce-8b43-7e7e607f5274.tmp, EstimatedImpact: 0%

2025-11-24T08:58:21.408 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 1882, Count: 193, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\drivers\afd.sys, EstimatedImpact: 0%

2025-11-24T08:58:21.408 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1841, Count: 109, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\3454547c-c680-4d02-a59a-48310275b1b7.tmp, EstimatedImpact: 0%

2025-11-24T08:58:21.408 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1427, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 91%

2025-11-24T08:58:21.408 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1280, Count: 32, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 100%

2025-11-24T08:58:21.408 ProcessImageName: RuntimeBroker.exe, Pid: 9976, TotalTime: 511, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-24T08:58:21.408 ProcessImageName: WmiPrvSE.exe, Pid: 14952, TotalTime: 285, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf, EstimatedImpact: 27%

2025-11-24T08:58:21.408 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 225, Count: 55, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-24T08:58:21.408 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 151, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T08:58:21.408 ProcessImageName: taskhostw.exe, Pid: 6636, TotalTime: 150, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-24T08:58:21.408 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 136, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-24T08:58:21.408 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 135, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-24T08:58:21.408 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 76, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-24T08:58:21.408 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 32%

2025-11-24T08:58:21.408 ProcessImageName: Spotify.exe, Pid: 24768, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\apppatch\DirectXApps.sdb, EstimatedImpact: 10%

2025-11-24T08:58:21.409 ProcessImageName: StoreDesktopExtension.exe, Pid: 7372, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-24T08:58:21.409 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 2%

2025-11-24T08:58:21.409 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-24T08:58:21.409 ProcessImageName: taskhostw.exe, Pid: 5904, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 17%

2025-11-24T08:58:21.409 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvdrsdb1.bin, EstimatedImpact: 0%

2025-11-24T08:58:21.409 ProcessImageName: taskhostw.exe, Pid: 22312, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-24T08:58:21.409 ProcessImageName: updater.exe, Pid: 6260, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\30404cd4-7981-4fdd-948f-41451b78967e.tmp, EstimatedImpact: 0%

2025-11-24T08:58:21.409 ProcessImageName: taskhostw.exe, Pid: 18508, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-24T08:58:21.409 ProcessImageName: updater.exe, Pid: 26328, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-24T09:02:48.425 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T09:04:07.264 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #254952, FileId: 0x61000000003fb3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T09:09:54.328 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #255095, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T09:17:53.421 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T09:19:07.289 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #255147, FileId: 0xc6000000022bf9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T09:32:58.413 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T09:34:07.510 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #255228, FileId: 0x9a000000008a91, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T09:45:41.001 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #255361, FileId: 0x1fc00000000f44a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T09:48:03.418 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T09:49:07.956 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #255377, FileId: 0xca000000019e60, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T09:52:06.619 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #255541, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T09:52:06.631 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #255542, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T09:52:16.619 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #255547, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T09:52:16.622 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #255549, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T10:03:08.408 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T10:04:08.083 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #255679, FileId: 0x20d00000001d5e8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T10:18:02.571 Bm signature throttled:0x0000fab3228bcd4d

2025-11-24T10:18:13.402 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T10:19:08.246 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #255925, FileId: 0x18b000000004363, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T10:33:18.402 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T10:34:08.619 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #255985, FileId: 0x650000000299f8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T10:48:23.395 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T10:49:08.938 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #256083, FileId: 0x7d000000014075, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T10:52:07.168 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #256118, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T10:52:07.174 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #256119, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T10:52:17.166 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #256124, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T10:52:17.170 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #256125, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T10:58:21.376 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 4208, Count: 259, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d6dd52b3-457d-4bce-8b43-7e7e607f5274.tmp, EstimatedImpact: 0%

2025-11-24T10:58:21.376 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2815, Count: 163, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\3454547c-c680-4d02-a59a-48310275b1b7.tmp, EstimatedImpact: 0%

2025-11-24T10:58:21.376 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 1912, Count: 199, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\drivers\afd.sys, EstimatedImpact: 0%

2025-11-24T10:58:21.376 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1427, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 91%

2025-11-24T10:58:21.376 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1280, Count: 32, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 100%

2025-11-24T10:58:21.376 ProcessImageName: RuntimeBroker.exe, Pid: 9976, TotalTime: 511, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-24T10:58:21.376 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 289, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T10:58:21.376 ProcessImageName: WmiPrvSE.exe, Pid: 14952, TotalTime: 285, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf, EstimatedImpact: 27%

2025-11-24T10:58:21.376 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 255, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-24T10:58:21.376 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 165, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-24T10:58:21.376 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 152, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-24T10:58:21.376 ProcessImageName: taskhostw.exe, Pid: 6636, TotalTime: 150, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-24T10:58:21.376 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 136, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-24T10:58:21.376 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-24T10:58:21.376 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 32%

2025-11-24T10:58:21.376 ProcessImageName: Spotify.exe, Pid: 24768, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\apppatch\DirectXApps.sdb, EstimatedImpact: 10%

2025-11-24T10:58:21.376 ProcessImageName: StoreDesktopExtension.exe, Pid: 7372, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-24T10:58:21.376 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 2%

2025-11-24T10:58:21.376 ProcessImageName: taskhostw.exe, Pid: 5904, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 17%

2025-11-24T10:58:21.376 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvdrsdb1.bin, EstimatedImpact: 0%

2025-11-24T10:58:21.376 ProcessImageName: taskhostw.exe, Pid: 12944, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-24T10:58:21.376 ProcessImageName: taskhostw.exe, Pid: 22312, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-24T10:58:21.376 ProcessImageName: updater.exe, Pid: 6260, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\30404cd4-7981-4fdd-948f-41451b78967e.tmp, EstimatedImpact: 0%

2025-11-24T10:58:21.376 ProcessImageName: taskhostw.exe, Pid: 18508, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-24T10:58:21.376 ProcessImageName: updater.exe, Pid: 26328, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-24T11:03:28.381 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T11:04:09.149 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #256252, FileId: 0x5a000000019dd0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

Internal signature match:subtype=Lowfi, sigseq=0x0000157E2CE6302D, sigsha=0df7fd029bfad03be2cc5ad7305e93356bdbb97f, cached=false, source=2, resourceid=0x169e3e31

Internal signature match:subtype=Lowfi, sigseq=0x0000157E98BBA293, sigsha=4086ec4288f6c8f13109984064d4d899f215d4cd, cached=false, source=2, resourceid=0x169e3e31

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=2, resourceid=0x169e3e31

2025-11-24T11:05:07.814 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-24T11:05:07.814 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T11:05:07.814 [Cloud] Queued cloud request.

2025-11-24T11:05:07.814 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-24T11:05:07.814 [Cloud] Dequeued cloud request.

2025-11-24T11:05:07.814 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T11:05:08.444 [Cloud] End of cloud request.

2025-11-24T11:05:08.444 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume4\Users\ServerPC\Downloads\FileZilla_Server_1.12.0_win64-setup.exe. status=0x40070000, statusex=0x200300, threatid=0x80000000, sigseq=0x157e2ce6302d

Internal signature match:subtype=Lowfi, sigseq=0x0000157EE0FE8DC8, sigsha=f5846efe9949451de5145a9eacbdc8c7f901eab3, cached=false, source=2, resourceid=0x169e3e31

Internal signature match:subtype=Lowfi, sigseq=0x0000157E50AA0757, sigsha=f6d1ff14a6f5c5438ada4e530996c660ec877fa1, cached=false, source=2, resourceid=0x169e3e31

Internal signature match:subtype=Lowfi, sigseq=0x0000157ED4763E79, sigsha=b62b847555f2db81af8b15e89b574189c0edd86e, cached=false, source=2, resourceid=0x169e3e31

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=2, resourceid=0x169e3e31

Internal signature match:subtype=Lowfi, sigseq=0x00000555498DA744, sigsha=f9fe7263cd98e932bfa7989bfe514ab1a1359a57, cached=false, source=2, resourceid=0x169e3e31

Internal signature match:subtype=Lowfi, sigseq=0x0000DBE7E136D7DE, sigsha=1e15556f033e026f78e8816adff4c585631f3502, cached=false, source=2, resourceid=0x169e3e31

2025-11-24T11:05:08.862 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-24T11:05:08.862 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T11:05:08.862 [Cloud] Queued cloud request.

2025-11-24T11:05:08.862 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-24T11:05:08.862 [Cloud] Dequeued cloud request.

2025-11-24T11:05:08.862 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T11:05:08.956 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T11:05:09.115 [Cloud] End of cloud request.

2025-11-24T11:05:09.115 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume4\Users\ServerPC\Downloads\FileZilla_Server_1.12.0_win64-setup.exe. status=0x40070000, statusex=0x200310, threatid=0x80000000, sigseq=0x157ee0fe8dc8

2025-11-24T11:05:09.638 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T11:05:23.064 Bm signature throttled:0x00002db31bed458f

2025-11-24T11:05:23.754 Bm signature throttled:0x00002db31bed458f

2025-11-24T11:05:25.645 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #257299, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T11:05:27.167 Bm signature throttled:0x00002db31bed458f

2025-11-24T11:06:01.593 Bm signature throttled:0x00002db31bed458f

2025-11-24T11:18:33.376 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T11:19:09.339 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #258182, FileId: 0x1a0000000232ed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T11:33:38.376 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T11:34:04.650 Bm signature throttled:0x00002db31bed458f

2025-11-24T11:34:10.504 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #258285, FileId: 0xee0000000198d8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T11:48:43.367 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T11:49:11.624 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #258419, FileId: 0x385000000023c1b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T11:52:05.246 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #258440, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T11:52:05.250 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #258441, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T11:52:15.260 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #258454, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T11:52:15.260 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #258455, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T11:52:15.264 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #258456, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T12:03:48.366 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T12:04:12.819 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #258603, FileId: 0x75000000023e6e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T12:18:53.352 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T12:19:13.924 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #258827, FileId: 0x3f000000029c68, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T12:33:58.359 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T12:34:14.696 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #258886, FileId: 0x9900000001d496, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T12:49:03.344 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T12:49:15.263 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #258963, FileId: 0x53000000029cbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T12:52:05.980 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #258970, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T12:52:05.983 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #258971, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T12:52:15.989 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #258974, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T12:52:15.993 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #258976, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T12:58:21.340 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 4510, Count: 281, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d6dd52b3-457d-4bce-8b43-7e7e607f5274.tmp, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3057, Count: 177, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\3454547c-c680-4d02-a59a-48310275b1b7.tmp, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 1927, Count: 201, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\drivers\afd.sys, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1871, Count: 49, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\FileZilla_Server_1.12.0_win64-setup.exe, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1427, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 91%

2025-11-24T12:58:21.340 ProcessImageName: RuntimeBroker.exe, Pid: 9976, TotalTime: 511, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-24T12:58:21.340 ProcessImageName: Speedtest.exe, Pid: 26616, TotalTime: 495, Count: 88, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Ookla.SpeedtestbyOokla_1.18.194.0_x64__43tkc6nmykmb6\Data\boot.config, EstimatedImpact: 25%

2025-11-24T12:58:21.340 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 405, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 71%

2025-11-24T12:58:21.340 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 394, Count: 33, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: WmiPrvSE.exe, Pid: 14952, TotalTime: 285, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf, EstimatedImpact: 27%

2025-11-24T12:58:21.340 ProcessImageName: powershell.exe, Pid: 17508, TotalTime: 274, Count: 45, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\4acfdbda9fe7d2c227cd2d57ea292ba9\System.Management.Automation.ni.dll, EstimatedImpact: 26%

2025-11-24T12:58:21.340 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 270, Count: 63, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 255, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 212, Count: 34, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 211, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 154, Count: 9, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server.exe, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: WmiPrvSE.exe, Pid: 20708, TotalTime: 154, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\portcls.sys, EstimatedImpact: 100%

2025-11-24T12:58:21.340 ProcessImageName: taskhostw.exe, Pid: 6636, TotalTime: 150, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-24T12:58:21.340 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: wallpaper32.exe, Pid: 18800, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 52%

2025-11-24T12:58:21.340 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\25ed6720-833b-418c-a9be-9785d25ef4b6.tmp, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: ffdetect.exe, Pid: 7684, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 10%

2025-11-24T12:58:21.340 ProcessImageName: nvcontainer.exe, Pid: 12680, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\UXD\Log.nvcontainer.exe.log, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: Spotify.exe, Pid: 24768, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\apppatch\DirectXApps.sdb, EstimatedImpact: 10%

2025-11-24T12:58:21.340 ProcessImageName: MicrosoftStartFeedProvider.exe, Pid: 12960, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 6%

2025-11-24T12:58:21.340 ProcessImageName: StoreDesktopExtension.exe, Pid: 7372, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: taskhostw.exe, Pid: 12944, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-24T12:58:21.340 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvdrsdb1.bin, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: taskhostw.exe, Pid: 5904, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 17%

2025-11-24T12:58:21.340 ProcessImageName: PhoneExperienceHost.exe, Pid: 1316, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\1044\StructuredQuerySchema.bin, EstimatedImpact: 12%

2025-11-24T12:58:21.340 ProcessImageName: taskhostw.exe, Pid: 536, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 15%

2025-11-24T12:58:21.340 ProcessImageName: dllhost.exe, Pid: 7840, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: taskhostw.exe, Pid: 22312, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-24T12:58:21.340 ProcessImageName: updater.exe, Pid: 6260, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\30404cd4-7981-4fdd-948f-41451b78967e.tmp, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: taskhostw.exe, Pid: 18508, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-24T12:58:21.340 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 3%

2025-11-24T12:58:21.340 ProcessImageName: powershell.exe, Pid: 20336, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\__PSScriptPolicyTest_dzwq4saq.td1.psm1, EstimatedImpact: 0%

2025-11-24T12:58:21.340 ProcessImageName: updater.exe, Pid: 26328, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-24T13:04:08.348 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T13:04:16.292 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #259071, FileId: 0x7d000000029db9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T13:19:13.335 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T13:19:17.056 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #259314, FileId: 0x60000000029de6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T13:34:18.127 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #259384, FileId: 0x58000000029e53, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T13:34:18.341 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T13:49:18.802 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #259471, FileId: 0xe4000000023cc4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T13:49:23.323 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T13:52:07.232 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #259532, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T13:52:07.236 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #259533, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T13:52:17.246 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #259536, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T13:52:17.246 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #259537, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T13:52:17.251 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #259538, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T14:04:20.013 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #259759, FileId: 0x1af000000003f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T14:04:28.324 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T14:19:21.045 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #260069, FileId: 0x9900000000d251, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T14:19:33.326 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T14:34:22.059 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #260209, FileId: 0x7100000001a565, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T14:34:38.309 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

Internal signature match:subtype=Lowfi, sigseq=0x0002C7BD6F0B1013, sigsha=8bb06083c03020ac23ff7c874afe346f250526db, cached=false, source=12, resourceid=0x3190196d

2025-11-24T14:34:41.151 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-24T14:34:41.151 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T14:34:41.151 [Cloud] Queued cloud request.

2025-11-24T14:34:41.151 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-24T14:34:41.151 [Cloud] Dequeued cloud request.

2025-11-24T14:34:41.151 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T14:34:41.464 [Cloud] End of cloud request.



BEGIN BM telemetry

GUID:{55083783-0A79-66CC-0276-7252D199EAB1}

SignatureID:41451339027548

SigSha:f9012984297b7b6d6d5ac8e1327d18b6210fde19

ThreatLevel:0

ProcessID:25044

ProcessCreationTime:134084684807118401

SessionID:0

CreationTime:11-24-2025 14:34:41

ImagePath:C:\Windows\System32\VSSVC.exe

Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: C:\Windows\System32\services.exe:1040:1,

Operations:None

END BM telemetry



AMSI Result:LoFi

AMSI Originating Process:000061D4

2025-11-24T14:34:41.477 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 1 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: TRUE

Internal signature match:subtype=Lowfi, sigseq=0x0002C7BD6F0B1013, sigsha=8bb06083c03020ac23ff7c874afe346f250526db, cached=false, source=12, resourceid=0x3e62eed3

2025-11-24T14:34:41.499 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-24T14:34:41.499 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T14:34:41.499 [Cloud] Queued cloud request.

2025-11-24T14:34:41.499 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-24T14:34:41.499 [Cloud] Dequeued cloud request.

2025-11-24T14:34:41.499 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T14:34:41.525 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9de09ba67ffffffe

2025-11-24T14:34:41.526 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9de09ba67ffffffe

2025-11-24T14:34:41.544 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext)

2025-11-24T14:34:41.544 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T14:34:41.544 [Cloud] Queued cloud request.

2025-11-24T14:34:41.544 [Cloud] Dequeued cloud request.

2025-11-24T14:34:41.571 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T14:34:41.748 [Cloud] End of cloud request.

AMSI Result:LoFi

AMSI Originating Process:000061D4

2025-11-24T14:34:41.760 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-24T14:34:41.761 [Cloud] End of cloud request.

Internal signature match:subtype=Lowfi, sigseq=0x0002C7BD6F0B1013, sigsha=8bb06083c03020ac23ff7c874afe346f250526db, cached=false, source=12, resourceid=0x8162bbfd

2025-11-24T14:34:41.850 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-24T14:34:41.850 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T14:34:41.850 [Cloud] Queued cloud request.

2025-11-24T14:34:41.850 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-24T14:34:41.850 [Cloud] Dequeued cloud request.

2025-11-24T14:34:41.850 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T14:34:41.982 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T14:34:41.997 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-24T14:34:41.997 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T14:34:41.998 [Cloud] Queued cloud request.

2025-11-24T14:34:41.998 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-24T14:34:41.998 [Cloud] Dequeued cloud request.

2025-11-24T14:34:41.998 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T14:34:42.090 [Cloud] End of cloud request.

2025-11-24T14:34:42.098 [Cloud] SubmitReport(CMpBmSpyNetReportContext)

2025-11-24T14:34:42.098 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T14:34:42.098 [Cloud] Queued cloud request.

2025-11-24T14:34:42.098 [Cloud] Dequeued cloud request.

2025-11-24T14:34:42.099 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T14:34:42.224 [Cloud] End of cloud request.

AMSI Result:LoFi

AMSI Originating Process:000061D4

2025-11-24T14:34:42.268 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-24T14:34:42.269 [Cloud] End of cloud request.

2025-11-24T14:34:42.602 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T14:34:56.545 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 1 (0 - Regular, 1 - MemScan), 2 resources, RtpIoavOnly: TRUE

2025-11-24T14:34:56.548 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xf4f7913a7ffffffe

2025-11-24T14:34:56.549 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x4cdd02ee7ffffffe

2025-11-24T14:34:56.549 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xf4f7913a7ffffffe

2025-11-24T14:34:56.549 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x4cdd02ee7ffffffe

2025-11-24T14:34:56.573 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext)

2025-11-24T14:34:56.573 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T14:34:56.573 [Cloud] Queued cloud request.

2025-11-24T14:34:56.573 [Cloud] Dequeued cloud request.

2025-11-24T14:34:56.596 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T14:34:56.656 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-24T14:34:56.656 [Cloud] End of cloud request.

2025-11-24T14:34:57.176 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T14:42:40.969 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume4\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #263810, FileId: 0x1a000000009c78, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T14:49:22.655 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #263860, FileId: 0x800000000039b8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T14:49:43.303 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T14:52:05.671 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #263869, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T14:52:05.675 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #263870, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T14:52:15.682 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #263876, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T14:52:15.683 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #263877, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T14:52:15.686 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #263878, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T14:52:15.688 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #263879, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T14:58:21.308 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 5020, Count: 320, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d6dd52b3-457d-4bce-8b43-7e7e607f5274.tmp, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3419, Count: 200, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\3454547c-c680-4d02-a59a-48310275b1b7.tmp, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: SrTasks.exe, Pid: 23164, TotalTime: 3001, Count: 741, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 10%

2025-11-24T14:58:21.308 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 1927, Count: 203, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\drivers\afd.sys, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1871, Count: 49, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\FileZilla_Server_1.12.0_win64-setup.exe, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1427, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 91%

2025-11-24T14:58:21.308 ProcessImageName: SrTasks.exe, Pid: 22928, TotalTime: 1095, Count: 325, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy16\Windows\System32\DriverStore\FileRepository\netvwifimp.inf_amd64_dca919233ea9fbe7\netvwifimp.inf, EstimatedImpact: 6%

2025-11-24T14:58:21.308 ProcessImageName: Speedtest.exe, Pid: 26616, TotalTime: 705, Count: 144, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Ookla.SpeedtestbyOokla_1.18.194.0_x64__43tkc6nmykmb6\Data\boot.config, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: RuntimeBroker.exe, Pid: 9976, TotalTime: 511, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-24T14:58:21.308 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 500, Count: 41, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 405, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 71%

2025-11-24T14:58:21.308 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 376, Count: 59, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 375, Count: 55, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 330, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 315, Count: 68, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: WmiPrvSE.exe, Pid: 14952, TotalTime: 285, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf, EstimatedImpact: 27%

2025-11-24T14:58:21.308 ProcessImageName: powershell.exe, Pid: 17508, TotalTime: 274, Count: 45, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\4acfdbda9fe7d2c227cd2d57ea292ba9\System.Management.Automation.ni.dll, EstimatedImpact: 26%

2025-11-24T14:58:21.308 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 272, Count: 42, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 154, Count: 9, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server.exe, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: WmiPrvSE.exe, Pid: 20708, TotalTime: 154, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\portcls.sys, EstimatedImpact: 100%

2025-11-24T14:58:21.308 ProcessImageName: taskhostw.exe, Pid: 6636, TotalTime: 150, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-24T14:58:21.308 ProcessImageName: ngentask.exe, Pid: 17416, TotalTime: 150, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 14%

2025-11-24T14:58:21.308 ProcessImageName: ngentask.exe, Pid: 3048, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 15%

2025-11-24T14:58:21.308 ProcessImageName: ngentask.exe, Pid: 21084, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 16%

2025-11-24T14:58:21.308 ProcessImageName: ngentask.exe, Pid: 20892, TotalTime: 120, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 20%

2025-11-24T14:58:21.308 ProcessImageName: taskhostw.exe, Pid: 22036, TotalTime: 107, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 4%

2025-11-24T14:58:21.308 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: ngentask.exe, Pid: 20588, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 47%

2025-11-24T14:58:21.308 ProcessImageName: wallpaper32.exe, Pid: 18800, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 52%

2025-11-24T14:58:21.308 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\25ed6720-833b-418c-a9be-9785d25ef4b6.tmp, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: ffdetect.exe, Pid: 7684, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 10%

2025-11-24T14:58:21.308 ProcessImageName: ngentask.exe, Pid: 17128, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 38%

2025-11-24T14:58:21.308 ProcessImageName: nvcontainer.exe, Pid: 12680, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\UXD\Log.nvcontainer.exe.log, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: Spotify.exe, Pid: 24768, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\apppatch\DirectXApps.sdb, EstimatedImpact: 10%

2025-11-24T14:58:21.308 ProcessImageName: StoreDesktopExtension.exe, Pid: 7372, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: MicrosoftStartFeedProvider.exe, Pid: 12960, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 6%

2025-11-24T14:58:21.308 ProcessImageName: ngentask.exe, Pid: 22856, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 25%

2025-11-24T14:58:21.308 ProcessImageName: taskhostw.exe, Pid: 5904, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 17%

2025-11-24T14:58:21.308 ProcessImageName: PhoneExperienceHost.exe, Pid: 1316, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\1044\StructuredQuerySchema.bin, EstimatedImpact: 12%

2025-11-24T14:58:21.308 ProcessImageName: taskhostw.exe, Pid: 536, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 15%

2025-11-24T14:58:21.308 ProcessImageName: taskhostw.exe, Pid: 13368, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 15%

2025-11-24T14:58:21.308 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvdrsdb1.bin, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: taskhostw.exe, Pid: 12944, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-24T14:58:21.308 ProcessImageName: taskhostw.exe, Pid: 13704, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 13%

2025-11-24T14:58:21.308 ProcessImageName: taskhostw.exe, Pid: 22312, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-24T14:58:21.308 ProcessImageName: dllhost.exe, Pid: 7840, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: updater.exe, Pid: 25732, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\b216cf5e-50de-4728-9cbd-7da7a113e9ed.tmp, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: updater.exe, Pid: 6260, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\30404cd4-7981-4fdd-948f-41451b78967e.tmp, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: taskhostw.exe, Pid: 18508, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-24T14:58:21.308 ProcessImageName: taskhostw.exe, Pid: 4136, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 7%

2025-11-24T14:58:21.308 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 3%

2025-11-24T14:58:21.308 ProcessImageName: powershell.exe, Pid: 20336, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\__PSScriptPolicyTest_dzwq4saq.td1.psm1, EstimatedImpact: 0%

2025-11-24T14:58:21.308 ProcessImageName: updater.exe, Pid: 26328, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-24T15:04:23.900 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #264118, FileId: 0xba000000008a91, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T15:04:48.300 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T15:11:31.483 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume4\ProgramData\NVIDIA\DisplaySessionContainer4.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #264720, FileId: 0x9200000000483f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T15:11:31.544 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\NvContainer\NvContainerSession4.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #264725, FileId: 0x4b00000001452b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T15:11:32.630 Bm signature throttled:0x00002db31bed458f

2025-11-24T15:11:34.001 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\console.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #264967, FileId: 0xd68000000000041, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T15:11:34.994 Bm signature throttled:0x00002db31bed458f

2025-11-24T15:11:36.967 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\GallerySettings.json. Process: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA Overlay.exe, Status: 0xc0000001, State: 0, ScanRequest #265351, FileId: 0x40000000792d2, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T15:11:37.716 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\ShadowPlay\CaptureCore.log. Process: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe, Status: 0xc0000001, State: 0, ScanRequest #265397, FileId: 0x500000001ce2c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T15:12:27.403 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent_new.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #265605, FileId: 0x8600000001de1b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T15:12:33.541 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #265607, FileId: 0xaf00000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T15:18:07.554 Bm signature throttled:0x0000fab3228bcd4d

2025-11-24T15:19:11.536 Bm signature throttled:0x00002db31bed458f

2025-11-24T15:19:24.808 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #265711, FileId: 0x1db00000000767b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T15:19:53.303 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T15:34:58.288 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T15:50:03.291 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T16:05:08.284 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T16:19:25.957 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #266596, FileId: 0x7900000002a227, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T16:20:13.282 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T16:35:18.274 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T16:50:23.268 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T16:58:21.272 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 5155, Count: 330, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d6dd52b3-457d-4bce-8b43-7e7e607f5274.tmp, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4159, Count: 251, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\3454547c-c680-4d02-a59a-48310275b1b7.tmp, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 3250, Count: 75, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\FileZilla_Server_1.12.0_win64-setup.exe, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: SrTasks.exe, Pid: 23164, TotalTime: 3001, Count: 741, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 10%

2025-11-24T16:58:21.272 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 2107, Count: 230, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\drivers\afd.sys, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 1938, Count: 200, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\osc\main.497d57969ef1c036.js, EstimatedImpact: 2%

2025-11-24T16:58:21.272 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1427, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 91%

2025-11-24T16:58:21.272 ProcessImageName: SrTasks.exe, Pid: 22928, TotalTime: 1095, Count: 325, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy16\Windows\System32\DriverStore\FileRepository\netvwifimp.inf_amd64_dca919233ea9fbe7\netvwifimp.inf, EstimatedImpact: 6%

2025-11-24T16:58:21.272 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 919, Count: 90, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\90b9ee00-f237-4380-a94d-e2db8003e49f.tmp, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: Speedtest.exe, Pid: 26616, TotalTime: 705, Count: 144, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Ookla.SpeedtestbyOokla_1.18.194.0_x64__43tkc6nmykmb6\Data\boot.config, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 605, Count: 50, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: RuntimeBroker.exe, Pid: 9976, TotalTime: 511, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-24T16:58:21.272 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 465, Count: 67, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 435, Count: 63, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 421, Count: 66, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 405, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 71%

2025-11-24T16:58:21.272 ProcessImageName: NVIDIA Overlay.exe, Pid: 20688, TotalTime: 379, Count: 32, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\shared_proto_db\metadata\LOG, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: wallpaper32.exe, Pid: 7136, TotalTime: 347, Count: 32, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 26%

2025-11-24T16:58:21.272 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 332, Count: 50, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 330, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: WmiPrvSE.exe, Pid: 14952, TotalTime: 285, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf, EstimatedImpact: 27%

2025-11-24T16:58:21.272 ProcessImageName: powershell.exe, Pid: 17508, TotalTime: 274, Count: 45, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\4acfdbda9fe7d2c227cd2d57ea292ba9\System.Management.Automation.ni.dll, EstimatedImpact: 26%

2025-11-24T16:58:21.272 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 181, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 180, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 154, Count: 9, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\filezilla-server.exe, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: WmiPrvSE.exe, Pid: 20708, TotalTime: 154, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\portcls.sys, EstimatedImpact: 100%

2025-11-24T16:58:21.272 ProcessImageName: nvcontainer.exe, Pid: 26200, TotalTime: 152, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\UXD\Log.nvcontainer.exe.log, EstimatedImpact: 24%

2025-11-24T16:58:21.272 ProcessImageName: taskhostw.exe, Pid: 6636, TotalTime: 150, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-24T16:58:21.272 ProcessImageName: ngentask.exe, Pid: 17416, TotalTime: 150, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 14%

2025-11-24T16:58:21.272 ProcessImageName: ngentask.exe, Pid: 3048, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 15%

2025-11-24T16:58:21.272 ProcessImageName: ngentask.exe, Pid: 21084, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 16%

2025-11-24T16:58:21.272 ProcessImageName: ngentask.exe, Pid: 20892, TotalTime: 120, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 20%

2025-11-24T16:58:21.272 ProcessImageName: taskhostw.exe, Pid: 22036, TotalTime: 107, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 4%

2025-11-24T16:58:21.272 ProcessImageName: nvcontainer.exe, Pid: 12680, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\UXD\Log.nvcontainer.exe.log, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: ngentask.exe, Pid: 20588, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 47%

2025-11-24T16:58:21.272 ProcessImageName: wallpaper32.exe, Pid: 18800, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 52%

2025-11-24T16:58:21.272 ProcessImageName: ngentask.exe, Pid: 17128, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 38%

2025-11-24T16:58:21.272 ProcessImageName: ffdetect.exe, Pid: 7684, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 10%

2025-11-24T16:58:21.272 ProcessImageName: PhoneExperienceHost.exe, Pid: 1316, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\1044\StructuredQuerySchema.bin, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvdrsdb1.bin, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: Spotify.exe, Pid: 24768, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\apppatch\DirectXApps.sdb, EstimatedImpact: 10%

2025-11-24T16:58:21.272 ProcessImageName: MicrosoftStartFeedProvider.exe, Pid: 12960, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 6%

2025-11-24T16:58:21.272 ProcessImageName: StoreDesktopExtension.exe, Pid: 7372, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: wallpaper32.exe, Pid: 18760, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 25%

2025-11-24T16:58:21.272 ProcessImageName: NVIDIA Overlay.exe, Pid: 9224, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 10%

2025-11-24T16:58:21.272 ProcessImageName: taskhostw.exe, Pid: 27132, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 5%

2025-11-24T16:58:21.272 ProcessImageName: ngentask.exe, Pid: 22856, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 25%

2025-11-24T16:58:21.272 ProcessImageName: taskhostw.exe, Pid: 6432, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 29%

2025-11-24T16:58:21.272 ProcessImageName: taskhostw.exe, Pid: 536, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 15%

2025-11-24T16:58:21.272 ProcessImageName: taskhostw.exe, Pid: 13704, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 13%

2025-11-24T16:58:21.272 ProcessImageName: taskhostw.exe, Pid: 13368, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 15%

2025-11-24T16:58:21.272 ProcessImageName: taskhostw.exe, Pid: 5904, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 17%

2025-11-24T16:58:21.272 ProcessImageName: taskhostw.exe, Pid: 12944, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-24T16:58:21.272 ProcessImageName: dllhost.exe, Pid: 7840, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: taskhostw.exe, Pid: 22312, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-24T16:58:21.272 ProcessImageName: updater.exe, Pid: 6260, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\30404cd4-7981-4fdd-948f-41451b78967e.tmp, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: updater.exe, Pid: 25732, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\b216cf5e-50de-4728-9cbd-7da7a113e9ed.tmp, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: taskhostw.exe, Pid: 4136, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 7%

2025-11-24T16:58:21.272 ProcessImageName: taskhostw.exe, Pid: 18508, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-24T16:58:21.272 ProcessImageName: ffdetect.exe, Pid: 18656, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 4%

2025-11-24T16:58:21.272 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 3%

2025-11-24T16:58:21.272 ProcessImageName: powershell.exe, Pid: 21868, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Windows\Prefetch\POWERSHELL.EXE-022A1004.pf, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: powershell.exe, Pid: 13828, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\__PSScriptPolicyTest_rhetklux.eqq.psm1, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: powershell.exe, Pid: 20336, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\__PSScriptPolicyTest_dzwq4saq.td1.psm1, EstimatedImpact: 0%

2025-11-24T16:58:21.272 ProcessImageName: updater.exe, Pid: 26328, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-24T17:02:58.640 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\51CFD948-35BF-4081-92E1-6E17548E68BD5130.1dc5d642e726ff0

2025-11-24T17:02:58.667 Verifying engine and signature files (source: 0) ...

2025-11-24T17:02:58.667 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{56965AF5-5A27-42E8-B323-A47C9909840D}\mpengine.dll] due to PPL.

2025-11-24T17:02:58.667 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{56965AF5-5A27-42E8-B323-A47C9909840D}\mpasbase.vdm] (file in cache)

2025-11-24T17:02:58.667 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{56965AF5-5A27-42E8-B323-A47C9909840D}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-24T17:02:58.679 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{56965AF5-5A27-42E8-B323-A47C9909840D}\mpasdlta.vdm]

2025-11-24T17:02:58.679 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{56965AF5-5A27-42E8-B323-A47C9909840D}\mpavbase.vdm] (file in cache)

2025-11-24T17:02:58.679 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{56965AF5-5A27-42E8-B323-A47C9909840D}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-24T17:02:58.687 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{56965AF5-5A27-42E8-B323-A47C9909840D}\mpavdlta.vdm]

2025-11-24T17:02:58.763 [Engine] IsHybridMode: 0

2025-11-24T17:02:58.763 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-24T17:02:58.771 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-0A87E4BF131A23A41250BF410753CFC3A13427C6.bin): 0x00000002

2025-11-24T17:02:58.775 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-0A87E4BF131A23A41250BF410753CFC3A13427C6.bin)

2025-11-24T17:02:58.775 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-24T17:02:58.775 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-24T17:02:58.775 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-24T17:02:58.775 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-24T17:03:03.989 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-24T17:03:03.989 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-24T17:03:03.997 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE717EA660, lRefCount: 5, hr=0

2025-11-24T17:03:03.997 [Engine] New active engine 00007FFE4C3EA660 replacing engine 00007FFE717EA660. Number of active engines: 2

2025-11-24T17:03:03.999 EngineInit:Global ASOC is enabled

2025-11-24T17:03:03.999 EngineInit:ASOO is enabled for developer volumes

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-24T17:03:04.028 MpWriteUupSignatureVersion 1.441.460.0, hr = 0

2025-11-24T17:03:04.028 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-24T17:03:04.043 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-24T17:03:04.045 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-24T17:03:04.045 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-24T17:03:04.045 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-24T17:03:04.045 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-24T17:03:04.057 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-24T17:03:04.057 [Plugin] Initializing RTP plugin state...

2025-11-24T17:03:04.057 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-24T17:03:04.057 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 24 - 2025 05:58:21

Last Perf: 11 - 24 - 2025 05:58:21

First RTP Scan: 11 - 24 - 2025 05:58:21

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:3896

  Misses:9906

BM Queue:0,63,0

  Proc:0,39,0

  File:0,31,0

Plugin Queue:0,1,0

  Threat:0,0,0

  Susp:0,1,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:267225

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1338801110

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:18

  TotalStreamCon:16054

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:1139880

   TotalHits:1921842

   InstanceCacheInserts:87924

   InstanceCacheUpdates:0

   InstanceCacheDeletes:64235

   InstanceCacheHits:4651

   InstanceCacheMisses:322000

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (1124/1220)

   Success: 1220, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-24T17:03:04.057 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{56965AF5-5A27-42E8-B323-A47C9909840D}

2025-11-24T17:03:04.057 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BD703DE-85C0-4890-96D2-607253C51FF7}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BD703DE-85C0-4890-96D2-607253C51FF7}\mpasbase.vdm in use, hr=0x80070020

2025-11-24T17:03:04.057 [SCC][CID=689013015_19152] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-24T17:03:04.057 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-24T17:03:04.057 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-24T17:03:04.057 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-24T17:03:04.057 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-24T17:03:04.057 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-24T17:03:04.061 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-24-2025 17:03:04

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-24-2025 17:03:04

2025-11-24T17:03:04.063 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-24T17:03:04.063 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-24T17:03:04.063 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-24T17:03:04.063 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-24-2025 17:03:04

END TDT(U) telemetry



2025-11-24T17:03:04.065 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T17:03:04.065 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-24T17:03:04.065 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-24T17:03:04.065 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-24T17:03:04.065 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-24T17:03:04.065 MdCoreSvc is supported in this platform and OS

Signature updated on 11-24-2025 17:03:04

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.460.0

AV Signature Version: 1.441.460.0

************************************************************

2025-11-24T17:03:04.065 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-24T17:03:04.065 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\51CFD948-35BF-4081-92E1-6E17548E68BD5130.1dc5d642e726ff0

2025-11-24T17:03:04.082 Process scan (postsignatureupdatescan) started.

2025-11-24T17:03:04.106 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-24T17:03:04.106 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-24T17:03:04.239 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-24T17:03:04.239 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-24T17:03:04.239 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-24T17:03:04.239 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-24T17:03:04.239 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-24T17:03:04.243 [Engine] Engine 00007FFE717EA660 no longer in use. Number of active engines: 1

2025-11-24T17:03:04.243 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-24T17:03:04.243 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-24T17:03:04.392 ProcessImageName: NVIDIA Overlay.exe, Pid: 23040, TotalTime: 5155, Count: 330, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d6dd52b3-457d-4bce-8b43-7e7e607f5274.tmp, EstimatedImpact: 0%

2025-11-24T17:03:04.392 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4204, Count: 254, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\3454547c-c680-4d02-a59a-48310275b1b7.tmp, EstimatedImpact: 0%

2025-11-24T17:03:04.392 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 3250, Count: 75, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\FileZilla_Server_1.12.0_win64-setup.exe, EstimatedImpact: 0%

2025-11-24T17:03:04.392 ProcessImageName: SrTasks.exe, Pid: 23164, TotalTime: 3001, Count: 741, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 10%

2025-11-24T17:03:04.392 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 2107, Count: 230, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\drivers\afd.sys, EstimatedImpact: 0%

2025-11-24T17:03:04.392 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 1938, Count: 200, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\osc\main.497d57969ef1c036.js, EstimatedImpact: 2%

2025-11-24T17:03:04.392 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1427, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 91%

2025-11-24T17:03:04.392 ProcessImageName: SrTasks.exe, Pid: 22928, TotalTime: 1095, Count: 325, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy16\Windows\System32\DriverStore\FileRepository\netvwifimp.inf_amd64_dca919233ea9fbe7\netvwifimp.inf, EstimatedImpact: 6%

2025-11-24T17:03:04.392 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 980, Count: 93, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\aa992214-3244-4502-bc0f-8b5d02b9f3ca.tmp, EstimatedImpact: 0%

2025-11-24T17:03:04.392 ProcessImageName: Speedtest.exe, Pid: 26616, TotalTime: 705, Count: 144, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Ookla.SpeedtestbyOokla_1.18.194.0_x64__43tkc6nmykmb6\Data\boot.config, EstimatedImpact: 0%

2025-11-24T17:03:04.392 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 605, Count: 50, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T17:03:04.392 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 511, Count: 69, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-24T17:03:04.392 ProcessImageName: RuntimeBroker.exe, Pid: 9976, TotalTime: 511, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-24T17:03:04.392 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 450, Count: 67, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-24T17:03:04.392 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 421, Count: 66, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-24T17:03:04.392 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 405, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 71%

2025-11-24T17:03:04.413 [Engine] RSIG_UNLOADENGINE, 00007FFE717EA660, err=0x0

2025-11-24T17:03:04.433 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BD703DE-85C0-4890-96D2-607253C51FF7} removed

2025-11-24T17:03:04.549 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-24T17:03:04.555 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-24T17:03:04.555 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-24T17:03:04.555 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-24T17:03:04.555 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-24T17:03:04.555 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-24T17:03:04.555 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-24T17:03:04.559 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-24T17:03:04.559 [RTP] Duplicating the current plugin configuration object...

2025-11-24T17:03:04.559 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-24T17:03:04.559 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-24T17:03:04.559 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-24T17:03:04.559 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-24T17:03:04.559 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-24T17:03:04.559 [RTP] No config change detected. Not updating plugin configuration.

2025-11-24T17:03:04.559 [RTP] No config changes found. No configuration switch.

2025-11-24T17:03:04.559 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-24T17:03:04.559 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-24T17:03:04.559 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-24T17:03:04.559 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-24T17:03:04.559 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-24T17:03:04.559 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-24T17:03:04.559 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-24T17:03:04.559 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-24T17:03:04.559 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-24T17:03:04.559 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-24T17:03:04.559 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-24T17:03:04.559 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-24T17:03:04.559 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-24T17:03:04.559 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-24T17:03:04.559 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-24T17:03:04.559 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-24T17:03:04.559 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T17:03:04.559 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T17:03:04.562 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T17:03:04.564 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T17:03:04.566 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T17:03:04.566 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 33030419(ms) from now at 03:13 (02:13 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-24T17:03:06.072 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-24T17:03:06.076 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-24T17:03:06.076 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-24T17:03:07.109 [RTP] Duplicating the current plugin configuration object...

2025-11-24T17:03:07.109 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-24T17:03:07.109 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-24T17:03:07.109 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-24T17:03:07.109 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-24T17:03:09.541 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-24T17:03:09.541 [Cloud] Start of cloud request. Passive mode: 0

2025-11-24T17:03:09.541 [Cloud] Queued cloud request.

2025-11-24T17:03:09.541 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-24T17:03:09.541 [Cloud] Dequeued cloud request.

2025-11-24T17:03:09.541 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-24T17:03:09.974 [Cloud] End of cloud request.

2025-11-24T17:03:10.489 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T17:03:18.397 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-24T17:03:18.397 Process scan (postsignatureupdatescan) completed.

2025-11-24T17:04:27.840 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #267379, FileId: 0x3d000000016fa3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T17:05:28.259 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T17:08:04.053 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-24T17:19:29.168 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #267981, FileId: 0x45000000016fa3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T17:20:33.269 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T17:34:29.229 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #268155, FileId: 0x3400000000d47a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T17:35:38.255 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T17:36:15.577 Bm signature throttled:0x00002db31bed458f

2025-11-24T17:39:40.901 Bm signature throttled:0x00002db31bed458f

2025-11-24T17:49:30.616 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #269042, FileId: 0x7800000001d423, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T17:50:43.251 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T17:52:06.271 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #269122, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T17:52:06.287 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #269123, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T17:52:16.271 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #269128, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T17:52:16.276 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #269129, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T18:01:37.744 Bm signature throttled:0x00002db31bed458f

2025-11-24T18:04:31.923 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #269269, FileId: 0x13f0000000189bd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T18:05:19.630 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #269359, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T18:05:48.256 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T18:11:01.198 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #269564, FileId: 0xed000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T18:11:56.617 Bm signature throttled:0x00002db31bed458f

2025-11-24T18:18:10.526 Bm signature throttled:0x0000fab3228bcd4d

2025-11-24T18:19:32.529 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #269648, FileId: 0x3d000000024484, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T18:20:53.242 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T18:34:32.865 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #270127, FileId: 0x29600000001ac76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T18:35:58.239 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T18:45:40.998 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #270374, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T18:45:53.392 Bm signature throttled:0x00002db31bed458f

2025-11-24T18:49:32.927 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #270395, FileId: 0x84000000055497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T18:51:03.236 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T18:52:07.503 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #270409, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T18:52:07.510 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #270410, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T18:52:17.514 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #270415, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T18:52:17.516 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #270416, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T19:03:03.971 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1480, Count: 86, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\9fe3007b-4d27-459d-8ed9-45c88a03f900.tmp, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1456, Count: 81, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-24T19:03:03.971 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1396, Count: 201, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1193, Count: 52, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\59549583-1586-49be-b596-5ee7bd24cbb5.tmp, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 901, Count: 147, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\SAW\3. Saw III (2006) Unrated 1080p HighCode.mkv, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 676, Count: 122, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 98%

2025-11-24T19:03:03.971 ProcessImageName: RuntimeBroker.exe, Pid: 17368, TotalTime: 527, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 29%

2025-11-24T19:03:03.971 ProcessImageName: WmiPrvSE.exe, Pid: 17500, TotalTime: 431, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 89%

2025-11-24T19:03:03.971 ProcessImageName: taskhostw.exe, Pid: 536, TotalTime: 210, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-24T19:03:03.971 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 195, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 140, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\mrxsmb.sys, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 138, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 137, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 136, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 135, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 62, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\611dc605-90eb-4d8f-ada6-5668087d0d6b.tmp, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 61, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\NvConfig\LocalizedConfig.json, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: StoreDesktopExtension.exe, Pid: 23876, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 28%

2025-11-24T19:03:03.971 ProcessImageName: nvngx_update.exe, Pid: 16776, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\nvngx_config.txt, EstimatedImpact: 5%

2025-11-24T19:03:03.971 ProcessImageName: updater.exe, Pid: 3848, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\35042b59-ac64-4178-b437-5ecc261e5c56.tmp, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 23%

2025-11-24T19:03:03.971 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalState\Spotify\cr_ri.pb, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-24T19:03:03.971 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NvProfileUpdaterPlugin\optimus\metadata.json, EstimatedImpact: 1%

2025-11-24T19:03:03.971 ProcessImageName: nvngx_update.exe, Pid: 3900, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpFC_TS_UseStrictOriginQuery new=0 old1

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-24T19:04:32.186 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T19:04:32.203 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-24T19:04:32.203 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-24T19:04:32.203 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0

2025-11-24T19:04:32.203 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T19:04:32.203 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-24T19:04:32.203 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-24T19:04:32.203 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-24T19:04:32.203 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-24T19:04:32.203 MdCoreSvc is supported in this platform and OS

2025-11-24T19:04:32.688 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-24T19:04:32.688 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-24T19:04:32.688 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-24T19:04:33.576 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #270549, FileId: 0x3e4000000015396, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T19:06:08.241 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T19:19:33.759 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #271241, FileId: 0x1db00000001a284, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T19:21:13.239 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T19:34:34.991 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #271387, FileId: 0xd7000000002311, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T19:36:18.224 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T19:45:41.039 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #271600, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T19:49:35.069 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #271628, FileId: 0x1b800000000e57f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T19:51:23.222 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T19:52:05.967 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #271698, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T19:52:05.973 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #271699, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T19:52:15.974 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #271706, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T19:52:15.980 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #271707, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T19:52:15.987 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #271708, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T19:52:15.991 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #271709, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T20:01:40.794 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #271983, FileId: 0xb300000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T20:04:35.426 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #272007, FileId: 0x25300000000eddd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T20:06:28.221 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T20:17:37.755 Bm signature throttled:0x0000fab3228bcd4d

2025-11-24T20:19:35.572 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #272321, FileId: 0x23a000000001b4a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T20:21:33.214 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T20:34:35.716 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #272392, FileId: 0x111000000011e8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T20:36:38.211 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T20:37:01.291 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #272470, FileId: 0xef000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T20:45:41.067 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #273204, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T20:47:54.761 Bm signature throttled:0x00002db31bed458f

2025-11-24T20:49:36.068 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #273223, FileId: 0x180000000018ca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T20:51:43.207 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T20:52:08.008 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #273232, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T20:52:08.011 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #273233, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T20:52:18.012 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #273238, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T20:52:18.016 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #273239, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T20:54:36.940 Bm signature throttled:0x0000fab3228bcd4d

2025-11-24T21:03:03.969 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3141, Count: 175, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\f5eb83e5-ef8c-4b53-865e-2bb796cee1f4.tmp, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2248, Count: 105, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\59549583-1586-49be-b596-5ee7bd24cbb5.tmp, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1781, Count: 184, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\ffprobe.exe, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: plugin-container.exe, Pid: 7304, TotalTime: 1498, Count: 8, MaxTime: 1390, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 100%

2025-11-24T21:03:03.969 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1456, Count: 81, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-24T21:03:03.969 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1396, Count: 201, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 691, Count: 124, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: RuntimeBroker.exe, Pid: 17368, TotalTime: 527, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 29%

2025-11-24T21:03:03.969 ProcessImageName: WmiPrvSE.exe, Pid: 17500, TotalTime: 431, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 89%

2025-11-24T21:03:03.969 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 255, Count: 66, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 243, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: taskhostw.exe, Pid: 536, TotalTime: 210, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-24T21:03:03.969 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 210, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 184, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 167, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\42771547-dee5-45dd-809c-4ba064348be7.tmp, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 151, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 140, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\mrxsmb.sys, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 139, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\611dc605-90eb-4d8f-ada6-5668087d0d6b.tmp, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: ffprobe.exe, Pid: 26060, TotalTime: 124, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\libx265_main12.dll, EstimatedImpact: 33%

2025-11-24T21:03:03.969 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 90, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: taskhostw.exe, Pid: 13612, TotalTime: 76, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-24T21:03:03.969 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 61, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\NvConfig\LocalizedConfig.json, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: StoreDesktopExtension.exe, Pid: 23876, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: svchost.exe, Pid: 20084, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_1795988618\BIT6BA8.tmp, EstimatedImpact: 1%

2025-11-24T21:03:03.969 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 28%

2025-11-24T21:03:03.969 ProcessImageName: nvngx_update.exe, Pid: 16776, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\nvngx_config.txt, EstimatedImpact: 5%

2025-11-24T21:03:03.969 ProcessImageName: updater.exe, Pid: 3848, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\35042b59-ac64-4178-b437-5ecc261e5c56.tmp, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 23%

2025-11-24T21:03:03.969 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_64A201640BD8E31E72E33FB1EBF9962D, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: steamwebhelper.exe, Pid: 16236, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Steam\htmlcache\Network\63b6be3b-8ab3-4dc7-a6f9-0d55dc5b2cc7.tmp, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NvProfileUpdaterPlugin\optimus\metadata.json, EstimatedImpact: 1%

2025-11-24T21:03:03.969 ProcessImageName: updater.exe, Pid: 12008, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\524297d0-e377-47d3-af7c-74f7da1a3896.tmp, EstimatedImpact: 0%

2025-11-24T21:03:03.969 ProcessImageName: nvngx_update.exe, Pid: 3900, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-24T21:04:36.294 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #273435, FileId: 0x2990000000010f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T21:06:48.211 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T21:19:36.405 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #273707, FileId: 0x2f2000000001f0b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T21:21:53.213 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T21:34:37.139 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #273863, FileId: 0x3b600000000206a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T21:36:58.210 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T21:45:40.996 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #274049, FileId: 0xf0000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T21:47:17.786 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\Nucleus-2025-11-24.1418.5324.3.aodl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #274120, FileId: 0x26d000000002562, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T21:47:17.853 Bm signature throttled:0x0000fab3228bcd4d

2025-11-24T21:49:37.712 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #274211, FileId: 0x3fe000000007ddf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T21:52:03.194 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T21:52:05.378 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #274238, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T21:52:05.381 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #274239, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T21:52:15.383 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #274246, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T21:52:15.387 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #274247, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T22:03:25.829 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #274515, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T22:04:38.869 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #274524, FileId: 0x44000000008e68, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T22:07:08.196 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T22:19:39.374 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #274771, FileId: 0xd7000000003e8e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T22:22:13.196 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T22:23:56.691 Bm signature throttled:0x00002db31bed458f

2025-11-24T22:34:39.937 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #275102, FileId: 0x540000000018aa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T22:37:18.182 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T22:47:31.532 Bm signature throttled:0x0000fab3228bcd4d

2025-11-24T22:49:40.299 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #275236, FileId: 0x51000000008b29, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T22:52:07.088 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #275243, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T22:52:07.093 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #275244, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T22:52:17.090 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #275250, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T22:52:17.093 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #275251, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T22:52:23.180 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T23:03:03.948 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 4117, Count: 262, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\f5eb83e5-ef8c-4b53-865e-2bb796cee1f4.tmp, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3017, Count: 158, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\59549583-1586-49be-b596-5ee7bd24cbb5.tmp, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1796, Count: 185, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\ffprobe.exe, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: plugin-container.exe, Pid: 7304, TotalTime: 1498, Count: 8, MaxTime: 1390, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 100%

2025-11-24T23:03:03.948 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1456, Count: 81, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-24T23:03:03.948 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1396, Count: 201, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 691, Count: 124, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: RuntimeBroker.exe, Pid: 17368, TotalTime: 527, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 29%

2025-11-24T23:03:03.948 ProcessImageName: WmiPrvSE.exe, Pid: 17500, TotalTime: 431, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 89%

2025-11-24T23:03:03.948 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 348, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 285, Count: 71, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 257, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 240, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 229, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: taskhostw.exe, Pid: 536, TotalTime: 210, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-24T23:03:03.948 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 197, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\42771547-dee5-45dd-809c-4ba064348be7.tmp, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 150, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 140, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\mrxsmb.sys, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 139, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\611dc605-90eb-4d8f-ada6-5668087d0d6b.tmp, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 135, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: ffprobe.exe, Pid: 26060, TotalTime: 124, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\libx265_main12.dll, EstimatedImpact: 33%

2025-11-24T23:03:03.948 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 15348, TotalTime: 90, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Videos\desktop.ini, EstimatedImpact: 1%

2025-11-24T23:03:03.948 ProcessImageName: backgroundTaskHost.exe, Pid: 17124, TotalTime: 90, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1763509465, EstimatedImpact: 19%

2025-11-24T23:03:03.948 ProcessImageName: taskhostw.exe, Pid: 13612, TotalTime: 76, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-24T23:03:03.948 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 61, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\NvConfig\LocalizedConfig.json, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: StoreDesktopExtension.exe, Pid: 23876, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: svchost.exe, Pid: 7032, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BITB611.tmp, EstimatedImpact: 1%

2025-11-24T23:03:03.948 ProcessImageName: svchost.exe, Pid: 20084, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_1795988618\BIT6BA8.tmp, EstimatedImpact: 1%

2025-11-24T23:03:03.948 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 28%

2025-11-24T23:03:03.948 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_64A201640BD8E31E72E33FB1EBF9962D, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: nvngx_update.exe, Pid: 16776, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\nvngx_config.txt, EstimatedImpact: 5%

2025-11-24T23:03:03.948 ProcessImageName: updater.exe, Pid: 3848, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\35042b59-ac64-4178-b437-5ecc261e5c56.tmp, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 23%

2025-11-24T23:03:03.948 ProcessImageName: steamwebhelper.exe, Pid: 16236, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Steam\htmlcache\Network\63b6be3b-8ab3-4dc7-a6f9-0d55dc5b2cc7.tmp, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NvProfileUpdaterPlugin\optimus\metadata.json, EstimatedImpact: 1%

2025-11-24T23:03:03.948 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: taskhostw.exe, Pid: 26980, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-24T23:03:03.948 ProcessImageName: updater.exe, Pid: 12008, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\524297d0-e377-47d3-af7c-74f7da1a3896.tmp, EstimatedImpact: 0%

2025-11-24T23:03:03.948 ProcessImageName: nvngx_update.exe, Pid: 3900, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

2025-11-24T23:04:33.811 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T23:04:33.824 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-24T23:04:33.825 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-24T23:04:33.825 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0

2025-11-24T23:04:33.828 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-24T23:04:33.829 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-24T23:04:33.829 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-24T23:04:33.829 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-24T23:04:33.829 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-24T23:04:33.829 MdCoreSvc is supported in this platform and OS

2025-11-24T23:04:34.322 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-24T23:04:34.322 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-24T23:04:34.322 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-24T23:04:41.114 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #275387, FileId: 0x2a000000008f3d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T23:07:28.182 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T23:19:41.631 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #275739, FileId: 0x21000000008e45, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T23:22:33.171 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T23:34:42.500 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #275839, FileId: 0x33000000009277, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T23:37:38.174 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-24T23:49:43.294 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #276386, FileId: 0x29000000008fec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T23:52:06.666 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #276421, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T23:52:06.668 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #276422, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T23:52:16.669 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #276429, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T23:52:16.674 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #276430, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-24T23:52:43.172 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T00:04:43.737 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #276525, FileId: 0x5f0000000094f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T00:07:48.159 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T00:17:08.164 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3

2025-11-25T00:17:08.164 Job Notification: New process added to job (13612)

2025-11-25T00:17:08.166 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched

2025-11-25T00:17:08.173 Aggressive catchup quick scan threshold: 6047957722307 / 25920000000000

2025-11-25T00:17:08.174 Job Notification: New process added to job (19644)

2025-11-25T00:17:08.181 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:13612] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:19644]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-25T00:17:08.227 Job Notification: New process added to job (6228)

2025-11-25T00:17:08.229 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched

2025-11-25T00:17:08.231 Job Notification: New process added to job (24068)

2025-11-25T00:17:08.238 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:6228] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:24068]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-25T00:17:08.267 Job Notification: New process added to job (4012)

2025-11-25T00:17:08.270 Task(GetDeviceTicket -AccessKey B1F797E7-4C95-4C23-9F37-D3D13C0A14A8 ) launched as network service

2025-11-25T00:17:08.685 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-25T00:17:08.685 [RTP] Duplicating the current plugin configuration object...

2025-11-25T00:17:08.685 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-25T00:17:08.685 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-25T00:17:08.685 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-25T00:17:08.685 [RTP] No config change detected. Not updating plugin configuration.

2025-11-25T00:17:08.685 [RTP] No config changes found. No configuration switch.

2025-11-25T00:17:08.685 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-25T00:17:08.760 Job Notification: Process exited from job (4012)

2025-11-25T00:17:08.968 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-25T00:17:08.968 [Cloud] Start of cloud request. Passive mode: 0

2025-11-25T00:17:08.968 [Cloud] Queued cloud request.

2025-11-25T00:17:08.968 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-25T00:17:08.968 [Cloud] Dequeued cloud request.

2025-11-25T00:17:08.968 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-25T00:17:08.969 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0

2025-11-25T00:17:08.969 [Cloud] Start of cloud request. Passive mode: 0

2025-11-25T00:17:08.969 [Cloud] Queued cloud request.

2025-11-25T00:17:08.969 [Cloud] Dequeued cloud request.

2025-11-25T00:17:08.970 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-25T00:17:09.047 [Cloud] End of cloud request.

2025-11-25T00:17:09.085 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-25T00:17:09.086 [Cloud] End of cloud request.

2025-11-25T00:17:09.475 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T00:17:22.498 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\B40C8CAF-2592-459C-91A7-FD9F049B6A0E5a3c.1dc5da0ddb1c0e8

2025-11-25T00:17:22.530 Verifying engine and signature files (source: 0) ...

2025-11-25T00:17:22.530 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96E3949D-AD89-48EE-990D-0695AA4ADF09}\mpengine.dll] due to PPL.

2025-11-25T00:17:22.530 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96E3949D-AD89-48EE-990D-0695AA4ADF09}\mpasbase.vdm] (file in cache)

2025-11-25T00:17:22.530 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96E3949D-AD89-48EE-990D-0695AA4ADF09}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-25T00:17:22.540 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96E3949D-AD89-48EE-990D-0695AA4ADF09}\mpasdlta.vdm]

2025-11-25T00:17:22.540 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96E3949D-AD89-48EE-990D-0695AA4ADF09}\mpavbase.vdm] (file in cache)

2025-11-25T00:17:22.540 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96E3949D-AD89-48EE-990D-0695AA4ADF09}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-25T00:17:22.549 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96E3949D-AD89-48EE-990D-0695AA4ADF09}\mpavdlta.vdm]

2025-11-25T00:17:22.628 [Engine] IsHybridMode: 0

2025-11-25T00:17:22.628 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-25T00:17:22.637 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-0C942AA994B35AE0AC336C1AAB232BDAA6589CCA.bin): 0x00000002

2025-11-25T00:17:22.639 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-0C942AA994B35AE0AC336C1AAB232BDAA6589CCA.bin)

2025-11-25T00:17:22.639 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-25T00:17:22.639 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-25T00:17:22.639 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-25T00:17:22.639 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-25T00:17:28.212 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-25T00:17:28.212 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpFC_TS_UseStrictOriginQuery new=0 old1

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-25T00:17:28.220 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE4C3EA660, lRefCount: 5, hr=0

2025-11-25T00:17:28.220 [Engine] New active engine 00007FFE7225A660 replacing engine 00007FFE4C3EA660. Number of active engines: 2

2025-11-25T00:17:28.228 EngineInit:Global ASOC is enabled

2025-11-25T00:17:28.228 EngineInit:ASOO is enabled for developer volumes

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.258 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T00:17:28.260 MpWriteUupSignatureVersion 1.441.469.0, hr = 0

2025-11-25T00:17:28.261 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-25T00:17:28.273 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-25T00:17:28.274 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-25T00:17:28.274 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-25T00:17:28.274 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-25T00:17:28.274 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-25T00:17:28.288 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-25T00:17:28.288 [Plugin] Initializing RTP plugin state...

2025-11-25T00:17:28.288 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-25T00:17:28.288 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 24 - 2025 18:03:04

Last Perf: 11 - 24 - 2025 18:03:04

First RTP Scan: 11 - 24 - 2025 18:03:05

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:837

  Misses:6382

BM Queue:0,43,0

  Proc:0,41,0

  File:0,30,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,2,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:276812

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1424440840

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:18

  TotalStreamCon:15711

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:1187054

   TotalHits:1986218

   InstanceCacheInserts:91082

   InstanceCacheUpdates:0

   InstanceCacheDeletes:67822

   InstanceCacheHits:4664

   InstanceCacheMisses:362599

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (1604/1606)

   Success: 1606, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-25T00:17:28.288 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96E3949D-AD89-48EE-990D-0695AA4ADF09}

2025-11-25T00:17:28.289 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{56965AF5-5A27-42E8-B323-A47C9909840D}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{56965AF5-5A27-42E8-B323-A47C9909840D}\mpasbase.vdm in use, hr=0x80070020

2025-11-25T00:17:28.289 [SCC][CID=715077359_18228] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-25T00:17:28.289 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-25T00:17:28.289 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-25T00:17:28.289 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-25T00:17:28.290 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-25T00:17:28.290 MdCoreSvc is supported in this platform and OS

2025-11-25T00:17:28.290 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-25-2025 00:17:28

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-25-2025 00:17:28

2025-11-25T00:17:28.293 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-25T00:17:28.293 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-25T00:17:28.293 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-25T00:17:28.293 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-25-2025 00:17:28

END TDT(U) telemetry



2025-11-25T00:17:28.295 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T00:17:28.295 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-25T00:17:28.295 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-25T00:17:28.295 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-25T00:17:28.295 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-25T00:17:28.296 MdCoreSvc is supported in this platform and OS

Signature updated on 11-25-2025 00:17:28

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.469.0

AV Signature Version: 1.441.469.0

************************************************************

2025-11-25T00:17:28.297 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-25T00:17:28.297 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\B40C8CAF-2592-459C-91A7-FD9F049B6A0E5a3c.1dc5da0ddb1c0e8

2025-11-25T00:17:28.308 Process scan (postsignatureupdatescan) started.

2025-11-25T00:17:28.346 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-25T00:17:28.347 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

Signature updated via MicrosoftUpdateServer on 11-25-2025 00:17:28

************************************************************

2025-11-25T00:17:28.376 Job Notification: Process exited from job (6228)

2025-11-25T00:17:28.377 Job Notification: Process exited from job (24068)

2025-11-25T00:17:28.413 Job Notification: Process exited from job (13612)

2025-11-25T00:17:28.414 Job Notification: Process exited from job (19644)

2025-11-25T00:17:28.488 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-25T00:17:28.488 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-25T00:17:28.488 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-25T00:17:28.488 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-25T00:17:28.488 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-25T00:17:28.492 [Engine] Engine 00007FFE4C3EA660 no longer in use. Number of active engines: 1

2025-11-25T00:17:28.492 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-25T00:17:28.492 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-25T00:17:28.654 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 4537, Count: 316, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\f5eb83e5-ef8c-4b53-865e-2bb796cee1f4.tmp, EstimatedImpact: 0%

2025-11-25T00:17:28.654 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3453, Count: 189, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\59549583-1586-49be-b596-5ee7bd24cbb5.tmp, EstimatedImpact: 0%

2025-11-25T00:17:28.654 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1811, Count: 186, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\ffprobe.exe, EstimatedImpact: 0%

2025-11-25T00:17:28.654 ProcessImageName: plugin-container.exe, Pid: 7304, TotalTime: 1498, Count: 8, MaxTime: 1390, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 100%

2025-11-25T00:17:28.654 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1456, Count: 81, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-25T00:17:28.654 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1396, Count: 201, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-25T00:17:28.654 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 691, Count: 124, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-25T00:17:28.654 ProcessImageName: RuntimeBroker.exe, Pid: 17368, TotalTime: 527, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 29%

2025-11-25T00:17:28.654 ProcessImageName: WmiPrvSE.exe, Pid: 17500, TotalTime: 431, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 89%

2025-11-25T00:17:28.654 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 378, Count: 30, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T00:17:28.654 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5324, TotalTime: 285, Count: 71, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-25T00:17:28.654 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 259, Count: 32, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-25T00:17:28.654 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 257, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-25T00:17:28.654 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 255, Count: 36, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-25T00:17:28.654 ProcessImageName: taskhostw.exe, Pid: 536, TotalTime: 210, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-25T00:17:28.654 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 197, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\42771547-dee5-45dd-809c-4ba064348be7.tmp, EstimatedImpact: 0%

2025-11-25T00:17:28.673 [Engine] RSIG_UNLOADENGINE, 00007FFE4C3EA660, err=0x0

2025-11-25T00:17:28.694 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{56965AF5-5A27-42E8-B323-A47C9909840D} removed

2025-11-25T00:17:28.787 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

IDynamicConfig::ReportChange value=MpFC_TS_UseStrictOriginQuery new=1 old0

IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpFC_TS_UseStrictOriginQuery new=0 old1

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-25T00:17:28.794 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-25T00:17:28.794 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-25T00:17:28.794 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-25T00:17:28.794 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-25T00:17:28.794 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-25T00:17:28.794 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-25T00:17:28.797 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-25T00:17:28.797 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-25T00:17:28.797 [RTP] Duplicating the current plugin configuration object...

2025-11-25T00:17:28.797 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-25T00:17:28.797 [RTP] Updating plugin configuration due to recent config changes (0x22) ...

2025-11-25T00:17:28.797 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-25T00:17:28.797 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-25T00:17:28.797 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-25T00:17:28.797 [RTP] No config change detected. Not updating plugin configuration.

2025-11-25T00:17:28.797 [RTP] No config changes found. No configuration switch.

2025-11-25T00:17:28.797 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x22, Changed: 0

2025-11-25T00:17:28.797 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-25T00:17:28.797 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-25T00:17:28.797 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-25T00:17:28.797 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-25T00:17:28.798 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-25T00:17:28.798 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-25T00:17:28.798 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-25T00:17:28.798 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-25T00:17:28.798 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-25T00:17:28.798 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-25T00:17:28.798 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-25T00:17:28.798 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-25T00:17:28.798 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-25T00:17:28.798 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-25T00:17:28.798 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T00:17:28.800 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T00:17:28.802 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T00:17:28.804 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T00:17:28.805 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T00:17:28.807 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 13292330(ms) from now at 04:59 (03:59 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-25T00:17:30.318 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-25T00:17:30.323 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-25T00:17:30.324 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-25T00:17:31.341 [RTP] Duplicating the current plugin configuration object...

2025-11-25T00:17:31.341 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-25T00:17:31.341 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-25T00:17:31.341 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-25T00:17:31.341 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-25T00:17:33.716 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-25T00:17:33.716 [Cloud] Start of cloud request. Passive mode: 0

2025-11-25T00:17:33.716 [Cloud] Queued cloud request.

2025-11-25T00:17:33.716 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-25T00:17:33.716 [Cloud] Dequeued cloud request.

2025-11-25T00:17:33.717 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-25T00:17:34.062 [Cloud] End of cloud request.

2025-11-25T00:17:34.580 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T00:17:42.855 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-25T00:17:42.856 Process scan (postsignatureupdatescan) completed.

2025-11-25T00:19:44.102 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #277485, FileId: 0x430000000009657, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T00:22:28.245 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-25T00:22:53.151 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T00:34:44.434 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #277663, FileId: 0x198000000002001, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T00:37:58.152 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T00:49:45.233 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #277909, FileId: 0x4900000000988c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T00:52:06.727 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #277929, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T00:52:06.730 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #277930, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T00:52:16.733 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #277935, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T00:52:16.738 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #277936, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T00:53:03.141 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T01:04:45.994 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #278197, FileId: 0xb9000000003cbb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T01:08:08.142 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T01:19:46.855 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #278615, FileId: 0x1e000000009d9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T01:23:13.142 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T01:34:47.481 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #278686, FileId: 0x1c000000009dc0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T01:38:18.128 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T01:39:45.250 [AutoPurge] Verification Routine tasks have started.

2025-11-25T01:39:45.250 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-25T01:39:45.257 [AutoPurge] Routine task for Cache Maintenance has started.

2025-11-25T01:39:45.258 [AutoPurge] Routine task for Cache Maintenance ...

2025-11-25T01:39:45.258 [AutoPurge] Routine task for MpSFCBuild ...

2025-11-25T01:39:45.258 [AutoPurge] MpCmIsBuildCompleted() - S_OK

2025-11-25T01:39:45.258 [AutoPurge] MpSignalMaintenanceMode ...

2025-11-25T01:39:45.259 [AutoPurge] Cleanup Routine tasks have started.

2025-11-25T01:39:45.263 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:B2C4A125-20F6-477A-B126-55C4744AFB78, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1)

2025-11-25T01:39:45.263 Scheduled scan with Id B2C4A125-20F6-477A-B126-55C4744AFB78 configured CPU priority: normal (LowCpuPriority: 0)

2025-11-25T01:39:45.263 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0)

2025-11-25T01:39:45.263 [AutoPurge] Purged 0 expired detection item(s) from a total of 0.

2025-11-25T01:39:45.264 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 3, expiration in 86400 seconds)

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:65538

Start time:11-25-2025 01:39:45

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-25-2025 01:39:45

2025-11-25T01:39:45.264 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build.

2025-11-25T01:39:45.264 [SFC] System file cache build is not needed (already completed)

2025-11-25T01:39:45.267 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ...

2025-11-25T01:39:45.267 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0 ...

2025-11-25T01:39:45.267 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0 ...

2025-11-25T01:39:45.267 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ...

2025-11-25T01:39:45.268 [AutoPurge] Cleanup Routine tasks have ended.

2025-11-25T01:39:45.308 EnsureProtectedFolderAcls(), hr = 0x0

2025-11-25T01:39:45.310 [AutoPurge] MpReinforceServiceAcls: 0

2025-11-25T01:39:45.320 Engine:Setting original file name "WIARPC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiarpc.dll.mui_0c913b87", hr=0x0

2025-11-25T01:39:45.320 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0

2025-11-25T01:39:45.324 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed.

2025-11-25T01:39:45.325 [AutoPurge] Verification Routine tasks have ended.

2025-11-25T01:39:45.345 Engine:Setting original file name "nlsbres.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..ocale-nls.resources_31bf3856ad364e35_10.0.26100.4484_nb-no_339b02f7f61c146e\winnlsres.dll.mui", hr=0x0

2025-11-25T01:39:45.598 Engine:Setting original file name "IEXPLORE.EXE" for "c:\program files (x86)\internet explorer\en-us\iexplore.exe.mui", hr=0x0

2025-11-25T01:39:45.627 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_en-us_1258b52c940aadb7_winload.efi.mui_35ee487d", hr=0x0

2025-11-25T01:39:45.850 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

2025-11-25T01:39:45.860 [DLP] DlpEngineConfigStorage::OnConfigChange DlpDwordSettingsMap:

2025-11-25T01:39:45.860 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-25T01:39:45.860 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-25T01:39:45.860 [RTP] Duplicating the current plugin configuration object...

2025-11-25T01:39:45.860 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-25T01:39:45.860 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-25T01:39:45.860 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-25T01:39:45.860 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-25T01:39:45.861 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-25T01:39:45.861 [RTP] No config change detected. Not updating plugin configuration.

2025-11-25T01:39:45.861 [RTP] No config changes found. No configuration switch.

2025-11-25T01:39:45.861 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-25T01:39:45.861 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-25T01:39:45.861 [RTP] [RtpConfig] Config change detected, type: 16

2025-11-25T01:39:45.861 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-25T01:39:45.861 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-25T01:39:45.861 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-25T01:39:45.861 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-25T01:39:45.861 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-25T01:39:45.861 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-25T01:39:45.861 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-25T01:39:45.861 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-25T01:39:45.861 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-25T01:39:45.861 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-25T01:39:45.862 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-25T01:39:45.862 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-25T01:39:45.862 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-25T01:39:45.862 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-25T01:39:45.862 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T01:39:45.864 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T01:39:45.866 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T01:39:45.867 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T01:39:45.869 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T01:39:45.869 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 10206916(ms) from now at 05:29 (04:29 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-25T01:39:46.085 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sr-..-rs_d1943ecc8317ab66_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-25T01:39:46.226 Engine:Setting original file name " " for "c:\program files (x86)\steam\bin\cef\cef.win7x64\dxcompiler.dll", hr=0x0

2025-11-25T01:39:46.272 Engine:Setting original file name "dual_engine_adapter.dll" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\dual_engine_adapter_x64.dll", hr=0x0

2025-11-25T01:39:46.410 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\winsxs\wow64_microsoft-windows-bcp47languages_31bf3856ad364e35_10.0.26100.7019_none_40ac55a9bb1ab239\bcp47langs.dll", hr=0x0

2025-11-25T01:39:46.423 Engine:Setting original file name "MAPI32.DLL.MUI" for "c:\windows\system32\nb-no\mapistub.dll.mui", hr=0x0

2025-11-25T01:39:46.577 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-25T01:39:46.613 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_ar-sa_af75f4ef024a79a1_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-25T01:39:46.679 Engine:Setting original file name "Apphelp" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a4bb088d5aa4193f97a4bdef0c1f8c71\apphelp.dll.mui", hr=0x0

2025-11-25T01:39:46.726 Engine:Setting original file name "F12Chooser.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-ie-iechooser.resources_31bf3856ad364e35_11.0.26100.1_nb-no_a7630c027f26ac69\iechooser.exe.mui", hr=0x0

2025-11-25T01:39:46.760 Engine:Setting original file name "THEMESERVICE.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-themeservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_5e5bf64d5b3ca824_themeservice.dll.mui_9e71f1ab", hr=0x0

2025-11-25T01:39:46.790 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_ad141a64b8fd6038_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:46.870 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\wow64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.26100.712_none_5cfec91758ee0662\windows.security.credentials.ui.credentialpicker.dll", hr=0x0

2025-11-25T01:39:46.922 Engine:Setting original file name "mavinject32.exe" for "c:\windows\winsxs\wow64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_592d553ad6e77100\mavinject.exe", hr=0x0

2025-11-25T01:39:47.050 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_bfcde09794ad7074_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-25T01:39:47.056 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\zh-cn\memtest.efi.mui", hr=0x0

2025-11-25T01:39:47.160 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_nb-no_022ea2e874b2cab6_winresume.efi.mui_f412814e", hr=0x0

2025-11-25T01:39:47.219 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lt-lt_11cd7cc1c62eb609_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:47.280 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-25T01:39:47.284 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-25T01:39:47.285 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-25T01:39:47.523 Engine:Setting original file name "WmiApSrv.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiapsrv.exe.mui_b1567840", hr=0x0

2025-11-25T01:39:47.576 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kk-kz_bb9a512b689c9b87_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:47.602 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_b5793645604cae79_memtest.efi.mui_71e15c22", hr=0x0

2025-11-25T01:39:47.618 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_he-il_3abd6f82e93c03e5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:47.625 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.26100.1_en-us_c3d82ef5c0380efa_wudfpf.sys.mui_f61e9e86", hr=0x0

2025-11-25T01:39:47.875 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaihdrx.dll", hr=0x0

2025-11-25T01:39:48.016 Engine:Setting original file name "l3codec.acm.mui" for "c:\windows\system32\nb-no\l3codeca.acm.mui", hr=0x0

2025-11-25T01:39:48.127 Engine:Setting original file name "w32topl.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_10.0.26100.1_none_cbd0eec659c2eb5c_w32topl.dll_1a0f388b", hr=0x0

2025-11-25T01:39:48.142 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ms-my_6f80e6fda2cebe8f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:48.386 [RTP] Duplicating the current plugin configuration object...

2025-11-25T01:39:48.386 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-25T01:39:48.386 [RTP] Updating plugin configuration due to recent config changes (0x41e) ...

2025-11-25T01:39:48.386 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-25T01:39:48.386 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x218

2025-11-25T01:39:48.415 Engine:Setting original file name "NVPTXJITCOMPILER32.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvptxjitcompiler64.dll", hr=0x0

2025-11-25T01:39:48.454 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5de87d4a39ffc584310f0b06dff9fcd0\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-25T01:39:48.529 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_38f499759ea365c4_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:48.582 Engine:Setting original file name "ddputils.lib.mui" for "c:\windows\system32\nb-no\ddputils.dll.mui", hr=0x0

2025-11-25T01:39:48.693 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kn-in_6e7a81f857a45cbe_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:48.723 Engine:Setting original file name "officeimm.odf" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\office.odf", hr=0x0

2025-11-25T01:39:48.920 Engine:Setting original file name ""AcGenral.dll"" for "c:\windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_10.0.26100.7019_none_a8119654a230db44\acgenral.dll", hr=0x0

2025-11-25T01:39:48.999 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sr-..-rs_7327597d7718c882_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:49.013 Engine:Setting original file name "Hyper-V Host Compute Service Diagnostics Tool" for "c:\windows\winsxs\amd64_hyperv-compute-cont..sticstool.resources_31bf3856ad364e35_10.0.26100.1_en-us_61074b8c7d2f38cf\hcsdiag.exe.mui", hr=0x0

2025-11-25T01:39:49.030 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.32530.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-25T01:39:49.069 Engine:Setting original file name "davsvc.dll.mui" for "c:\windows\system32\nb-no\webclnt.dll.mui", hr=0x0

2025-11-25T01:39:49.099 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\nb-no\wsepno.dll.mui", hr=0x0

2025-11-25T01:39:49.111 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x0

2025-11-25T01:39:49.148 Engine:Setting original file name "bootstr.exe.mui" for "c:\windows\system32\nb-no\bootstr.dll.mui", hr=0x0

2025-11-25T01:39:49.164 Engine:Setting original file name "msvcp140_2_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_2_app.dll", hr=0x0

2025-11-25T01:39:49.392 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-libraryloader-l1-1-0.dll", hr=0x0

2025-11-25T01:39:49.398 Engine:Setting original file name "dvsvc.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..rationsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_5c873aff49ea76e6\dcsvc.dll.mui", hr=0x0

2025-11-25T01:39:49.427 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_qps-ploc_5c9773f9ea1ce396_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:49.430 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_cs-cz_7086b4650c9e547c_memtest.efi.mui_71e15c22", hr=0x0

2025-11-25T01:39:49.525 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa78d0db4729269ff4beb393d45ca94a\dnsapi.dll.mui", hr=0x0

2025-11-25T01:39:49.540 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hr-hr_86baa9ad7eed6d52_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:49.582 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ja-jp_ed01f249e53f7235_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-25T01:39:49.585 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-file-l1-1-0.dll", hr=0x0

2025-11-25T01:39:49.611 Engine:Setting original file name "D3DX10.dll" for "c:\windows\system32\d3dx10_43.dll", hr=0x0

2025-11-25T01:39:49.686 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_da-dk_f5abc0a0339bc397_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:49.781 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-conio-l1-1-0.dll", hr=0x0

2025-11-25T01:39:49.897 Engine:Setting original file name "Auto Enrollment DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..utoenroll.resources_31bf3856ad364e35_10.0.26100.1_en-us_b82b35a9c2228d6b\pautoenr.dll.mui", hr=0x0

2025-11-25T01:39:49.983 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\windows\winsxs\amd64_microsoft-textinput-helpers.resources_31bf3856ad364e35_10.0.26100.1_nb-no_2c9a52bac4b766e3\ime_textinputhelpers.dll.mui", hr=0x0

2025-11-25T01:39:49.997 Engine:Setting original file name "Ribbons" for "c:\windows\winsxs\amd64_microsoft-windows-ribbons.resources_31bf3856ad364e35_10.0.26100.1_en-us_f85e1124efc279b5\ribbons.scr.mui", hr=0x0

2025-11-25T01:39:50.040 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_18153ede37451276\memtest.exe.mui", hr=0x0

2025-11-25T01:39:50.089 Engine:Setting original file name "scecli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\978b70ff94ed14c641fe52c5237facec\scecli.dll.mui", hr=0x0

2025-11-25T01:39:50.109 Engine:Setting original file name "mpsdrv.sys.mui" for "c:\windows\winsxs\backup\amd64_networking-mpssvc-drv.resources_31bf3856ad364e35_10.0.26100.1_nb-no_05849dc2762f9d2d_mpsdrv.sys.mui_b2aea3b6", hr=0x0

2025-11-25T01:39:50.128 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-tw_21b451d70c8c2957_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-25T01:39:50.296 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_2b309b875a6f3e1e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:50.364 Engine:Setting original file name "Vulkan Runtime" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\vulkan-1.dll", hr=0x0

2025-11-25T01:39:50.406 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-p..i-ntprint.resources_31bf3856ad364e35_10.0.26100.1_en-us_6ff199c21e8ad886\ntprint.dll.mui", hr=0x0

2025-11-25T01:39:50.469 Engine:Setting original file name "bootstr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..environment-strings_31bf3856ad364e35_10.0.26100.1_none_f575b80d757af501\bootstr.dll", hr=0x0

2025-11-25T01:39:50.497 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_zh-cn_fd81e6b68df3d1a9_comctl32.dll.mui_0da4e682", hr=0x0

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=true, source=0, resourceid=0x36d4ed77

2025-11-25T01:39:50.677 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-25T01:39:50.765 Engine:Setting original file name "liblzma.dll" for "c:\program files\windowsapps\microsoft.6365217ce6eb4_102.2509.19002.0_x64__8wekyb3d8bbwe\lzma.dll", hr=0x0

2025-11-25T01:39:50.864 Engine:Setting original file name "wuapi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\uus\x86\nb-no\c120e79170c204b0e5f1ece795e86e83\wuapicore.dll.mui", hr=0x0

2025-11-25T01:39:50.930 Engine:Setting original file name "Ontology.dll" for "c:\users\serverpc\appdata\local\nvidia corporation\nvidia app\nvbackend\applicationontology\ontology64.dll", hr=0x0

2025-11-25T01:39:51.074 Engine:Setting original file name "VpnSohDesktop.dll" for "c:\windows\system32\windows.perception.stub.dll", hr=0x0

2025-11-25T01:39:51.155 Engine:Setting original file name "kernel32" for "c:\windows\syswow64\kernel32.dll", hr=0x0

2025-11-25T01:39:51.182 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.549981c3f5f10_4.2308.1005.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-25T01:39:51.374 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_b38289243d899c4c_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:51.444 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_82eb3d34cd19fa50_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:51.589 Engine:Setting original file name "Steamclient.dll" for "c:\program files (x86)\steam\steamclient64.dll", hr=0x0

2025-11-25T01:39:51.658 Engine:Setting original file name "VrdUmde.dll" for "c:\windows\winsxs\amd64_gpuvirtualizationumed_31bf3856ad364e35_10.0.26100.1150_none_17421023ba072774\vrdumed.dll", hr=0x0

2025-11-25T01:39:51.671 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.efi.mui", hr=0x0

2025-11-25T01:39:51.810 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.winmd", hr=0x0

2025-11-25T01:39:52.160 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_lt-lt_ba1ae95b692b9594_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-25T01:39:52.268 Engine:Setting original file name "windows.ui.xaml.resources.win81.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ctui-resourceswin81_31bf3856ad364e35_10.0.26100.1301_none_b7b52abe3d381205_windows.ui.xaml.resources.win81.dll_d426e245", hr=0x0

2025-11-25T01:39:52.403 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-timezone-l1-1-0.dll", hr=0x0

2025-11-25T01:39:52.446 Engine:Setting original file name "jscript9.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\c3275836e276aea69afa458336037853\jscript9legacy.dll.mui", hr=0x0

2025-11-25T01:39:52.769 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x0

2025-11-25T01:39:52.823 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-profile-l1-1-0.dll", hr=0x0

2025-11-25T01:39:53.060 Engine:Setting original file name "Windows.FileExplorer.Common.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\84c8a2171c12d91e854ffb6a27b39453\windows.fileexplorer.common.dll.mui", hr=0x0

2025-11-25T01:39:53.268 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.26100.1_en-us_99a73e6649d69102\ndisimplatcim.dll.mui", hr=0x0

2025-11-25T01:39:53.316 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-25T01:39:53.388 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-localization-l1-2-0.dll", hr=0x0

2025-11-25T01:39:53.448 Engine:Setting original file name "Placeholder.dll" for "c:\windows\winsxs\x86_netfx4-penimc_v0400_b03f5f7f11d50a3a_4.0.15920.102_none_21046749883d249b\penimc_v0400.dll", hr=0x0

2025-11-25T01:39:53.473 Engine:Setting original file name "NvCamera.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\nvcameraallowlisting32.dll", hr=0x0

Internal signature match:subtype=Lowfi, sigseq=0x0000157EBAD029E3, sigsha=a80b7cfbca5c0e7f9fba5768d931c4e463118bd7, cached=false, source=0, resourceid=0xa0580f5b

Internal signature match:subtype=Lowfi, sigseq=0x0000157E6A855602, sigsha=0994c4a442027631466fa0fa9a785e5f4c9a4e22, cached=false, source=0, resourceid=0xa0580f5b

Internal signature match:subtype=Lowfi, sigseq=0x0000157E79D31496, sigsha=ea85fbc31c099b374f0738a1e88ece004ab148bb, cached=false, source=0, resourceid=0xa0580f5b

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=0, resourceid=0xa0580f5b

Internal signature match:subtype=Lowfi, sigseq=0x0000157E3741FAAC, sigsha=a00e9ed2e65840846a4e1debb10f38e5c808e92f, cached=false, source=0, resourceid=0xa0580f5b

2025-11-25T01:39:53.542 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-25T01:39:53.542 [Cloud] Start of cloud request. Passive mode: 0

2025-11-25T01:39:53.542 [Cloud] Queued cloud request.

2025-11-25T01:39:53.542 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-25T01:39:53.543 [Cloud] Dequeued cloud request.

2025-11-25T01:39:53.543 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-25T01:39:53.727 Engine:Setting original file name ".NET Host Policy -" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\hostpolicy.dll", hr=0x0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b30570a0bd07ef299df5e873ae4331a910955ee8

Dynamic Signature Compilation Timestamp:11-25-2025 01:39:53

Persistence Type:Duration

Time remaining:864000000

2025-11-25T01:39:53.759 Dynamic signature received

2025-11-25T01:39:53.759 [Cloud] End of cloud request.

2025-11-25T01:39:53.759 RTSD:RTSD recieved, rescanning impacted resources

2025-11-25T01:39:54.139 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sv-se_cac4b549037c269f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:54.143 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-25T01:39:54.176 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-25T01:39:54.194 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\winsxs\amd64_microsoft-windows-appx-deployment-server_31bf3856ad364e35_10.0.26100.7171_none_fd3893d466902045\applytrustoffline.exe", hr=0x0

2025-11-25T01:39:54.281 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T01:39:54.337 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\wow64_microsoft-windows-a..on-logger.resources_31bf3856ad364e35_10.0.26100.1_en-us_a0e09b8ec526451d\aeevts.dll.mui", hr=0x0

2025-11-25T01:39:54.430 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-25T01:39:54.617 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\4f8d3bb436c7\apex_particleschecked_x86.dll", hr=0x0

2025-11-25T01:39:54.695 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_it-it_72537c4985790e22_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:54.830 Engine:Setting original file name "EsclWiaDriver.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_esclwiadriver.dll.mui_d4a5b959", hr=0x0

2025-11-25T01:39:54.952 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_da-dk_be356ba870c91e76\msprivs.dll.mui", hr=0x0

2025-11-25T01:39:54.954 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-25T01:39:54.967 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_es-es_bdfd06f72820647a_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-25T01:39:55.085 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pl-pl\msprivs.dll.mui", hr=0x0

2025-11-25T01:39:55.103 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-25T01:39:55.125 Engine:Setting original file name "rmactivate.exe.mui" for "c:\windows\syswow64\en-us\rmactivate_isv.exe.mui", hr=0x0

2025-11-25T01:39:55.362 Engine:Setting original file name "apex.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\73be2921551d\apex_turbulencefschecked_x86.dll", hr=0x0

2025-11-25T01:39:55.389 Engine:Setting original file name "ScrCons" for "c:\windows\winsxs\amd64_microsoft-windows-w..consumers.resources_31bf3856ad364e35_10.0.26100.1_en-us_5d0e2df387a86d5d\scrcons.exe.mui", hr=0x0

2025-11-25T01:39:55.396 Engine:Setting original file name "PtpProv" for "c:\windows\winsxs\amd64_microsoft-windows-t..-provider.resources_31bf3856ad364e35_10.0.26100.1_en-us_eec70481b215edf0\ptpprov.dll.mui", hr=0x0

2025-11-25T01:39:55.439 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\resources\themes\aero\nb-no\aerolite.msstyles.mui", hr=0x0

2025-11-25T01:39:55.615 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_cd255b4d1be69fe9_winload.efi.mui_35ee487d", hr=0x0

2025-11-25T01:39:55.648 Engine:Setting original file name "pegi.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_en-us_58f534214187451c\pegi.rs.mui", hr=0x0

2025-11-25T01:39:55.653 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-iexpress.resources_31bf3856ad364e35_11.0.26100.1_en-us_f84c0d683fdc407b\wextract.exe.mui", hr=0x0

2025-11-25T01:39:56.132 Engine:Setting original file name "updater.exe" for "c:\program files (x86)\google\update\googleupdate.exe", hr=0x0

2025-11-25T01:39:56.288 Engine:Setting original file name "ServicingBase.dll" for "c:\windows\system32\servicingcommon.dll", hr=0x0

2025-11-25T01:39:56.316 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.exe.mui", hr=0x0

2025-11-25T01:39:56.504 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\vulkan-1.dll", hr=0x0

2025-11-25T01:39:56.554 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_c77eb7b609c47f12\diagpackage.dll.mui", hr=0x0

2025-11-25T01:39:56.674 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\system32\wbem\en-us\netadaptercim.dll.mui", hr=0x0

2025-11-25T01:39:56.700 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\syswow64\nb-no\wextract.exe.mui", hr=0x0

2025-11-25T01:39:56.816 Engine:Setting original file name "NvTelemetry.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvinstallerutil.dll", hr=0x0

2025-11-25T01:39:56.863 Engine:Setting original file name "NvMessageBusBroadcast.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\localsystem\_nvmsgbusbroadcast.dll", hr=0x0

2025-11-25T01:39:57.075 Engine:Setting original file name "NVOPENCL.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvopencl64.dll", hr=0x0

2025-11-25T01:39:57.083 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x0

2025-11-25T01:39:57.158 Engine:Setting original file name "Ribbons" for "c:\windows\system32\nb-no\ribbons.scr.mui", hr=0x0

2025-11-25T01:39:57.318 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_de-de_bb6100e4729f7310\msprivs.dll.mui", hr=0x0

2025-11-25T01:39:57.485 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_en-gb_943f70b729277031_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:57.515 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570\dnsapi.dll.mui", hr=0x0

2025-11-25T01:39:57.518 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x0

2025-11-25T01:39:57.608 Engine:Setting original file name "expediteupdater" for "c:\program files\microsoft update health tools\expediteupdater.exe", hr=0x0

2025-11-25T01:39:57.657 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5fc58c6fab06ca1651cc2f24f6b3294e\dnsapi.dll.mui", hr=0x0

2025-11-25T01:39:57.772 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-25T01:39:57.811 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-25T01:39:57.883 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pt-br\msprivs.dll.mui", hr=0x0

2025-11-25T01:39:57.941 Engine:Setting original file name "vcomp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-25T01:39:57.990 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_pt-br_45b1cef334010120_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-25T01:39:58.037 Engine:Setting original file name "DismProvPS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..ing-management-core_31bf3856ad364e35_10.0.26100.7019_none_c721839bdaa557fd\dismcoreps.dll", hr=0x0

2025-11-25T01:39:58.153 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x0

2025-11-25T01:39:58.187 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.efi", hr=0x0

2025-11-25T01:39:58.191 Engine:Setting original file name "ProfSvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-profsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_63afbc426d007f3f_profsvc.dll.mui_32482e9e", hr=0x0

2025-11-25T01:39:58.298 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2cfe4c864d785675f415b7e6aa962e4\msinfo32.exe.mui", hr=0x0

2025-11-25T01:39:58.511 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\6dfad87d7e49db84e1a96c1c1b32fef6\msidntld.dll.mui", hr=0x0

2025-11-25T01:39:58.526 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7\memtest.exe.mui", hr=0x0

2025-11-25T01:39:58.631 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pa-in_9c6b14ad918eaffd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:58.651 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ar-sa_51090f9ff64b96bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:58.698 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.26100.1_en-us_c94c280205b42295\bubbles.scr.mui", hr=0x0

2025-11-25T01:39:58.935 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\nb-no\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x0

2025-11-25T01:39:58.958 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-console-l1-2-0.dll", hr=0x0

2025-11-25T01:39:58.973 Engine:Setting original file name "SETUP.EXE.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-wow64-legacy.resources_31bf3856ad364e35_10.0.26100.1_nb-no_735ab890ce560efa\setup16.exe.mui", hr=0x0

2025-11-25T01:39:59.127 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x0

2025-11-25T01:39:59.161 Engine:Setting original file name "RarExt.dll" for "c:\program files\winrar\rarext32.dll", hr=0x0

2025-11-25T01:39:59.202 Engine:Setting original file name "pcw.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-pcw_31bf3856ad364e35_10.0.26100.1150_none_4bf8e6d5066a4f9f_pcw.sys_dbeb0bbd", hr=0x0

2025-11-25T01:39:59.295 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\syswow64\nb-no\ieadvpack.dll.mui", hr=0x0

2025-11-25T01:39:59.327 Engine:Setting original file name "EmbyServer.dll" for "c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe", hr=0x0

2025-11-25T01:39:59.439 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-environment-l1-1-0.dll", hr=0x0

2025-11-25T01:39:59.584 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2535f07be6867822893c0bd7f299affd\dwmcore.dll.mui", hr=0x0

2025-11-25T01:39:59.598 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_am-et_12002fbedc3ad139_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:39:59.639 Engine:Setting original file name "mavinject64.exe" for "c:\windows\winsxs\amd64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_4ed8aae8a286af05\mavinject.exe", hr=0x0

2025-11-25T01:39:59.800 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_b1cb38b404e84204\seclogon.dll.mui", hr=0x0

2025-11-25T01:39:59.842 Engine:Setting original file name "AuditPolicyGP.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\1e37baae98dce76981781b53776e70b9\auditpolicygpinterop.dll.mui", hr=0x0

2025-11-25T01:39:59.922 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9c4e95300400790b8d8a05d9bf7e1f5c\winnlsres.dll.mui", hr=0x0

2025-11-25T01:39:59.935 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e981bfd75ae177a858ec5c78a5cfda25\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-25T01:39:59.992 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-25T01:40:00.189 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ru-ru_e71c93fcf7d6f33e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:00.242 Engine:Setting original file name "qualityupdateassistant" for "c:\windows\system32\qualityupdateassistant.dll", hr=0x0

2025-11-25T01:40:00.253 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ro-ro_2c617f480dd85974_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:00.382 Engine:Setting original file name "wersvc" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2f884580919ab799dbe1ecd0f275799\wersvc.dll.mui", hr=0x0

2025-11-25T01:40:00.470 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_fa-ir_f7555235024374d9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:00.502 Engine:Setting original file name "ClrCompression" for "c:\program files\windowsapps\microsoft.net.native.runtime.1.7_1.7.25531.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-25T01:40:00.538 Engine:Setting original file name "WIASERVC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiaservc.dll.mui_54051b53", hr=0x0

2025-11-25T01:40:00.540 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-25T01:40:00.575 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ru-ru_0752c1c778fe6e7c_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-25T01:40:00.683 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-25T01:40:01.081 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_id-id_6be80829898706a2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:01.087 Engine:Setting original file name "STI.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_en-us_d64b3cbf22b2a8d1_sti.dll.mui_00a4f15b", hr=0x0

2025-11-25T01:40:01.094 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9035fe481934c33719e75dea902d1698\bcastdvruserservice.dll.mui", hr=0x0

2025-11-25T01:40:01.127 Engine:Setting original file name "NVIDIA Debug Dump" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvdebugdump.exe", hr=0x0

2025-11-25T01:40:01.145 Engine:Setting original file name "acpiex.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-acpiex_31bf3856ad364e35_10.0.26100.1150_none_d0b1f61a88e2f0e9_acpiex.sys_6a8b9aed", hr=0x0

2025-11-25T01:40:01.164 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_60b47cf61af27adc_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-25T01:40:01.181 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x0

2025-11-25T01:40:01.378 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sv-se_29319a980f7b0983_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-25T01:40:01.481 Engine:Setting original file name "pshed.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-pshed_31bf3856ad364e35_10.0.26100.1_none_633b3602ca01eb94_pshed.dll_f6ac239e", hr=0x0

2025-11-25T01:40:01.571 Engine:Setting original file name "ClipSVC.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-client-li..m-service.resources_31bf3856ad364e35_10.0.26100.1_en-us_3f436cbd520195fd_clipsvc.dll.mui_18823613", hr=0x0

2025-11-25T01:40:01.595 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_cy-gb_976c80cbdb5c65c1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:01.811 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_uk-ua_c5d15aec526b5235_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:01.880 Engine:Setting original file name "msfltr32.acm" for "c:\windows\winsxs\wow64_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_10.0.26100.1_none_e82ddbd17df6cb5b\msacm32.dll", hr=0x0

2025-11-25T01:40:01.935 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-25T01:40:01.950 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-25T01:40:02.004 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_6dcfa7c5391fe7a2_dnsapi.dll.mui_97465f8a", hr=0x0

2025-11-25T01:40:02.141 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_3cda2262e7ef70ab_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:02.249 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_10.0.26100.7171_none_f70fffd91c8f0404\winload.exe", hr=0x0

2025-11-25T01:40:02.415 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_et-ee_9786a4bcaafec5cb_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:02.691 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files\mozilla firefox\dxcompiler.dll", hr=0x0

2025-11-25T01:40:02.756 Engine:Setting original file name "Device_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\device\nb-no\edb83efa185c0a23d97fafe6a71cd608\diagpackage.dll.mui", hr=0x0

2025-11-25T01:40:02.776 Engine:Setting original file name "rtutils.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasrtutils_31bf3856ad364e35_10.0.26100.3037_none_a90518339a5ed736_rtutils.dll_243724ab", hr=0x0

2025-11-25T01:40:02.893 Engine:Setting original file name "udiapi.dll" for "c:\windows\system32\udiapiclient.dll", hr=0x0

2025-11-25T01:40:02.914 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-25T01:40:02.975 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaidvc.dll", hr=0x0

2025-11-25T01:40:02.981 Engine:Setting original file name "DWrite" for "c:\windows\winsxs\amd64_microsoft-windows-directwrite.resources_31bf3856ad364e35_10.0.26100.1_en-us_8e75f00536c95f8c\dwrite.dll.mui", hr=0x0

2025-11-25T01:40:02.989 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\windows\syswow64\nb-no\mfc40u.dll.mui", hr=0x0

2025-11-25T01:40:03.102 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.26100.1_en-us_12a038f1fa40c367_wlrmdr.exe.mui_ee563c83", hr=0x0

2025-11-25T01:40:03.196 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.xaml.winmd", hr=0x0

2025-11-25T01:40:03.275 Engine:Setting original file name "raspptp.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasbase-raspptp_31bf3856ad364e35_10.0.26100.1882_none_358d932997f7087d_raspptp.sys_25e89db1", hr=0x0

2025-11-25T01:40:03.368 Engine:Setting original file name "l3codec.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\17e7113a56f3171dc40844c9d3ee9e47\l3codeca.acm.mui", hr=0x0

2025-11-25T01:40:03.399 Engine:Setting original file name "bridgeres.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-networkbridge_31bf3856ad364e35_10.0.26100.2454_none_a3b07853b6183928_bridgeres.dll_55e40455", hr=0x0

2025-11-25T01:40:03.639 Engine:Setting original file name "mf.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..oundation.resources_31bf3856ad364e35_10.0.26100.1_en-us_8b9cc1ab2476fea1\mfpmp.exe.mui", hr=0x0

2025-11-25T01:40:03.738 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-processthreads-l1-1-1.dll", hr=0x0

2025-11-25T01:40:03.804 Engine:Setting original file name "FreeImage.dll" for "c:\program files (x86)\steam\steamapps\common\wallpaper_engine\bin\freeimage64.dll", hr=0x0

2025-11-25T01:40:03.808 Engine:Setting original file name "tier0_s.dll" for "c:\program files (x86)\steam\tier0_s64.dll", hr=0x0

2025-11-25T01:40:03.825 Engine:Setting original file name "nvaudcap.dll" for "c:\windows\syswow64\nvaudcap32v.dll", hr=0x0

2025-11-25T01:40:03.865 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mi-nz_b80bad72b6b0ee53_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:03.893 Engine:Setting original file name "CertCli" for "c:\windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_10.0.26100.1_en-us_61b2ff4b086153b8\certcli.dll.mui", hr=0x0

2025-11-25T01:40:03.898 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\en-us\wsepno.dll.mui", hr=0x0

2025-11-25T01:40:03.920 Engine:Setting original file name "ConfigurationRemotingServer.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\configurationremotingserver.exe", hr=0x0

2025-11-25T01:40:03.934 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_sr-..-rs_e67ffd847af5d250_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:03.937 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\power\en-us\diagpackage.dll.mui", hr=0x0

2025-11-25T01:40:03.961 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay8-payload_31bf3856ad364e35_1.0.26100.4202_none_bb7ce817a226517c\dpnaddr.dll", hr=0x0

2025-11-25T01:40:04.215 Engine:Setting original file name "msfltr32.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8836c193640d589410b5cc3dbe67e146\msacm32.dll.mui", hr=0x0

2025-11-25T01:40:04.323 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_6a24110114ad15ad_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-25T01:40:04.348 Engine:Setting original file name "usk.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\7c8e526d244ad657f882f8bbba0149ec\usk.rs.mui", hr=0x0

2025-11-25T01:40:04.360 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-25T01:40:04.382 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay4-payload_31bf3856ad364e35_1.0.26100.4202_none_186a372066698d60\dpmodemx.dll", hr=0x0

2025-11-25T01:40:04.574 Engine:Setting original file name "Register-CimProvider2.exe.mui" for "c:\windows\syswow64\en-us\register-cimprovider.exe.mui", hr=0x0

2025-11-25T01:40:04.676 Engine:Setting original file name "metabase.dll.mui" for "c:\windows\winsxs\wow64_microsoft-windows-iis-metabase.resources_31bf3856ad364e35_10.0.26100.1_en-us_8ff50fedc8451a7b\metadata.dll.mui", hr=0x0

2025-11-25T01:40:04.681 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x0

2025-11-25T01:40:04.764 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_de-de_ab2a1f0520f5ef2b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:04.833 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_6fced6fbf4c0e3e0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:05.086 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\en-us\diagpackage.dll.mui", hr=0x0

2025-11-25T01:40:05.107 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_7478bb53490dd7a8_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-25T01:40:05.159 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\windows\system32\nb-no\msidntld.dll.mui", hr=0x0

2025-11-25T01:40:05.164 Engine:Setting original file name "glu32" for "c:\windows\winsxs\amd64_microsoft-windows-opengl.resources_31bf3856ad364e35_10.0.26100.1_en-us_9c3b296d3d668ac3\glu32.dll.mui", hr=0x0

2025-11-25T01:40:05.186 Engine:Setting original file name "mf.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mediafoundation_31bf3856ad364e35_10.0.26100.7171_none_384874e2bca9ce3f\mfpmp.exe", hr=0x0

2025-11-25T01:40:05.223 Engine:Setting original file name "scesrv" for "c:\windows\system32\nb-no\scesrv.dll.mui", hr=0x0

2025-11-25T01:40:05.237 Engine:Setting original file name "DWWIN" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ae2b7dc24859d1fa2a509d5b642451b4\dwwin.exe.mui", hr=0x0

2025-11-25T01:40:05.379 Engine:Setting original file name "nvcuvid.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcuvid64.dll", hr=0x0

2025-11-25T01:40:05.415 Engine:Setting original file name "AppHostNameRegistrationVerifier.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\baf91a75f57ca8730dd9a6f926a58dd0\apphostregistrationverifier.exe.mui", hr=0x0

2025-11-25T01:40:05.425 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_en-gb_9672c12aaba943d2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:05.535 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-rtlsupport-l1-1-0.dll", hr=0x0

2025-11-25T01:40:05.556 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-25T01:40:05.585 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_gu-in_97d53b15f69aaeca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:05.647 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_84875939fc6b99b1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:05.673 Engine:Setting original file name "ServDeps.exe.mui" for "c:\windows\syswow64\wbem\nb-no\servdeps.dll.mui", hr=0x0

2025-11-25T01:40:05.705 Engine:Setting original file name "schtasks.exe" for "c:\windows\winsxs\amd64_microsoft-windows-sctasks_31bf3856ad364e35_10.0.26100.6725_none_25e27f3a6574108c\schtasks.exe", hr=0x0

2025-11-25T01:40:05.718 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_e38364b045f31518_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:05.769 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_el-gr_b382575af3d00da3_memtest.efi.mui_71e15c22", hr=0x0

2025-11-25T01:40:05.933 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.26100.1_en-us_0e875971ea5fda56\ieadvpack.dll.mui", hr=0x0

2025-11-25T01:40:05.974 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-datetime-l1-1-0.dll", hr=0x0

2025-11-25T01:40:05.998 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-25T01:40:06.037 Engine:Setting original file name "user32" for "c:\windows\system32\user32.dll", hr=0x0

2025-11-25T01:40:06.111 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.642.119.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-25T01:40:06.123 Engine:Setting original file name "shutdownui" for "c:\windows\winsxs\amd64_microsoft-windows-shutdownext.resources_31bf3856ad364e35_10.0.26100.1_en-us_9bd0f22e3578c871\shutdownext.dll.mui", hr=0x0

2025-11-25T01:40:06.281 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4\memtest.exe.mui", hr=0x0

2025-11-25T01:40:06.323 Engine:Setting original file name ".NET Host Resolver - 8.0.20" for "c:\users\serverpc\appdata\local\temp\emby-server-updater\hostfxr.dll", hr=0x0

2025-11-25T01:40:06.346 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_bs-..-ba_3017f7e2648d7e73_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:06.429 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_quz-pe_0266e81632046792_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:06.536 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lb-lu_cb546bb0b0d79a98_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:06.570 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\amd64_microsoft-windows-a..perience-ait-static_31bf3856ad364e35_10.0.26100.7019_none_ccd1f49f5e2b3b28\aitstatic.exe", hr=0x0

2025-11-25T01:40:06.665 Engine:Setting original file name "UNPShared.dll" for "c:\windows\winsxs\amd64_microsoft-windows-update-upshared_31bf3856ad364e35_10.0.26100.5074_none_29764f36135e6d4c\upshared.dll", hr=0x0

2025-11-25T01:40:06.743 Engine:Setting original file name "messagin.dll" for "c:\program files\bitdefender agent\27.1.1.23\messaging.dll", hr=0x0

2025-11-25T01:40:06.813 Engine:Setting original file name "WindowsCodecs" for "c:\windows\syswow64\windowscodecs.dll", hr=0x0

2025-11-25T01:40:06.850 Engine:Setting original file name "WerMgr" for "c:\windows\system32\wermgr.exe", hr=0x0

2025-11-25T01:40:06.897 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d\memtest.exe.mui", hr=0x0

2025-11-25T01:40:06.900 Engine:Setting original file name "imapi.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bd7c223153b9576fe4c4e66ebf1c6ece\imapi.dll.mui", hr=0x0

2025-11-25T01:40:07.032 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hi-in_8555c5797fc8795e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:07.105 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\esrb.rs.mui", hr=0x0

2025-11-25T01:40:07.118 Engine:Triggered AR EMS scan


2025-11-25T01:40:07.121 Engine:EMS scan for process: svchost pid: 1268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.133 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.136 Engine:EMS scan for process: svchost pid: 1444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.139 Engine:EMS scan for process: svchost pid: 1624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.140 Engine:EMS scan for process: svchost pid: 1652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.146 Engine:EMS scan for process: svchost pid: 1784, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.149 Engine:EMS scan for process: svchost pid: 1792, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.151 Engine:EMS scan for process: svchost pid: 1800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.153 Engine:EMS scan for process: svchost pid: 1924, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.154 Engine:EMS scan for process: svchost pid: 1932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.157 Engine:EMS scan for process: svchost pid: 1940, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.160 Engine:EMS scan for process: svchost pid: 1948, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.162 Engine:EMS scan for process: svchost pid: 1208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.163 Engine:EMS scan for process: svchost pid: 1496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.165 Engine:EMS scan for process: svchost pid: 1812, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.167 Engine:EMS scan for process: svchost pid: 2084, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.168 Engine:EMS scan for process: svchost pid: 2220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.171 Engine:EMS scan for process: svchost pid: 2448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.174 Engine:EMS scan for process: svchost pid: 2500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.176 Engine:EMS scan for process: svchost pid: 2696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.178 Engine:EMS scan for process: svchost pid: 2908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.180 Engine:EMS scan for process: svchost pid: 2976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.183 Engine:EMS scan for process: svchost pid: 3000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.185 Engine:EMS scan for process: svchost pid: 3016, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.187 Engine:EMS scan for process: svchost pid: 3052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.188 Engine:EMS scan for process: svchost pid: 3060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.190 Engine:EMS scan for process: svchost pid: 3068, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.191 Engine:EMS scan for process: svchost pid: 2276, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.193 Engine:EMS scan for process: svchost pid: 3244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.194 Engine:EMS scan for process: svchost pid: 3288, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.195 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-25T01:40:07.197 Engine:EMS scan for process: svchost pid: 3296, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.199 Engine:EMS scan for process: svchost pid: 3380, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.203 Engine:EMS scan for process: svchost pid: 3412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.204 Engine:EMS scan for process: svchost pid: 3556, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.208 Engine:EMS scan for process: svchost pid: 3696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.210 Engine:EMS scan for process: svchost pid: 3704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.211 Engine:EMS scan for process: svchost pid: 3808, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.213 Engine:EMS scan for process: svchost pid: 3868, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.215 Engine:EMS scan for process: svchost pid: 3932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.218 Engine:EMS scan for process: svchost pid: 3168, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.220 Engine:EMS scan for process: svchost pid: 8, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.220 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_zh-tw_ff4ad39908e2da78_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:07.222 Engine:EMS scan for process: svchost pid: 4196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.223 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-25T01:40:07.224 Engine:EMS scan for process: svchost pid: 4244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.225 Engine:EMS scan for process: svchost pid: 4304, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.230 Engine:EMS scan for process: svchost pid: 4352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.235 Engine:EMS scan for process: svchost pid: 4400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.237 Engine:EMS scan for process: svchost pid: 4724, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.244 Engine:EMS scan for process: svchost pid: 4732, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.249 Engine:EMS scan for process: svchost pid: 4748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.250 Engine:EMS scan for process: svchost pid: 4756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.254 Engine:EMS scan for process: svchost pid: 4796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.257 Engine:EMS scan for process: svchost pid: 4804, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.262 Engine:EMS scan for process: svchost pid: 4820, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.264 Engine:EMS scan for process: svchost pid: 4828, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.266 Engine:EMS scan for process: svchost pid: 4836, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.268 Engine:EMS scan for process: svchost pid: 4856, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.270 Engine:EMS scan for process: svchost pid: 5092, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.272 Engine:EMS scan for process: svchost pid: 5360, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.275 Engine:Setting original file name "microsoftedgedevtools.exe" for "c:\windows\system32\microsoftedgecp.exe", hr=0x0

2025-11-25T01:40:07.275 Engine:EMS scan for process: svchost pid: 5576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.276 Engine:EMS scan for process: svchost pid: 5952, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.280 Engine:EMS scan for process: svchost pid: 6112, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.282 Engine:EMS scan for process: svchost pid: 7428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.284 Engine:EMS scan for process: svchost pid: 7608, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.287 Engine:EMS scan for process: svchost pid: 7916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.290 Engine:EMS scan for process: svchost pid: 7980, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.292 Engine:EMS scan for process: svchost pid: 8028, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.293 Bm signature throttled:0x00002db31bed458f

2025-11-25T01:40:07.299 Engine:Setting original file name "la57setup.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ec428185df2994f7d7954c1efe1b2738\la57setup.exe.mui", hr=0x0

2025-11-25T01:40:07.299 Engine:EMS scan for process: svchost pid: 7540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.301 Bm signature throttled:0x00002db31bed458f

2025-11-25T01:40:07.303 Engine:EMS scan for process: svchost pid: 8648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.306 Engine:EMS scan for process: explorer pid: 8868, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.306 Engine:Setting original file name "wuapi.dll" for "c:\windows\uus\x86\wuapicore.dll", hr=0x0

2025-11-25T01:40:07.344 Engine:EMS scan for process: svchost pid: 9032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.349 Engine:EMS scan for process: svchost pid: 8600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.351 Engine:EMS scan for process: svchost pid: 9412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.353 Engine:EMS scan for process: svchost pid: 10236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.356 Engine:EMS scan for process: svchost pid: 11004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.357 Bm signature throttled:0x00002db31bed458f

2025-11-25T01:40:07.359 Engine:EMS scan for process: svchost pid: 13336, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.360 Bm signature throttled:0x00002db31bed458f

2025-11-25T01:40:07.363 Engine:EMS scan for process: svchost pid: 11216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.366 Engine:EMS scan for process: svchost pid: 17572, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.369 Engine:EMS scan for process: svchost pid: 18256, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.369 Bm signature throttled:0x00002db31bed458f

2025-11-25T01:40:07.371 Engine:EMS scan for process: svchost pid: 16804, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.372 Engine:EMS scan for process: svchost pid: 4424, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.373 Bm signature throttled:0x00002db31bed458f

2025-11-25T01:40:07.377 Engine:EMS scan for process: svchost pid: 5528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.378 Bm signature throttled:0x00002db31bed458f

2025-11-25T01:40:07.378 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\system32\en-us\dsprop.dll.mui", hr=0x0

2025-11-25T01:40:07.380 Engine:EMS scan for process: svchost pid: 16044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.385 Engine:EMS scan for process: svchost pid: 14652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.387 Engine:EMS scan for process: svchost pid: 6184, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.389 Engine:EMS scan for process: svchost pid: 3312, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.392 Engine:EMS scan for process: dllhost pid: 5328, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.395 Engine:EMS scan for process: svchost pid: 1224, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.397 Engine:EMS scan for process: svchost pid: 15608, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.399 Engine:EMS scan for process: svchost pid: 22188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.401 Engine:EMS scan for process: dllhost pid: 5472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.409 Engine:EMS scan for process: svchost pid: 19428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.411 Engine:EMS scan for process: svchost pid: 23972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.412 Engine:EMS scan for process: dllhost pid: 4660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.415 Engine:EMS scan for process: svchost pid: 18356, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.416 Engine:EMS scan for process: svchost pid: 26712, sigseq: 0x0, sendMemoryScanReport: 0, source: 1

2025-11-25T01:40:07.635 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-25T01:40:07.655 Engine:Setting original file name "etweseproviderresources.dll" for "c:\windows\winsxs\backup\amd64_microsoft-etw-ese_31bf3856ad364e35_10.0.26100.1_none_cc4e7afeeee8d3b1_etweseproviderresources.dll_f21e8ea7", hr=0x0

2025-11-25T01:40:07.720 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_2821a024e044bada_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:07.721 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-25T01:40:07.759 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bf8ce2a53903d9e6d302aee07de95dd9\mfc40u.dll.mui", hr=0x0

2025-11-25T01:40:07.771 Engine:Setting original file name "TAPISRV.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-tapiservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_83c985f74a352be9\tapisrv.dll.mui", hr=0x0

2025-11-25T01:40:07.974 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lo-la_099683f3cb70d44f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:07.976 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x0

2025-11-25T01:40:08.069 Engine:Setting original file name "wininet.dll" for "c:\windows\systemresources\wininet.dll.mun", hr=0x0

2025-11-25T01:40:08.100 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\nb-no\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x0

2025-11-25T01:40:08.118 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_hu-hu_9dd052ebcaf187fd_memtest.efi.mui_71e15c22", hr=0x0

2025-11-25T01:40:08.121 Engine:Setting original file name "PrintBrmEng.exe.mui" for "c:\windows\system32\spool\tools\en-us\printbrmengine.exe.mui", hr=0x0

2025-11-25T01:40:08.123 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_it-it_4087c8eabdc39e5f_memtest.efi.mui_71e15c22", hr=0x0

2025-11-25T01:40:08.157 Engine:Setting original file name "audioadg.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f411807b0749e7d602e77baf3c1c4e60\audiodg.exe.mui", hr=0x0

2025-11-25T01:40:08.228 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x0

2025-11-25T01:40:08.306 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-t..iprovider.resources_31bf3856ad364e35_10.0.26100.1_en-us_41b711b4f2db4fe7\rdpsign.exe.mui", hr=0x0

2025-11-25T01:40:08.440 Engine:Setting original file name "Video_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\video\nb-no\2ca5a0690699da595bd35a22420a1c04\diagpackage.dll.mui", hr=0x0

2025-11-25T01:40:08.447 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-25T01:40:08.469 Engine:Setting original file name "FvSDKTestClientPublic" for "c:\program files\nvidia corporation\frameviewsdk\sdk\fvsdktestclient_public.exe", hr=0x0

2025-11-25T01:40:08.515 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\qps-ploc\msprivs.dll.mui", hr=0x0

2025-11-25T01:40:08.517 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-25T01:40:08.642 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\windows\system32\nb-no\pnpclean.dll.mui", hr=0x0

2025-11-25T01:40:08.656 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_or-in_f89501f89f876dc5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:08.688 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.26100.7171_none_4ad020869b677502\taskmgr.exe.mun", hr=0x0

2025-11-25T01:40:08.739 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_ca98740be1962356_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:08.797 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x0

2025-11-25T01:40:08.856 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_it-it_f0fca0072ba86c5a\msprivs.dll.mui", hr=0x0

2025-11-25T01:40:08.900 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps-ploc_7ccda1c46b445ed4\memtest.exe.mui", hr=0x0

2025-11-25T01:40:08.918 Engine:Setting original file name "NETBIOS.SYS" for "c:\windows\winsxs\backup\amd64_microsoft-windows-netbios_31bf3856ad364e35_10.0.26100.1_none_56d5608ad3abe945_netbios.sys_6f23c4df", hr=0x0

2025-11-25T01:40:08.976 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-process-l1-1-0.dll", hr=0x0

2025-11-25T01:40:09.111 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\systemresources\etwcoreuicomponentsresources.dll.mun", hr=0x0

2025-11-25T01:40:09.124 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pt-br_55b72b827c87f88f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:09.247 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_0dc0948c02e4507b_memtest.efi.mui_71e15c22", hr=0x0

2025-11-25T01:40:09.261 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mt-mt_b4ebaa02b8bfece3_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:09.295 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.devices.winmd", hr=0x0

2025-11-25T01:40:09.332 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_576ce8a1070e9744_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:09.345 Engine:Setting original file name "FileInfo.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-fileinfominifilter_31bf3856ad364e35_10.0.26100.1150_none_729c4b9be137bb96_fileinfo.sys_9be2dfcd", hr=0x0

2025-11-25T01:40:09.425 Engine:Setting original file name "aclui.dll" for "c:\windows\winsxs\amd64_microsoft-windows-aclui_31bf3856ad364e35_10.0.26100.7019_none_f0f7bbb4638cf785\aclui.dll.mun", hr=0x0

2025-11-25T01:40:09.429 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\73be2921551d\apex_fieldsamplerchecked_x86.dll", hr=0x0

2025-11-25T01:40:09.488 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.777.2143.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-25T01:40:09.550 Engine:Setting original file name "qualityupdateassistant" for "c:\program files\microsoft update health tools\qualityupdateassistant.dll", hr=0x0

2025-11-25T01:40:09.573 Engine:Setting original file name "NVPPE.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvppex.dll", hr=0x0

2025-11-25T01:40:09.650 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_en-us_4761fcc7ecd6d884_winresume.efi.mui_f412814e", hr=0x0

2025-11-25T01:40:09.841 Engine:Setting original file name "NVPrxy.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvprxy32.dll", hr=0x0

2025-11-25T01:40:09.946 Engine:Setting original file name "Mystify" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\589bec7339e102473dc7566c3b9b0f45\mystify.scr.mui", hr=0x0

2025-11-25T01:40:09.973 Engine:Setting original file name "volmgrx.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..memanager.resources_31bf3856ad364e35_10.0.26100.1_en-us_a18734abf077f9b4_volmgrx.sys.mui_b0c205d7", hr=0x0

2025-11-25T01:40:10.008 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-25T01:40:10.111 Engine:Setting original file name "libcrypto" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\libcrypto-3-x64.dll", hr=0x0

2025-11-25T01:40:10.135 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-string-l1-1-0.dll", hr=0x0

2025-11-25T01:40:10.169 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hi-in_83227505fd46a5bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:10.211 Engine:Setting original file name "CertCa" for "c:\windows\winsxs\amd64_microsoft-windows-c..ertca-dll.resources_31bf3856ad364e35_10.0.26100.1_nb-no_25e015431023bb9b\certca.dll.mui", hr=0x0

2025-11-25T01:40:10.319 Engine:Setting original file name "PCW_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_ddc581f4a364804b\diagpackage.dll.mui", hr=0x0

2025-11-25T01:40:10.404 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..subsystem.resources_31bf3856ad364e35_10.0.26100.1_nb-no_ab8620bc0ed41a36\scardsvr.dll.mui", hr=0x0

2025-11-25T01:40:10.421 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_6.0.3624.51421.dll", hr=0x0

2025-11-25T01:40:10.504 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-25T01:40:10.539 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_06d4a9c0547686dc\msprivs.dll.mui", hr=0x0

2025-11-25T01:40:10.692 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mapi_31bf3856ad364e35_10.0.26100.7019_none_473a9ee5c9a5ebee\mapistub.dll", hr=0x0

2025-11-25T01:40:10.811 Engine:Setting original file name "mofcomp.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_nb-no_8c87dcbbb8114be3_mofcomp.exe.mui_35badf56", hr=0x0

2025-11-25T01:40:10.816 Engine:Setting original file name "MspsProv.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..oning-wmi.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd6de3cbb42de1cb\mspsprov.dll.mui", hr=0x0

2025-11-25T01:40:10.861 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x0

2025-11-25T01:40:10.962 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.26100.7019_none_4a484d6501b73a17\wwanapi.dll", hr=0x0

2025-11-25T01:40:11.034 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ne-np_591939d32e7d4223_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:11.111 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.xboxidentityprovider_12.130.16001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-25T01:40:11.279 Engine:Setting original file name "Operativsystemet Microsoft� Windows�" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e2a170892be5347a116ae0806fb5309d\pcalua.exe.mui", hr=0x0

2025-11-25T01:40:11.358 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x0

2025-11-25T01:40:11.375 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x0

2025-11-25T01:40:11.666 Engine:Setting original file name "imageres.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-imageres_31bf3856ad364e35_10.0.26100.1_none_d9b14b936072a0bc\imageres.dll.mun", hr=0x0

2025-11-25T01:40:11.879 Engine:Setting original file name "vcruntime140.dll" for "c:\config.msi\1c742.rbf", hr=0x0

2025-11-25T01:40:11.922 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-25T01:40:11.964 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_kk-kz_71b9c9e0d19e9ee0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:12.173 Engine:Setting original file name "Apps_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\apps\nb-no\d2a92c7cfed83dc547a21508b5b0ea0f\diagpackage.dll.mui", hr=0x0

2025-11-25T01:40:12.191 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32.dll", hr=0x0

2025-11-25T01:40:12.244 Engine:Setting original file name "CertPKICmdlet" for "c:\windows\system32\en-us\certpkicmdlet.dll.mui", hr=0x0

2025-11-25T01:40:12.301 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ed4232cecc06e9efb72d2a7c142b63b4\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x0

2025-11-25T01:40:12.311 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.424.1611.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-25T01:40:12.374 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_0cb2119581e88ce0\diagpackage.dll.mui", hr=0x0

2025-11-25T01:40:12.539 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\system32\bcp47langs.dll", hr=0x0

2025-11-25T01:40:12.609 Engine:Setting original file name "gpapi.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-g..licy-base.resources_31bf3856ad364e35_10.0.26100.1_en-us_be2843fbd972ca37_gpapi.dll.mui_ef0a9748", hr=0x0

2025-11-25T01:40:12.611 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-math-l1-1-0.dll", hr=0x0

2025-11-25T01:40:12.668 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x0

2025-11-25T01:40:12.677 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\winsxs\amd64_microsoft-windows-aerolite.resources_31bf3856ad364e35_10.0.26100.1_en-us_bc993ceae8fc48bf\aerolite.msstyles.mui", hr=0x0

2025-11-25T01:40:12.956 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\en-us\utilman.exe.mui", hr=0x0

2025-11-25T01:40:13.101 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x0

2025-11-25T01:40:13.213 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-25T01:40:13.221 Engine:Setting original file name "sqlite3" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\sqlite3.dll", hr=0x0

2025-11-25T01:40:13.287 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x0

2025-11-25T01:40:13.336 Engine:Setting original file name "w32time.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-time-tool.resources_31bf3856ad364e35_10.0.26100.1_en-us_7b897a2738f484fc\w32tm.exe.mui", hr=0x0

2025-11-25T01:40:13.339 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd473133072db5bb\diagpackage.dll.mui", hr=0x0

2025-11-25T01:40:13.366 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_80a1d04cb31f8eca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:13.370 Engine:Setting original file name "ERC" for "c:\windows\system32\nb-no\wercplsupport.dll.mui", hr=0x0

2025-11-25T01:40:13.403 Engine:Setting original file name "vdsutil.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-v..skservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_59d12af3dce743c1_vdsutil.dll.mui_0caf9b0e", hr=0x0

2025-11-25T01:40:13.492 Engine:Setting original file name "AppLockerCSP.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appidcore.resources_31bf3856ad364e35_10.0.26100.1_en-us_564c6ad9b132641f_applockercsp.dll.mui_d2a0df70", hr=0x0

2025-11-25T01:40:13.550 Engine:Setting original file name "dnsrslvr.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570_dnsrslvr.dll.mui_1e1a1ed1", hr=0x0

2025-11-25T01:40:13.620 Engine:Setting original file name "PSAPI" for "c:\windows\winsxs\backup\wow64_microsoft-windows-basedependencies_31bf3856ad364e35_10.0.26100.1_none_09ea4476c5bcc4c0_psapi.dll_e8b5b4d1", hr=0x0

2025-11-25T01:40:13.645 Engine:Setting original file name "AcPlugin.dll" for "c:\program files\windowsapps\microsoft.applicationcompatibilityenhancements_1.2511.9.0_x64__8wekyb3d8bbwe\amd64\acplugin_test.dll", hr=0x0

2025-11-25T01:40:13.657 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\426c2b1101abec586136a4bbd67a716e\narrator.exe.mui", hr=0x0

2025-11-25T01:40:13.674 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..tiator_ui.resources_31bf3856ad364e35_10.0.26100.1_en-us_7967a83a130d426e\iscsicpl.dll.mui", hr=0x0

2025-11-25T01:40:13.771 Engine:Setting original file name "WindowsMediaPlayerPlayDVD_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_587c1f8aa98a4a71\diagpackage.dll.mui", hr=0x0

2025-11-25T01:40:13.966 Engine:Setting original file name "scecli" for "c:\windows\system32\nb-no\scecli.dll.mui", hr=0x0

2025-11-25T01:40:13.984 Engine:Setting original file name "scesrv" for "c:\windows\winsxs\amd64_microsoft-windows-s..ionengine.resources_31bf3856ad364e35_10.0.26100.1_en-us_e63bd45b831a32e3\scesrv.dll.mui", hr=0x0

2025-11-25T01:40:14.014 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_bg-bg_af9bba51d24fbf0e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:14.074 Engine:Setting original file name "nvhda.sys" for "c:\windows\system32\driverstore\filerepository\nvhda.inf_amd64_c32d8360d192a82e\nvhda64v.sys", hr=0x0

2025-11-25T01:40:14.084 Engine:Setting original file name "wmiutils.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiutils.dll.mui_42583eaf", hr=0x0

2025-11-25T01:40:14.099 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_te-in_e10bae4a47776b9f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:14.128 Engine:Setting original file name "BdncProxy.dll" for "c:\program files\bitdefender agent\27.1.1.23\crash_handler\bdnc.dll", hr=0x0

2025-11-25T01:40:14.201 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.26100.1_nb-no_e175a2f7bf27ee8d_ws2ifsl.sys.mui_b672c7b4", hr=0x0

2025-11-25T01:40:14.266 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_eu-es_e55e702bbb854a24_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:14.303 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-msinfo32-exe.resources_31bf3856ad364e35_10.0.26100.1_en-us_53ae64398a08feba\msinfo32.exe.mui", hr=0x0

2025-11-25T01:40:14.347 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-25T01:40:14.446 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x86__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-25T01:40:14.466 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x0

2025-11-25T01:40:14.564 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x0

2025-11-25T01:40:14.571 Engine:Setting original file name "NxCooking.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\v2.7.6\physxcooking.dll", hr=0x0

2025-11-25T01:40:14.600 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-25T01:40:14.739 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x0

2025-11-25T01:40:14.815 Engine:Setting original file name "filterLib.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\4fffc8576907b0b5da815790887fb244\fltlib.dll.mui", hr=0x0

2025-11-25T01:40:14.844 Engine:Setting original file name "srpuxgp.dll" for "c:\windows\systemresources\srpuxnativesnapin.dll.mun", hr=0x0

2025-11-25T01:40:14.848 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-25T01:40:15.039 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_nl-nl_0d26e65c98dbf6f7_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:15.049 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sl-si_8549ba61ed8af84b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:15.053 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x0

2025-11-25T01:40:15.228 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_pl-pl_9d43c82914fc6152_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:15.250 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.web.winmd", hr=0x0

2025-11-25T01:40:15.313 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-25T01:40:15.426 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ca-es_584cefb2c144b7d8_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:15.436 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\winsxs\amd64_microsoft-windows-qedwipes_31bf3856ad364e35_10.0.26100.1_none_5473011012d79dc1\qedwipes.dll.mun", hr=0x0

2025-11-25T01:40:15.598 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_et-ee_4da61d721400c924_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:15.637 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_fb2fbffb5205c552_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:15.850 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..xe-common.resources_31bf3856ad364e35_10.0.26100.1_en-us_58b62bf54b9ae38a\msinfo32.exe.mui", hr=0x0

2025-11-25T01:40:15.969 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.70.1338.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-25T01:40:15.974 Engine:Setting original file name "netcfgx.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-tcpip.resources_31bf3856ad364e35_10.0.26100.1_en-us_c93621b935b09922_tcpipcfg.dll.mui_a5479fc1", hr=0x0

2025-11-25T01:40:16.024 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_f4c1513bcd79893e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:16.070 Engine:Setting original file name "nvxdsync.exe" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\session\nvxdsyncplugin.dll", hr=0x0

2025-11-25T01:40:16.200 Engine:Setting original file name "ReShade" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\reshadefxc64.exe", hr=0x0

2025-11-25T01:40:16.245 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-25T01:40:16.289 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_0fbfb1c9f2926e3e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:16.319 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\power\nb-no\2803551e72f3605cc0b181750700647e\diagpackage.dll.mui", hr=0x0

2025-11-25T01:40:16.380 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_th-th_25ee4fb15dc2e739_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:16.387 Engine:Setting original file name "Umpo.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-u..erservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_a887c532823d0a08_umpo.dll.mui_cac12e54", hr=0x0

2025-11-25T01:40:16.389 Engine:Setting original file name "bootres" for "c:\windows\boot\resources\nb-no\bootres.dll.mui", hr=0x0

2025-11-25T01:40:16.411 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\b74f41bc269d13282681d018820fb031\ddores.dll.mui", hr=0x0

2025-11-25T01:40:16.434 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x0

2025-11-25T01:40:16.443 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\mscordaccore_amd64_amd64_8.0.2125.47513.dll", hr=0x0

2025-11-25T01:40:16.469 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-namedpipe-l1-1-0.dll", hr=0x0

2025-11-25T01:40:16.574 Engine:Setting original file name "dxmasf.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_10.0.26100.7019_none_b1abcb083360b859\msdxm.ocx", hr=0x0

2025-11-25T01:40:16.700 Engine:Setting original file name "Bubbles" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ee15dd2b573766654f76694ac2f468d4\bubbles.scr.mui", hr=0x0

2025-11-25T01:40:16.737 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_tr-tr_2c24c8b8ddbbff8a_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:16.760 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_es-mx_9dca765f230af946_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:16.783 Engine:Setting original file name "CUDART64_65_19.DLL" for "c:\program files (x86)\nvidia corporation\physx\common\cudart64_65.dll", hr=0x0

2025-11-25T01:40:16.799 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-errorhandling-l1-1-0.dll", hr=0x0

2025-11-25T01:40:16.928 Engine:Setting original file name "wcp.dll" for "c:\windows\system32\ssshim.dll", hr=0x0

2025-11-25T01:40:17.027 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.exe", hr=0x0

2025-11-25T01:40:17.074 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-time-l1-1-0.dll", hr=0x0

2025-11-25T01:40:17.079 Engine:Setting original file name "SCardDlg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.26100.3323_en-us_fe960d41ea77a2e8_scarddlg.dll.mui_300ae9df", hr=0x0

2025-11-25T01:40:17.103 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-memory-l1-1-0.dll", hr=0x0

2025-11-25T01:40:17.113 Engine:Setting original file name "reg.exe" for "c:\windows\winsxs\wow64_microsoft-windows-r..-commandline-editor_31bf3856ad364e35_10.0.26100.5074_none_d7dcabbe0ef09540\reg.exe", hr=0x0

2025-11-25T01:40:17.126 Engine:Setting original file name "TrustedSignalCredProv.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..-credprov.resources_31bf3856ad364e35_10.0.26100.1_en-us_080e5e17ad23b7b4_trustedsignalcredprov.dll.mui_5edc427b", hr=0x0

2025-11-25T01:40:17.161 Engine:Setting original file name "fpb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\fpb.rs.mui", hr=0x0

2025-11-25T01:40:17.291 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ta-in_72c4ac1bf2d12188_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-25T01:40:17.291 OriginalFileName Maintenance::11485 files in Moac, 0 skipped (cached), 434 filename set

2025-11-25T01:40:17.291 [AutoPurge] Routine task for Cache Maintenance has ended.

2025-11-25T01:43:53.224 QuickScan:ScanID:B2C4A125-20F6-477A-B126-55C4744AFB78: Quick scan finished with error 0

2025-11-25T01:43:53.744 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-25T01:43:53.744 [RTP] Duplicating the current plugin configuration object...

2025-11-25T01:43:53.744 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-25T01:43:53.744 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-25T01:43:53.744 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-25T01:43:53.744 [RTP] No config change detected. Not updating plugin configuration.

2025-11-25T01:43:53.744 [RTP] No config changes found. No configuration switch.

2025-11-25T01:43:53.744 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-25T01:43:55.248 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-25T01:43:55.250 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-25T01:43:55.252 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-25T01:47:34.464 Bm signature throttled:0x0000fab3228bcd4d

2025-11-25T01:49:47.618 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #279351, FileId: 0x1c000000009e4f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T01:52:06.732 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #279445, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T01:52:06.735 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #279446, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T01:52:16.746 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #279454, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T01:52:16.749 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #279455, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T01:52:16.750 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #279456, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T01:53:23.130 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T02:04:48.351 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #279669, FileId: 0x62000000009d59, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T02:08:28.126 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T02:09:54.893 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #280011, FileId: 0xf1000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T02:17:28.189 ProcessImageName: RuntimeBroker.exe, Pid: 6752, TotalTime: 1145, Count: 42, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 796, Count: 86, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\57521aa9-2618-4baf-8110-1c06f0ea2127.tmp, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 630, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\efd29925-08ab-45c9-8758-051d0ead4b05.tmp, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: taskhostw.exe, Pid: 9736, TotalTime: 360, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\UusSettings.json, EstimatedImpact: 5%

2025-11-25T02:17:28.189 ProcessImageName: WmiPrvSE.exe, Pid: 7476, TotalTime: 330, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf, EstimatedImpact: 31%

2025-11-25T02:17:28.189 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 155, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 120, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 8%

2025-11-25T02:17:28.189 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 120, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: taskhostw.exe, Pid: 13900, TotalTime: 91, Count: 43, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-25T02:17:28.189 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: taskhostw.exe, Pid: 25364, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\UCPD.sys, EstimatedImpact: 4%

2025-11-25T02:17:28.189 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 45, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\8ce77958-1341-4a99-9c77-756f3bc3462e.tmp, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: taskhostw.exe, Pid: 1968, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-25T02:17:28.189 ProcessImageName: updater.exe, Pid: 27220, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9cb2b6b0-3e42-41a3-adf6-1f4b5033dfcb.tmp, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: updater.exe, Pid: 3540, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\114fe849-9595-4ec0-b5f9-50cbd7d22c18.tmp, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-25T02:17:28.189 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-25T02:19:48.895 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #280053, FileId: 0x27000000009d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T02:23:33.122 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T02:34:49.623 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #280165, FileId: 0x168000000009f5c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T02:38:38.121 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T02:49:50.562 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #280299, FileId: 0x12000000000a115, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T02:52:07.758 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #280308, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T02:52:07.762 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #280309, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T02:52:17.770 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #280314, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T02:52:17.774 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #280315, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T02:53:43.102 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T03:04:51.208 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #280430, FileId: 0x16f00000000a1fd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T03:08:48.109 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T03:19:52.071 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #280947, FileId: 0x1b000000009dca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T03:23:53.098 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T03:34:52.799 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #281047, FileId: 0x12500000000a122, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T03:38:58.101 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T03:47:36.542 Bm signature throttled:0x0000fab3228bcd4d

2025-11-25T03:49:53.337 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #281248, FileId: 0x2e000000009e8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T03:52:06.594 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #281272, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T03:52:06.598 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #281273, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T03:52:16.600 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #281280, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T03:52:16.600 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #281281, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T03:52:16.604 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #281282, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T03:54:03.091 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T04:04:53.936 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #281402, FileId: 0x16700000000a4f5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T04:09:08.091 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T04:17:28.164 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1607, Count: 172, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\57521aa9-2618-4baf-8110-1c06f0ea2127.tmp, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1261, Count: 106, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\99e84a76-b3e0-41cd-ad30-a12fcae006c2.tmp, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: RuntimeBroker.exe, Pid: 6752, TotalTime: 1145, Count: 42, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 676, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 54%

2025-11-25T04:17:28.164 ProcessImageName: taskhostw.exe, Pid: 9736, TotalTime: 360, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\UusSettings.json, EstimatedImpact: 5%

2025-11-25T04:17:28.164 ProcessImageName: WmiPrvSE.exe, Pid: 7476, TotalTime: 330, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf, EstimatedImpact: 31%

2025-11-25T04:17:28.164 ProcessImageName: DeviceCensus.exe, Pid: 18180, TotalTime: 296, Count: 13, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-25T04:17:28.164 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 195, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 155, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 150, Count: 44, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: taskhostw.exe, Pid: 13900, TotalTime: 91, Count: 43, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-25T04:17:28.164 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 90, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 75, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 60, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: taskhostw.exe, Pid: 25364, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\UCPD.sys, EstimatedImpact: 4%

2025-11-25T04:17:28.164 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: taskhostw.exe, Pid: 21172, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 17%

2025-11-25T04:17:28.164 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: taskhostw.exe, Pid: 9524, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 16%

2025-11-25T04:17:28.164 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\8ce77958-1341-4a99-9c77-756f3bc3462e.tmp, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: taskhostw.exe, Pid: 25252, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-25T04:17:28.164 ProcessImageName: taskhostw.exe, Pid: 1968, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-25T04:17:28.164 ProcessImageName: updater.exe, Pid: 27220, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9cb2b6b0-3e42-41a3-adf6-1f4b5033dfcb.tmp, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: updater.exe, Pid: 3540, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\114fe849-9595-4ec0-b5f9-50cbd7d22c18.tmp, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-25T04:17:28.164 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-25T04:19:54.479 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #281662, FileId: 0x1b000000009eaa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T04:24:13.088 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T04:34:55.040 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #281779, FileId: 0x11e00000000ae48, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T04:39:18.091 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T04:49:55.687 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #282343, FileId: 0x21400000000a59e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T04:52:06.009 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #282352, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T04:52:06.013 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #282353, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T04:52:16.019 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #282358, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T04:52:16.025 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #282359, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T04:54:23.076 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T05:04:56.159 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #282453, FileId: 0x15c00000000bd43, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T05:07:04.006 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\4E8F50FE-8C35-4204-94A5-1D3D3774302C236c.1dc5dc955e20053

2025-11-25T05:07:04.044 Verifying engine and signature files (source: 0) ...

2025-11-25T05:07:04.044 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2EBD876A-1A5A-41D2-9E4C-C5260E96DD5A}\mpengine.dll] due to PPL.

2025-11-25T05:07:04.044 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2EBD876A-1A5A-41D2-9E4C-C5260E96DD5A}\mpasbase.vdm] (file in cache)

2025-11-25T05:07:04.044 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2EBD876A-1A5A-41D2-9E4C-C5260E96DD5A}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-25T05:07:04.055 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2EBD876A-1A5A-41D2-9E4C-C5260E96DD5A}\mpasdlta.vdm]

2025-11-25T05:07:04.055 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2EBD876A-1A5A-41D2-9E4C-C5260E96DD5A}\mpavbase.vdm] (file in cache)

2025-11-25T05:07:04.055 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2EBD876A-1A5A-41D2-9E4C-C5260E96DD5A}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-25T05:07:04.064 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2EBD876A-1A5A-41D2-9E4C-C5260E96DD5A}\mpavdlta.vdm]

2025-11-25T05:07:04.145 [Engine] IsHybridMode: 0

2025-11-25T05:07:04.146 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-25T05:07:04.157 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3D59ACB41C3CD65B3B7E3D00F2DFCEF4BBB917D1.bin): 0x00000002

2025-11-25T05:07:04.159 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3D59ACB41C3CD65B3B7E3D00F2DFCEF4BBB917D1.bin)

2025-11-25T05:07:04.159 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-25T05:07:04.159 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-25T05:07:04.159 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-25T05:07:04.159 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-25T05:07:09.812 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-25T05:07:09.812 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-25T05:07:09.820 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7225A660, lRefCount: 5, hr=0

2025-11-25T05:07:09.820 [Engine] New active engine 00007FFE4C3EA660 replacing engine 00007FFE7225A660. Number of active engines: 2

2025-11-25T05:07:09.827 EngineInit:Global ASOC is enabled

2025-11-25T05:07:09.827 EngineInit:ASOO is enabled for developer volumes

2025-11-25T05:07:09.859 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-25T05:07:09.860 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.860 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-25T05:07:09.860 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-25T05:07:09.860 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-25T05:07:09.860 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.861 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.861 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.861 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-25T05:07:09.862 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.862 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.862 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-25T05:07:09.863 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.863 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.863 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.864 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.864 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.864 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.864 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.865 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T05:07:09.865 Dynamic signature dropped

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8ca8e74d319b26fe9c0901b2ed05c72ff6f6a67f

Dynamic Signature Compilation Timestamp:11-24-2025 04:58:27

Persistence Type:Duration

Time remaining:864000000

2025-11-25T05:07:09.867 MpWriteUupSignatureVersion 1.441.473.0, hr = 0

2025-11-25T05:07:09.868 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-25T05:07:09.881 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-25T05:07:09.882 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-25T05:07:09.882 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-25T05:07:09.882 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-25T05:07:09.882 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-25T05:07:09.896 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-25T05:07:09.896 [Plugin] Initializing RTP plugin state...

2025-11-25T05:07:09.896 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-25T05:07:09.896 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 25 - 2025 01:17:28

Last Perf: 11 - 25 - 2025 01:17:28

First RTP Scan: 11 - 25 - 2025 01:17:29

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1365

  Misses:3556

BM Queue:0,22,0

  Proc:0,21,0

  File:0,14,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,2,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:282935

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1455773566

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:18

  TotalStreamCon:15542

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:1223911

   TotalHits:2026432

   InstanceCacheInserts:92838

   InstanceCacheUpdates:0

   InstanceCacheDeletes:71492

   InstanceCacheHits:4675

   InstanceCacheMisses:368511

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (795/916)

   Success: 916, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-25T05:07:09.896 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2EBD876A-1A5A-41D2-9E4C-C5260E96DD5A}

2025-11-25T05:07:09.896 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96E3949D-AD89-48EE-990D-0695AA4ADF09}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96E3949D-AD89-48EE-990D-0695AA4ADF09}\mpasbase.vdm in use, hr=0x80070020

2025-11-25T05:07:09.896 [SCC][CID=377344953_22456] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-25T05:07:09.897 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-25T05:07:09.897 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-25T05:07:09.897 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-25T05:07:09.897 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-25T05:07:09.898 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-25-2025 05:07:09

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-25-2025 05:07:09

2025-11-25T05:07:09.898 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-25T05:07:09.902 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-25T05:07:09.902 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-25T05:07:09.903 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-25T05:07:09.903 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-25-2025 05:07:09

END TDT(U) telemetry



2025-11-25T05:07:09.905 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T05:07:09.905 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-25T05:07:09.905 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-25T05:07:09.906 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-25T05:07:09.906 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-25T05:07:09.906 MdCoreSvc is supported in this platform and OS

Signature updated on 11-25-2025 05:07:09

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.473.0

AV Signature Version: 1.441.473.0

************************************************************

2025-11-25T05:07:09.907 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-25T05:07:09.907 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\4E8F50FE-8C35-4204-94A5-1D3D3774302C236c.1dc5dc955e20053

2025-11-25T05:07:09.923 Process scan (postsignatureupdatescan) started.

2025-11-25T05:07:09.952 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-25T05:07:09.953 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-25T05:07:10.092 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-25T05:07:10.092 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-25T05:07:10.092 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-25T05:07:10.092 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-25T05:07:10.092 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-25T05:07:10.093 [Engine] Engine 00007FFE7225A660 no longer in use. Number of active engines: 1

2025-11-25T05:07:10.093 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-25T05:07:10.093 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-25T05:07:10.237 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1983, Count: 206, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\57521aa9-2618-4baf-8110-1c06f0ea2127.tmp, EstimatedImpact: 0%

2025-11-25T05:07:10.237 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1630, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 85%

2025-11-25T05:07:10.237 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1546, Count: 130, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\99e84a76-b3e0-41cd-ad30-a12fcae006c2.tmp, EstimatedImpact: 0%

2025-11-25T05:07:10.237 ProcessImageName: RuntimeBroker.exe, Pid: 6752, TotalTime: 1145, Count: 42, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-25T05:07:10.237 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 676, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 54%

2025-11-25T05:07:10.237 ProcessImageName: taskhostw.exe, Pid: 9736, TotalTime: 360, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\UusSettings.json, EstimatedImpact: 5%

2025-11-25T05:07:10.237 ProcessImageName: WmiPrvSE.exe, Pid: 7476, TotalTime: 330, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf, EstimatedImpact: 31%

2025-11-25T05:07:10.237 ProcessImageName: DeviceCensus.exe, Pid: 18180, TotalTime: 296, Count: 13, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-25T05:07:10.237 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 195, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-25T05:07:10.237 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 195, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T05:07:10.237 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 170, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-25T05:07:10.237 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 165, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T05:07:10.237 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 105, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-25T05:07:10.237 ProcessImageName: taskhostw.exe, Pid: 13900, TotalTime: 91, Count: 43, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-25T05:07:10.237 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 75, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-25T05:07:10.237 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 75, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T05:07:10.256 [Engine] RSIG_UNLOADENGINE, 00007FFE7225A660, err=0x0

2025-11-25T05:07:10.273 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96E3949D-AD89-48EE-990D-0695AA4ADF09} removed

2025-11-25T05:07:10.384 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-25T05:07:10.390 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-25T05:07:10.390 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-25T05:07:10.390 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-25T05:07:10.390 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-25T05:07:10.390 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-25T05:07:10.390 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-25T05:07:10.394 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-25T05:07:10.394 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-25T05:07:10.394 [RTP] Duplicating the current plugin configuration object...

2025-11-25T05:07:10.394 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-25T05:07:10.394 [RTP] Updating plugin configuration due to recent config changes (0x22) ...

2025-11-25T05:07:10.394 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-25T05:07:10.394 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-25T05:07:10.394 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-25T05:07:10.394 [RTP] No config change detected. Not updating plugin configuration.

2025-11-25T05:07:10.394 [RTP] No config changes found. No configuration switch.

2025-11-25T05:07:10.394 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x22, Changed: 0

2025-11-25T05:07:10.394 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-25T05:07:10.394 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-25T05:07:10.394 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-25T05:07:10.394 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-25T05:07:10.394 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-25T05:07:10.394 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-25T05:07:10.394 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-25T05:07:10.394 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-25T05:07:10.394 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-25T05:07:10.394 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-25T05:07:10.394 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-25T05:07:10.394 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-25T05:07:10.394 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-25T05:07:10.395 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-25T05:07:10.395 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T05:07:10.396 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T05:07:10.398 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T05:07:10.399 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T05:07:10.401 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T05:07:10.403 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 82831846(ms) from now at 05:07 (04:07 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-25T05:07:11.923 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-25T05:07:11.927 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-25T05:07:11.928 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-25T05:07:12.918 [RTP] Duplicating the current plugin configuration object...

2025-11-25T05:07:12.918 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-25T05:07:12.918 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-25T05:07:12.918 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-25T05:07:12.918 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157ED7C270CE, sigsha=5eded354160aa060b3f2a16db0725661264de9cd, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF9518016, sigsha=8fa60ffaf004b3696b5767c35f78f1425d04eb09, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0xa85b3f00

2025-11-25T05:07:15.408 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-25T05:07:15.408 [Cloud] Start of cloud request. Passive mode: 0

2025-11-25T05:07:15.408 [Cloud] Queued cloud request.

2025-11-25T05:07:15.408 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-25T05:07:15.409 [Cloud] Dequeued cloud request.

2025-11-25T05:07:15.409 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0cde10c3c7a89f3395bc3d6917b759f095e80ea0

Dynamic Signature Compilation Timestamp:11-25-2025 05:07:15

Persistence Type:Duration

Time remaining:864000000

2025-11-25T05:07:15.638 Dynamic signature received

2025-11-25T05:07:15.639 [Cloud] End of cloud request.

2025-11-25T05:07:15.639 RTSD:RTSD recieved, rescanning impacted resources

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-25T05:07:16.153 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T05:07:17.084 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-25T05:07:17.084 [Cloud] Start of cloud request. Passive mode: 0

2025-11-25T05:07:17.084 [Cloud] Queued cloud request.

2025-11-25T05:07:17.084 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-25T05:07:17.084 [Cloud] Dequeued cloud request.

2025-11-25T05:07:17.084 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-25T05:07:17.554 [Cloud] End of cloud request.

2025-11-25T05:07:18.072 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T05:07:26.823 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-25T05:07:26.824 Process scan (postsignatureupdatescan) completed.

2025-11-25T05:09:28.076 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T05:12:09.856 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-25T05:19:56.920 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #284306, FileId: 0x54f00000000bba7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T05:24:33.075 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T05:30:18.185 Bm signature throttled:0x00002db31bed458f

2025-11-25T05:34:57.403 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #284738, FileId: 0x12000000000910a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T05:39:38.072 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T05:49:58.138 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #285072, FileId: 0x3b00000000bbd5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T05:52:06.645 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #285119, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T05:52:06.648 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #285120, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T05:52:16.663 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #285127, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T05:52:16.663 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #285128, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T05:52:16.667 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #285129, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T05:54:43.060 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T06:04:58.762 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #285302, FileId: 0x29000000009cd2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T06:08:05.199 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #285537, FileId: 0xb600000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T06:09:48.056 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T06:10:19.506 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #285707, FileId: 0xf2000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T06:19:59.095 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #285799, FileId: 0x7f00000000be3c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T06:24:53.054 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T06:34:59.683 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #285934, FileId: 0x13b00000000ab84, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T06:39:58.058 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T06:47:39.435 Bm signature throttled:0x0000fab3228bcd4d

2025-11-25T06:50:00.065 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #286222, FileId: 0x2b000000009e79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T06:52:06.113 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #286232, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T06:52:06.116 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #286233, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T06:52:16.124 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #286238, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T06:52:16.127 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #286239, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T06:52:16.128 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #286240, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T06:55:03.050 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T07:05:00.956 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #286362, FileId: 0x3f00000000be19, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T07:07:09.798 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 690, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\3dfa53f9-5ae1-4776-8ac7-28c35c6e2535.tmp, EstimatedImpact: 0%

2025-11-25T07:07:09.798 ProcessImageName: RuntimeBroker.exe, Pid: 17216, TotalTime: 571, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 37%

2025-11-25T07:07:09.798 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 495, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\a395dda9-f113-452e-bf96-f751c9f55bed.tmp, EstimatedImpact: 0%

2025-11-25T07:07:09.798 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 330, Count: 80, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T07:07:09.798 ProcessImageName: taskhostw.exe, Pid: 25320, TotalTime: 270, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 16%

2025-11-25T07:07:09.798 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 150, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-25T07:07:09.798 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-25T07:07:09.798 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T07:07:09.798 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T07:07:09.798 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 45, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\desktop.ini->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T07:07:09.798 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-25T07:07:09.798 ProcessImageName: taskhostw.exe, Pid: 4292, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 7%

2025-11-25T07:07:09.798 ProcessImageName: StoreDesktopExtension.exe, Pid: 5340, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-25T07:07:09.798 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\packages\Microsoft.6365217CE6EB4_8wekyb3d8bbwe\LocalState\Logs\69e3adab40c241289c6fa8bb310c696f.tmp, EstimatedImpact: 0%

2025-11-25T07:07:09.798 ProcessImageName: updater.exe, Pid: 24244, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-25T07:07:09.798 ProcessImageName: updater.exe, Pid: 21700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9a0a04a1-7524-44f5-9748-ceebaf070055.tmp, EstimatedImpact: 0%

2025-11-25T07:10:08.053 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T07:20:01.502 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #286631, FileId: 0xcc00000000a264, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T07:25:13.038 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T07:35:02.154 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #286712, FileId: 0xe1000000007b88, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T07:40:18.040 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T07:50:02.756 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #286881, FileId: 0x13d00000000cace, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T07:52:05.962 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #286911, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T07:52:05.965 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #286912, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T07:52:15.967 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #286920, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T07:52:15.971 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #286922, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T07:55:23.031 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T08:01:42.454 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #287040, FileId: 0xb700000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T08:05:03.394 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #287056, FileId: 0x1d6000000002d8f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T08:10:28.028 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T08:20:03.872 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #287324, FileId: 0x3c000000009cab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T08:25:33.022 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T08:35:04.317 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #287406, FileId: 0xc4000000003f43, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T08:40:38.021 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T08:47:41.542 Bm signature throttled:0x0000fab3228bcd4d

2025-11-25T08:50:04.898 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #287572, FileId: 0xd2000000003f43, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T08:52:07.367 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #287579, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T08:52:07.371 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #287580, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T08:52:17.371 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #287585, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T08:52:17.375 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #287586, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T08:52:17.375 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #287587, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T08:55:43.013 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T09:05:05.530 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #287707, FileId: 0xc500000000c28a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T09:07:09.770 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1575, Count: 159, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\3dfa53f9-5ae1-4776-8ac7-28c35c6e2535.tmp, EstimatedImpact: 0%

2025-11-25T09:07:09.770 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1156, Count: 103, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\726869b8-d360-4c58-9105-a5543fea3b55.tmp, EstimatedImpact: 0%

2025-11-25T09:07:09.770 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 615, Count: 146, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T09:07:09.770 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 601, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 42%

2025-11-25T09:07:09.770 ProcessImageName: RuntimeBroker.exe, Pid: 17216, TotalTime: 571, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 37%

2025-11-25T09:07:09.770 ProcessImageName: taskhostw.exe, Pid: 25320, TotalTime: 270, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 16%

2025-11-25T09:07:09.770 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 165, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T09:07:09.770 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 150, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-25T09:07:09.770 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-25T09:07:09.770 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 75, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-25T09:07:09.770 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 75, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T09:07:09.770 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 45, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\desktop.ini->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T09:07:09.770 ProcessImageName: StoreDesktopExtension.exe, Pid: 5340, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-25T09:07:09.770 ProcessImageName: taskhostw.exe, Pid: 4292, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 7%

2025-11-25T09:07:09.770 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\packages\Microsoft.6365217CE6EB4_8wekyb3d8bbwe\LocalState\Logs\69e3adab40c241289c6fa8bb310c696f.tmp, EstimatedImpact: 0%

2025-11-25T09:07:09.770 ProcessImageName: taskhostw.exe, Pid: 7640, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-25T09:07:09.770 ProcessImageName: updater.exe, Pid: 24244, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-25T09:07:09.770 ProcessImageName: updater.exe, Pid: 21700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9a0a04a1-7524-44f5-9748-ceebaf070055.tmp, EstimatedImpact: 0%

2025-11-25T09:10:48.007 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T09:20:06.386 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #287907, FileId: 0x1b200000000c0cb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T09:25:53.003 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T09:35:06.939 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #288009, FileId: 0x1b700000000c0cb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T09:40:57.995 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T09:45:40.970 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #288132, FileId: 0xf3000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T09:50:07.862 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #288629, FileId: 0x3800000000a5cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T09:52:05.708 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #288654, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T09:52:05.712 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #288655, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T09:52:15.722 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #288662, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T09:52:15.726 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #288663, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T09:52:15.726 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #288664, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T09:56:03.004 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T10:05:08.305 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #288753, FileId: 0x380000000099c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T10:11:08.001 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T10:20:09.018 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #288999, FileId: 0x29f00000000a72b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T10:26:12.983 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T10:35:09.510 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #289087, FileId: 0xd800000000b1f2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T10:41:17.985 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T10:47:43.531 Bm signature throttled:0x0000fab3228bcd4d

2025-11-25T10:50:10.038 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #289260, FileId: 0x6300000000b232, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T10:52:06.901 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #289270, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T10:52:06.905 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #289271, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T10:52:16.914 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #289276, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T10:52:16.917 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #289277, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T10:56:22.985 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T11:05:10.319 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #289472, FileId: 0x2a800000000a6aa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T11:07:09.735 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2371, Count: 244, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7afee7cf-6074-4b65-8884-1e16273508b9.tmp, EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1862, Count: 157, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\726869b8-d360-4c58-9105-a5543fea3b55.tmp, EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1520, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 81%

2025-11-25T11:07:09.735 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 660, Count: 164, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 616, Count: 124, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: RuntimeBroker.exe, Pid: 17216, TotalTime: 571, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 37%

2025-11-25T11:07:09.735 ProcessImageName: taskhostw.exe, Pid: 25320, TotalTime: 270, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 16%

2025-11-25T11:07:09.735 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 195, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 150, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 135, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\desktop.ini->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 105, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 90, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: taskhostw.exe, Pid: 4292, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 7%

2025-11-25T11:07:09.735 ProcessImageName: StoreDesktopExtension.exe, Pid: 5340, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\packages\Microsoft.6365217CE6EB4_8wekyb3d8bbwe\LocalState\Logs\69e3adab40c241289c6fa8bb310c696f.tmp, EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: taskhostw.exe, Pid: 23884, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-25T11:07:09.735 ProcessImageName: taskhostw.exe, Pid: 7640, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-25T11:07:09.735 ProcessImageName: updater.exe, Pid: 24244, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-25T11:07:09.735 ProcessImageName: updater.exe, Pid: 21700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9a0a04a1-7524-44f5-9748-ceebaf070055.tmp, EstimatedImpact: 0%

2025-11-25T11:11:27.982 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

Internal signature match:subtype=Lowfi, sigseq=0x00005CE7CC5A3752, sigsha=7e1afd9d794bc98262152514a242044b80de6fc9, cached=false, source=5, resourceid=0xdf920bf3

2025-11-25T11:12:56.605 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-25T11:12:56.605 [Cloud] Start of cloud request. Passive mode: 0

2025-11-25T11:12:56.605 [Cloud] Queued cloud request.

2025-11-25T11:12:56.605 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-25T11:12:56.605 [Cloud] Dequeued cloud request.

2025-11-25T11:12:56.605 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-25T11:12:56.989 [Cloud] End of cloud request.

2025-11-25T11:12:56.989 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\component_crx_cache\temp_1.1238f37b8013068ffb70edbc7233af896e0eb3bc811a4facc7cdea4a97b0048e. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x5ce7cc5a3752

2025-11-25T11:12:57.504 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T11:20:10.764 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #289782, FileId: 0xf100000000aa19, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T11:26:32.969 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T11:35:11.155 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #289928, FileId: 0x2b900000000a72b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T11:41:37.971 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T11:50:11.923 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #290043, FileId: 0x6900000000b232, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T11:52:07.101 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #290069, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T11:52:07.104 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #290070, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T11:52:17.113 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #290077, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T11:52:17.114 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #290078, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T11:52:17.117 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #290079, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T11:52:17.119 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #290080, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T11:56:42.965 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T12:05:12.415 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #290200, FileId: 0x1c600000000b6ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T12:11:47.961 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T12:20:12.961 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #290448, FileId: 0x2500000000b825, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T12:26:52.949 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T12:35:13.654 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #290516, FileId: 0xaf000000009833, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T12:41:57.945 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T12:47:45.559 Bm signature throttled:0x0000fab3228bcd4d

2025-11-25T12:50:14.743 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #290654, FileId: 0x126000000007b88, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T12:52:05.833 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #290661, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T12:52:05.835 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #290662, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T12:52:15.843 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #290667, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T12:52:15.847 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #290668, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T12:57:02.943 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T13:05:15.650 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #291144, FileId: 0x2d00000000b819, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T13:07:09.707 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3136, Count: 328, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7afee7cf-6074-4b65-8884-1e16273508b9.tmp, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2463, Count: 210, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\726869b8-d360-4c58-9105-a5543fea3b55.tmp, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1520, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 81%

2025-11-25T13:07:09.707 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 720, Count: 189, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 631, Count: 127, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: RuntimeBroker.exe, Pid: 17216, TotalTime: 571, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 37%

2025-11-25T13:07:09.707 ProcessImageName: WmiPrvSE.exe, Pid: 27408, TotalTime: 390, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf->(UTF-16LE), EstimatedImpact: 36%

2025-11-25T13:07:09.707 ProcessImageName: taskhostw.exe, Pid: 25320, TotalTime: 270, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 16%

2025-11-25T13:07:09.707 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 270, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 150, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 135, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\desktop.ini->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 135, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 120, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\packages\Microsoft.6365217CE6EB4_8wekyb3d8bbwe\LocalState\Logs\69e3adab40c241289c6fa8bb310c696f.tmp, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: backgroundTaskHost.exe, Pid: 1752, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1764054557, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\37a51600-5612-46a6-a0c9-c277a109d21e.tmp, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: taskhostw.exe, Pid: 4292, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 7%

2025-11-25T13:07:09.707 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: StoreDesktopExtension.exe, Pid: 5340, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: taskhostw.exe, Pid: 23884, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-25T13:07:09.707 ProcessImageName: taskhostw.exe, Pid: 7640, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-25T13:07:09.707 ProcessImageName: updater.exe, Pid: 24244, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: updater.exe, Pid: 21700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9a0a04a1-7524-44f5-9748-ceebaf070055.tmp, EstimatedImpact: 0%

2025-11-25T13:07:09.707 ProcessImageName: updater.exe, Pid: 1188, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\11b7ee87-d747-4b2e-8f13-a5b6a610da11.tmp, EstimatedImpact: 0%

2025-11-25T13:12:07.939 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T13:20:16.299 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #291358, FileId: 0x12500000000a740, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T13:27:12.937 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T13:35:16.769 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #291441, FileId: 0x3100000000b91d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T13:42:17.939 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T13:50:17.415 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #291586, FileId: 0xfe00000000aa3c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T13:52:07.523 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #291626, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T13:52:07.526 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #291627, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T13:52:17.525 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #291637, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T13:52:17.525 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #291636, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T13:52:17.529 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #291638, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T13:57:22.934 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T14:05:17.762 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #291742, FileId: 0x5600000000b85c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T14:09:54.778 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #291954, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T14:12:27.937 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T14:20:18.565 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #292368, FileId: 0x2e400000000cb2a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T14:27:32.925 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T14:35:19.758 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #292452, FileId: 0x17b00000000c455, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T14:42:37.924 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T14:47:47.517 Bm signature throttled:0x0000fab3228bcd4d

2025-11-25T14:50:20.551 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #292591, FileId: 0x5300000000be19, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T14:52:06.407 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #292597, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T14:52:06.410 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #292598, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T14:52:16.410 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #292603, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T14:52:16.414 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #292604, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T14:57:42.915 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T15:05:21.801 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #292715, FileId: 0x25c00000000c60e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T15:07:09.690 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3961, Count: 417, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7afee7cf-6074-4b65-8884-1e16273508b9.tmp, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3109, Count: 262, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\726869b8-d360-4c58-9105-a5543fea3b55.tmp, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1520, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 81%

2025-11-25T15:07:09.690 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 750, Count: 203, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 631, Count: 127, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: RuntimeBroker.exe, Pid: 17216, TotalTime: 571, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 37%

2025-11-25T15:07:09.690 ProcessImageName: WmiPrvSE.exe, Pid: 27408, TotalTime: 390, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf->(UTF-16LE), EstimatedImpact: 36%

2025-11-25T15:07:09.690 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 360, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: taskhostw.exe, Pid: 25320, TotalTime: 270, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 16%

2025-11-25T15:07:09.690 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 165, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 150, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\desktop.ini->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 150, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 120, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\packages\Microsoft.6365217CE6EB4_8wekyb3d8bbwe\LocalState\Logs\69e3adab40c241289c6fa8bb310c696f.tmp, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: backgroundTaskHost.exe, Pid: 1752, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1764054557, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\37a51600-5612-46a6-a0c9-c277a109d21e.tmp, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: StoreDesktopExtension.exe, Pid: 5340, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: taskhostw.exe, Pid: 4292, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 7%

2025-11-25T15:07:09.690 ProcessImageName: taskhostw.exe, Pid: 23884, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-25T15:07:09.690 ProcessImageName: taskhostw.exe, Pid: 7640, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-25T15:07:09.690 ProcessImageName: updater.exe, Pid: 24244, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: updater.exe, Pid: 21700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9a0a04a1-7524-44f5-9748-ceebaf070055.tmp, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: taskhostw.exe, Pid: 16448, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-25T15:07:09.690 ProcessImageName: updater.exe, Pid: 1188, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\11b7ee87-d747-4b2e-8f13-a5b6a610da11.tmp, EstimatedImpact: 0%

2025-11-25T15:12:47.917 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T15:20:23.015 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #293052, FileId: 0xc300000000a71e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T15:27:52.909 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T15:33:34.605 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #293308, FileId: 0xf4000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T15:35:24.412 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #293332, FileId: 0x1c00000000b90b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T15:42:57.912 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T15:44:08.163 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume4\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #293919, FileId: 0x32400000000a328, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T15:46:05.966 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #293968, FileId: 0xb900000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T15:50:25.255 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #294011, FileId: 0x2c500000000a807, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T15:50:55.098 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume4\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #294033, FileId: 0x1bd00000000a620, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T15:52:05.605 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #294056, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T15:58:02.912 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T16:13:07.893 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T16:28:12.902 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T16:43:17.887 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T16:47:49.540 Bm signature throttled:0x0000fab3228bcd4d

2025-11-25T16:52:06.132 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #294959, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T16:58:22.888 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T17:07:09.664 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 4819, Count: 500, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7afee7cf-6074-4b65-8884-1e16273508b9.tmp, EstimatedImpact: 0%

2025-11-25T17:07:09.664 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3849, Count: 314, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\726869b8-d360-4c58-9105-a5543fea3b55.tmp, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1520, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 81%

2025-11-25T17:07:09.665 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 840, Count: 275, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 631, Count: 127, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: sdiagnhost.exe, Pid: 24772, TotalTime: 618, Count: 43, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wad78daf4#\f2e9e298131866baab3f1fccb4eae979\Microsoft.Windows.Diagnosis.SDHost.ni.dll, EstimatedImpact: 41%

2025-11-25T17:07:09.665 ProcessImageName: RuntimeBroker.exe, Pid: 17216, TotalTime: 571, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 37%

2025-11-25T17:07:09.665 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 435, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 405, Count: 50, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: WmiPrvSE.exe, Pid: 27408, TotalTime: 390, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf->(UTF-16LE), EstimatedImpact: 36%

2025-11-25T17:07:09.665 ProcessImageName: taskhostw.exe, Pid: 25320, TotalTime: 270, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 16%

2025-11-25T17:07:09.665 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 225, Count: 37, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: taskhostw.exe, Pid: 23536, TotalTime: 182, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\Temp\SDIAG_4ae9f5b2-b100-4be5-972c-55f153efb2de\result\results.xsl, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 180, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\desktop.ini->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: ngentask.exe, Pid: 9688, TotalTime: 165, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 16%

2025-11-25T17:07:09.665 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 150, Count: 50, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 150, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: ngentask.exe, Pid: 24012, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 15%

2025-11-25T17:07:09.665 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\packages\Microsoft.6365217CE6EB4_8wekyb3d8bbwe\LocalState\Logs\69e3adab40c241289c6fa8bb310c696f.tmp, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: taskhostw.exe, Pid: 26276, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\MicrosoftWindows.Client.CBS_1000.26100.265.0_x64__cw5n1h2txyewy\machine.pckgdep, EstimatedImpact: 72%

2025-11-25T17:07:09.665 ProcessImageName: ngentask.exe, Pid: 25648, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 59%

2025-11-25T17:07:09.665 ProcessImageName: WmiPrvSE.exe, Pid: 24360, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 86%

2025-11-25T17:07:09.665 ProcessImageName: backgroundTaskHost.exe, Pid: 1752, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1764054557, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\37a51600-5612-46a6-a0c9-c277a109d21e.tmp, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: ngentask.exe, Pid: 25052, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 13%

2025-11-25T17:07:09.665 ProcessImageName: ngentask.exe, Pid: 2032, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 32%

2025-11-25T17:07:09.665 ProcessImageName: taskhostw.exe, Pid: 2136, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\BTHUSB.SYS, EstimatedImpact: 2%

2025-11-25T17:07:09.665 ProcessImageName: ngentask.exe, Pid: 8684, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 8%

2025-11-25T17:07:09.665 ProcessImageName: taskhostw.exe, Pid: 4292, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 7%

2025-11-25T17:07:09.665 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: StoreDesktopExtension.exe, Pid: 5340, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: MicrosoftStartFeedProvider.exe, Pid: 12960, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.StartExperiencesApp_8wekyb3d8bbwe\LocalState\PreviewImages\553fd6d4a00a076195dbfcd2cf26efb031c3155435d58b00ba9647adbe479594.png, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: taskhostw.exe, Pid: 23884, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-25T17:07:09.665 ProcessImageName: taskhostw.exe, Pid: 7640, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-25T17:07:09.665 ProcessImageName: updater.exe, Pid: 24244, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: updater.exe, Pid: 21700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9a0a04a1-7524-44f5-9748-ceebaf070055.tmp, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 7%

2025-11-25T17:07:09.665 ProcessImageName: PhoneExperienceHost.exe, Pid: 1316, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\1044\StructuredQuerySchema.bin, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: taskhostw.exe, Pid: 16448, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: taskhostw.exe, Pid: 11468, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-25T17:07:09.665 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 0%

2025-11-25T17:07:09.666 ProcessImageName: updater.exe, Pid: 1188, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\11b7ee87-d747-4b2e-8f13-a5b6a610da11.tmp, EstimatedImpact: 0%

2025-11-25T17:13:27.891 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T17:28:32.878 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T17:32:46.698 Bm signature throttled:0x00002db31bed458f

2025-11-25T17:43:37.874 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T17:44:20.567 Bm signature throttled:0x00002db31bed458f

2025-11-25T17:49:18.314 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\F2BB60F2-B7C0-411F-A89C-B1DA20D02B2C4298.1dc5e33d19b6ddd

2025-11-25T17:49:18.349 Verifying engine and signature files (source: 0) ...

2025-11-25T17:49:18.349 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B24AC3F-8833-4C83-916A-FE6049A12D7A}\mpengine.dll] due to PPL.

2025-11-25T17:49:18.350 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B24AC3F-8833-4C83-916A-FE6049A12D7A}\mpasbase.vdm] (file in cache)

2025-11-25T17:49:18.350 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B24AC3F-8833-4C83-916A-FE6049A12D7A}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-25T17:49:18.361 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B24AC3F-8833-4C83-916A-FE6049A12D7A}\mpasdlta.vdm]

2025-11-25T17:49:18.361 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B24AC3F-8833-4C83-916A-FE6049A12D7A}\mpavbase.vdm] (file in cache)

2025-11-25T17:49:18.361 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B24AC3F-8833-4C83-916A-FE6049A12D7A}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-25T17:49:18.370 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B24AC3F-8833-4C83-916A-FE6049A12D7A}\mpavdlta.vdm]

2025-11-25T17:49:18.448 [Engine] IsHybridMode: 0

2025-11-25T17:49:18.449 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-25T17:49:18.460 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-26D63E5B1AC075B29B7AA769483D2DE7F8380744.bin): 0x00000002

2025-11-25T17:49:18.462 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-26D63E5B1AC075B29B7AA769483D2DE7F8380744.bin)

2025-11-25T17:49:18.462 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-25T17:49:18.462 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-25T17:49:18.462 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-25T17:49:18.462 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-25T17:49:24.384 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-25T17:49:24.384 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-25T17:49:24.392 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE4C3EA660, lRefCount: 5, hr=0

2025-11-25T17:49:24.392 [Engine] New active engine 00007FFE7225A660 replacing engine 00007FFE4C3EA660. Number of active engines: 2

2025-11-25T17:49:24.399 EngineInit:Global ASOC is enabled

2025-11-25T17:49:24.399 EngineInit:ASOO is enabled for developer volumes

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.433 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-25T17:49:24.435 MpWriteUupSignatureVersion 1.441.487.0, hr = 0

2025-11-25T17:49:24.436 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-25T17:49:24.450 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-25T17:49:24.451 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-25T17:49:24.451 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-25T17:49:24.451 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-25T17:49:24.451 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-25T17:49:24.465 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-25T17:49:24.466 [Plugin] Initializing RTP plugin state...

2025-11-25T17:49:24.466 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-25T17:49:24.466 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 25 - 2025 06:07:10

Last Perf: 11 - 25 - 2025 06:07:09

First RTP Scan: 11 - 25 - 2025 06:07:10

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:964

  Misses:8555

BM Queue:0,59,0

  Proc:0,39,0

  File:0,33,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:296165

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1544106552

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:18

  TotalStreamCon:15172

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:1289312

   TotalHits:2174288

   InstanceCacheInserts:97616

   InstanceCacheUpdates:0

   InstanceCacheDeletes:72712

   InstanceCacheHits:4700

   InstanceCacheMisses:380728

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (1445/1831)

   Success: 1831, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-25T17:49:24.466 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B24AC3F-8833-4C83-916A-FE6049A12D7A}

2025-11-25T17:49:24.466 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2EBD876A-1A5A-41D2-9E4C-C5260E96DD5A}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2EBD876A-1A5A-41D2-9E4C-C5260E96DD5A}\mpasbase.vdm in use, hr=0x80070020

2025-11-25T17:49:24.466 [SCC][CID=778193828_22792] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-25T17:49:24.467 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-25T17:49:24.467 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-25T17:49:24.467 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-25T17:49:24.467 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-25T17:49:24.468 MdCoreSvc is supported in this platform and OS

2025-11-25T17:49:24.468 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-25-2025 17:49:24

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-25-2025 17:49:24

2025-11-25T17:49:24.471 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-25T17:49:24.471 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-25T17:49:24.471 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-25T17:49:24.471 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-25-2025 17:49:24

END TDT(U) telemetry



2025-11-25T17:49:24.473 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T17:49:24.474 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-25T17:49:24.474 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-25T17:49:24.474 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-25T17:49:24.474 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-25T17:49:24.475 MdCoreSvc is supported in this platform and OS

Signature updated on 11-25-2025 17:49:24

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.487.0

AV Signature Version: 1.441.487.0

************************************************************

2025-11-25T17:49:24.476 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-25T17:49:24.476 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\F2BB60F2-B7C0-411F-A89C-B1DA20D02B2C4298.1dc5e33d19b6ddd

2025-11-25T17:49:24.497 Process scan (postsignatureupdatescan) started.

2025-11-25T17:49:24.520 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-25T17:49:24.522 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-25T17:49:24.687 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-25T17:49:24.687 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-25T17:49:24.687 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-25T17:49:24.687 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-25T17:49:24.687 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-25T17:49:24.690 [Engine] Engine 00007FFE4C3EA660 no longer in use. Number of active engines: 1

2025-11-25T17:49:24.690 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-25T17:49:24.690 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-25T17:49:24.867 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 5415, Count: 528, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\ecb16fda-0b20-409f-8689-b26542c01737.tmp, EstimatedImpact: 0%

2025-11-25T17:49:24.867 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4247, Count: 333, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\726869b8-d360-4c58-9105-a5543fea3b55.tmp, EstimatedImpact: 0%

2025-11-25T17:49:24.867 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1520, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 81%

2025-11-25T17:49:24.867 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1230, Count: 173, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\UpdateFramework\profile-catalog\component_profiles.json, EstimatedImpact: 0%

2025-11-25T17:49:24.867 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 885, Count: 293, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T17:49:24.867 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 631, Count: 127, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-25T17:49:24.867 ProcessImageName: sdiagnhost.exe, Pid: 24772, TotalTime: 618, Count: 43, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wad78daf4#\f2e9e298131866baab3f1fccb4eae979\Microsoft.Windows.Diagnosis.SDHost.ni.dll, EstimatedImpact: 41%

2025-11-25T17:49:24.867 ProcessImageName: RuntimeBroker.exe, Pid: 17216, TotalTime: 571, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 37%

2025-11-25T17:49:24.867 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 465, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T17:49:24.867 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 405, Count: 52, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-25T17:49:24.867 ProcessImageName: WmiPrvSE.exe, Pid: 27408, TotalTime: 390, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf->(UTF-16LE), EstimatedImpact: 36%

2025-11-25T17:49:24.869 ProcessImageName: taskhostw.exe, Pid: 25320, TotalTime: 270, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 16%

2025-11-25T17:49:24.869 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 240, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T17:49:24.869 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 196, Count: 54, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-25T17:49:24.869 ProcessImageName: taskhostw.exe, Pid: 23536, TotalTime: 182, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\Temp\SDIAG_4ae9f5b2-b100-4be5-972c-55f153efb2de\result\results.xsl, EstimatedImpact: 0%

2025-11-25T17:49:24.869 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 180, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\desktop.ini->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T17:49:24.890 [Engine] RSIG_UNLOADENGINE, 00007FFE4C3EA660, err=0x0

2025-11-25T17:49:24.915 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2EBD876A-1A5A-41D2-9E4C-C5260E96DD5A} removed

2025-11-25T17:49:24.960 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-25T17:49:24.968 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-25T17:49:24.968 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-25T17:49:24.968 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-25T17:49:24.968 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-25T17:49:24.968 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-25T17:49:24.968 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-25T17:49:24.972 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-25T17:49:24.972 [RTP] Duplicating the current plugin configuration object...

2025-11-25T17:49:24.972 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-25T17:49:24.972 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-25T17:49:24.972 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-25T17:49:24.972 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-25T17:49:24.972 [RTP] No config change detected. Not updating plugin configuration.

2025-11-25T17:49:24.972 [RTP] No config changes found. No configuration switch.

2025-11-25T17:49:24.972 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-25T17:49:24.972 [RTP] Duplicating the current plugin configuration object...

2025-11-25T17:49:24.972 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-25T17:49:24.972 [RTP] Updating plugin configuration due to recent config changes (0x2) ...

2025-11-25T17:49:24.972 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-25T17:49:24.972 [RTP] No config change detected. Not updating plugin configuration.

2025-11-25T17:49:24.972 [RTP] No config changes found. No configuration switch.

2025-11-25T17:49:24.972 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0

2025-11-25T17:49:24.972 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-25T17:49:24.972 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-25T17:49:24.972 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-25T17:49:24.973 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-25T17:49:24.973 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-25T17:49:24.973 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-25T17:49:24.973 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-25T17:49:24.973 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-25T17:49:24.973 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-25T17:49:24.973 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-25T17:49:24.973 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-25T17:49:24.973 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-25T17:49:24.973 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-25T17:49:24.973 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-25T17:49:24.973 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-25T17:49:24.973 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T17:49:24.975 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T17:49:24.977 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T17:49:24.979 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T17:49:24.981 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T17:49:24.985 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 29148852(ms) from now at 02:55 (01:55 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-25T17:49:26.499 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-25T17:49:26.503 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-25T17:49:26.504 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-25T17:49:27.506 [RTP] Duplicating the current plugin configuration object...

2025-11-25T17:49:27.506 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-25T17:49:27.506 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-25T17:49:27.506 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-25T17:49:27.506 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-25T17:49:30.491 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-25T17:49:30.491 [Cloud] Start of cloud request. Passive mode: 0

2025-11-25T17:49:30.491 [Cloud] Queued cloud request.

2025-11-25T17:49:30.491 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-25T17:49:30.491 [Cloud] Dequeued cloud request.

2025-11-25T17:49:30.491 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-25T17:49:31.070 [Cloud] End of cloud request.

2025-11-25T17:49:31.584 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-25T17:49:41.184 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-25T17:49:41.185 Process scan (postsignatureupdatescan) completed.

2025-11-25T17:50:30.843 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #296444, FileId: 0x7000000031c4a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T17:52:08.055 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #296509, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T17:52:08.060 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #296510, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T17:52:18.067 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #296517, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T17:52:18.068 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #296518, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T17:52:18.071 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #296519, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T17:52:18.073 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #296520, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T17:54:24.417 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-25T17:58:42.868 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T18:05:31.284 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #296893, FileId: 0x60000000328ca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T18:10:19.919 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #297373, FileId: 0xbb00000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T18:13:47.864 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T18:20:31.830 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #297451, FileId: 0x7000000032ece, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T18:28:52.856 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T18:35:31.833 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #298167, FileId: 0x60000000340bf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T18:43:57.864 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T18:45:50.690 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #298891, FileId: 0xf7000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T18:46:40.170 Bm signature throttled:0x00002db31bed458f

2025-11-25T18:50:32.115 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #298953, FileId: 0x230000000384d6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T18:52:05.268 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #298959, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T18:52:05.271 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #298960, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T18:52:15.273 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #298965, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T18:52:15.277 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #298966, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T18:52:15.277 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #298967, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T18:59:02.852 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T19:05:32.351 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #299139, FileId: 0x2f00000005738a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T19:14:07.840 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T19:20:33.172 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #299616, FileId: 0x2c0000000591e3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T19:29:12.835 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T19:35:34.174 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #299731, FileId: 0x1e00000005da31, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T19:44:17.836 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T19:45:41.102 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #299949, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T19:47:52.531 Bm signature throttled:0x0000fab3228bcd4d

2025-11-25T19:49:24.364 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1653, Count: 75, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 93%

2025-11-25T19:49:24.364 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1287, Count: 87, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\b59aa92f-1de6-473f-8851-1a4285c2e02e.tmp, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1035, Count: 144, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\plugins\configurations\2df08941e25c289a65b8c3e373220a10->(Base64), EstimatedImpact: 2%

2025-11-25T19:49:24.365 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 787, Count: 53, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\4891e36a-69d5-4a65-b896-183fa85e4345.tmp, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: WmiPrvSE.exe, Pid: 6860, TotalTime: 601, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89%

2025-11-25T19:49:24.365 ProcessImageName: RuntimeBroker.exe, Pid: 18756, TotalTime: 588, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 30%

2025-11-25T19:49:24.365 ProcessImageName: SecurityHealthHost.exe, Pid: 9956, TotalTime: 255, Count: 48, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 95%

2025-11-25T19:49:24.365 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 211, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: taskhostw.exe, Pid: 17088, TotalTime: 195, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 10%

2025-11-25T19:49:24.365 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 165, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6CC6FFDB826FC7EA06ED87CB7060C764, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: WmiPrvSE.exe, Pid: 26104, TotalTime: 138, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 100%

2025-11-25T19:49:24.365 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 91, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 90, Count: 86, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\config.json, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: taskhostw.exe, Pid: 7020, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 14%

2025-11-25T19:49:24.365 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 14%

2025-11-25T19:49:24.365 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\235dc3ed-83ef-4bf5-b29b-ac67617855fb.tmp, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: FileCoAuth.exe, Pid: 528, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 14%

2025-11-25T19:49:24.365 ProcessImageName: StoreDesktopExtension.exe, Pid: 19820, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\windowsZones.res, EstimatedImpact: 0%

2025-11-25T19:49:24.365 ProcessImageName: updater.exe, Pid: 13292, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9fb9ca0b-dd28-45b5-af8e-668144abfcee.tmp, EstimatedImpact: 0%

2025-11-25T19:50:35.098 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #300002, FileId: 0x1e00000005fdb8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T19:52:06.731 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #300028, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T19:52:06.744 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #300029, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T19:52:16.737 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #300037, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T19:52:16.747 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #300039, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T19:59:22.838 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T20:01:45.668 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #300259, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T20:03:18.646 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #300335, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T20:05:36.081 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #300349, FileId: 0x32000000061eba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T20:14:27.830 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T20:20:36.915 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #300658, FileId: 0x1600000005e2c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T20:21:25.943 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\Nucleus-2025-11-25.1547.6908.3.aodl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #300731, FileId: 0xb400000000a655, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T20:21:26.018 Bm signature throttled:0x0000fab3228bcd4d

2025-11-25T20:29:32.822 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T20:35:38.114 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #300894, FileId: 0x25000000061cdb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T20:44:37.818 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T20:50:38.101 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #301027, FileId: 0xce0000000263fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T20:52:05.307 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #301029, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T20:52:05.314 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #301030, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T20:52:15.316 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #301036, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T20:52:15.326 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #301037, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T20:54:37.179 Bm signature throttled:0x0000fab3228bcd4d

2025-11-25T20:59:42.809 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T21:04:25.656 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #301429, FileId: 0xf9000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T21:05:39.237 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #301441, FileId: 0x38000000061ce5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T21:14:47.806 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T21:20:40.472 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #301766, FileId: 0x1200000006405e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T21:29:52.805 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T21:35:41.335 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #301919, FileId: 0x3b000000061cfe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T21:44:57.809 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T21:49:24.343 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2764, Count: 172, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\c494c4c9-2eae-41a3-8913-93397517ac32.tmp, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1764, Count: 107, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\4891e36a-69d5-4a65-b896-183fa85e4345.tmp, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1653, Count: 75, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 93%

2025-11-25T21:49:24.343 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 1605, Count: 180, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1035, Count: 144, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\plugins\configurations\2df08941e25c289a65b8c3e373220a10->(Base64), EstimatedImpact: 2%

2025-11-25T21:49:24.343 ProcessImageName: WmiPrvSE.exe, Pid: 6860, TotalTime: 601, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89%

2025-11-25T21:49:24.343 ProcessImageName: RuntimeBroker.exe, Pid: 18756, TotalTime: 588, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 30%

2025-11-25T21:49:24.343 ProcessImageName: SecurityHealthHost.exe, Pid: 9956, TotalTime: 255, Count: 48, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 95%

2025-11-25T21:49:24.343 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 240, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6CC6FFDB826FC7EA06ED87CB7060C764, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 212, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 211, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 195, Count: 130, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: taskhostw.exe, Pid: 17088, TotalTime: 195, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 10%

2025-11-25T21:49:24.343 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 182, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 181, Count: 36, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\Nucleus-2025-11-25.2021.26396.1.odl, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 151, Count: 16, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 22364, TotalTime: 150, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 2%

2025-11-25T21:49:24.343 ProcessImageName: WmiPrvSE.exe, Pid: 26104, TotalTime: 138, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 100%

2025-11-25T21:49:24.343 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 136, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\3b8ad4e5-2ee1-4654-bae5-f2052eba115a.tmp, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 106, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\config.json, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: svchost.exe, Pid: 5108, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT7698.tmp, EstimatedImpact: 1%

2025-11-25T21:49:24.343 ProcessImageName: taskhostw.exe, Pid: 10852, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 2%

2025-11-25T21:49:24.343 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 14%

2025-11-25T21:49:24.343 ProcessImageName: taskhostw.exe, Pid: 7020, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 14%

2025-11-25T21:49:24.343 ProcessImageName: svchost.exe, Pid: 13332, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_20108_1626344050\BIT6405.tmp, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: svchost.exe, Pid: 2424, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_1535748200\BIT6C51.tmp, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: FileCoAuth.exe, Pid: 528, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 14%

2025-11-25T21:49:24.343 ProcessImageName: StoreDesktopExtension.exe, Pid: 19820, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\windowsZones.res, EstimatedImpact: 0%

2025-11-25T21:49:24.343 ProcessImageName: updater.exe, Pid: 13292, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9fb9ca0b-dd28-45b5-af8e-668144abfcee.tmp, EstimatedImpact: 0%

2025-11-25T21:50:42.258 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #302217, FileId: 0x1a000000067716, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T21:52:05.851 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #302254, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T21:52:05.854 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #302255, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T21:52:15.854 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #302263, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T21:52:15.859 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #302264, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T22:00:02.797 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T22:05:42.946 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #302564, FileId: 0x12000000069dd4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T22:15:07.796 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T22:20:43.869 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #302909, FileId: 0xe00000006b8af, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T22:21:40.446 Bm signature throttled:0x0000fab3228bcd4d

2025-11-25T22:30:12.799 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T22:35:44.735 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #303217, FileId: 0x1700000006df6d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T22:45:17.792 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T22:50:45.530 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #303390, FileId: 0x1900000006adb9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T22:52:06.412 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #303394, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T22:52:06.416 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #303395, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T22:52:16.414 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #303400, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T22:52:16.415 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #303401, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T22:52:16.419 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #303402, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T22:52:16.420 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #303403, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T23:00:22.799 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T23:05:46.198 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #303583, FileId: 0x1400000006a918, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T23:15:27.799 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T23:20:47.136 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #303999, FileId: 0x1c0000000686b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T23:30:32.788 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T23:35:48.168 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #304113, FileId: 0x18000000065770, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T23:45:37.787 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-25T23:49:24.353 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 5310, Count: 666, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3711, Count: 259, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\c494c4c9-2eae-41a3-8913-93397517ac32.tmp, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2427, Count: 161, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\4891e36a-69d5-4a65-b896-183fa85e4345.tmp, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1653, Count: 75, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 93%

2025-11-25T23:49:24.353 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1081, Count: 146, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\cache\httpclient\0fb243ded9649ae6d18059c674a4ae00, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: WmiPrvSE.exe, Pid: 6860, TotalTime: 601, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89%

2025-11-25T23:49:24.353 ProcessImageName: RuntimeBroker.exe, Pid: 18756, TotalTime: 588, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 30%

2025-11-25T23:49:24.353 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 360, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6CC6FFDB826FC7EA06ED87CB7060C764, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 287, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: SecurityHealthHost.exe, Pid: 9956, TotalTime: 255, Count: 48, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 95%

2025-11-25T23:49:24.353 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 240, Count: 155, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 211, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\Nucleus-2025-11-25.2021.26396.1.odl, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 211, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 211, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 197, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: taskhostw.exe, Pid: 17088, TotalTime: 195, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 10%

2025-11-25T23:49:24.353 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 180, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\config.json, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: backgroundTaskHost.exe, Pid: 16432, TotalTime: 165, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1764097670->(UTF-16LE), EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 165, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\Public\Desktop\Microsoft Edge.lnk, EstimatedImpact: 8%

2025-11-25T23:49:24.353 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 22364, TotalTime: 150, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 2%

2025-11-25T23:49:24.353 ProcessImageName: WmiPrvSE.exe, Pid: 26104, TotalTime: 138, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 100%

2025-11-25T23:49:24.353 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 136, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 136, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\3b8ad4e5-2ee1-4654-bae5-f2052eba115a.tmp, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: backgroundTaskHost.exe, Pid: 25376, TotalTime: 105, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000045\1764114229, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6908, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-25T23:49:24.353 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-25T23:49:24.354 ProcessImageName: svchost.exe, Pid: 5108, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT7698.tmp, EstimatedImpact: 1%

2025-11-25T23:49:24.354 ProcessImageName: taskhostw.exe, Pid: 10852, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 2%

2025-11-25T23:49:24.354 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 0%

2025-11-25T23:49:24.354 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 14%

2025-11-25T23:49:24.354 ProcessImageName: taskhostw.exe, Pid: 7020, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 14%

2025-11-25T23:49:24.354 ProcessImageName: svchost.exe, Pid: 13332, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_20108_1626344050\BIT6405.tmp, EstimatedImpact: 0%

2025-11-25T23:49:24.354 ProcessImageName: svchost.exe, Pid: 2424, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_1535748200\BIT6C51.tmp, EstimatedImpact: 0%

2025-11-25T23:49:24.354 ProcessImageName: StoreDesktopExtension.exe, Pid: 19820, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\windowsZones.res, EstimatedImpact: 0%

2025-11-25T23:49:24.354 ProcessImageName: FileCoAuth.exe, Pid: 528, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 14%

2025-11-25T23:49:24.354 ProcessImageName: updater.exe, Pid: 13292, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\9fb9ca0b-dd28-45b5-af8e-668144abfcee.tmp, EstimatedImpact: 0%

2025-11-25T23:49:24.354 ProcessImageName: updater.exe, Pid: 21912, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\5186f933-f33e-44ee-96fb-4ea3b8e7bed9.tmp, EstimatedImpact: 0%

2025-11-25T23:50:49.187 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #304877, FileId: 0x2e000000009c4f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T23:52:07.129 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #304896, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T23:52:07.133 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #304897, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T23:52:17.141 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #304904, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-25T23:52:17.145 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #304905, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T00:00:42.791 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T00:05:50.131 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #305076, FileId: 0x1b00000006aa6d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T00:15:47.787 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T00:17:07.793 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3

2025-11-26T00:17:07.793 Job Notification: New process added to job (17680)

2025-11-26T00:17:07.796 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched

2025-11-26T00:17:07.798 Aggressive catchup quick scan threshold: 814425338517 / 25920000000000

2025-11-26T00:17:07.800 Job Notification: New process added to job (5160)

2025-11-26T00:17:07.807 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:17680] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:5160]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-26T00:17:07.852 Job Notification: New process added to job (8368)

2025-11-26T00:17:07.855 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched

2025-11-26T00:17:07.856 Job Notification: New process added to job (14436)

2025-11-26T00:17:07.863 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:8368] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:14436]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-26T00:17:07.909 Job Notification: New process added to job (19644)

2025-11-26T00:17:07.911 Task(GetDeviceTicket -AccessKey E75E3022-661C-5DD8-43DF-05CC4E656881 ) launched as network service

2025-11-26T00:17:08.313 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-26T00:17:08.313 [RTP] Duplicating the current plugin configuration object...

2025-11-26T00:17:08.313 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-26T00:17:08.313 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-26T00:17:08.313 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-26T00:17:08.313 [RTP] No config change detected. Not updating plugin configuration.

2025-11-26T00:17:08.313 [RTP] No config changes found. No configuration switch.

2025-11-26T00:17:08.313 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-26T00:17:08.388 Job Notification: Process exited from job (19644)

2025-11-26T00:17:08.636 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-26T00:17:08.636 [Cloud] Start of cloud request. Passive mode: 0

2025-11-26T00:17:08.636 [Cloud] Queued cloud request.

2025-11-26T00:17:08.636 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-26T00:17:08.636 [Cloud] Dequeued cloud request.

2025-11-26T00:17:08.636 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-26T00:17:08.637 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0

2025-11-26T00:17:08.637 [Cloud] Start of cloud request. Passive mode: 0

2025-11-26T00:17:08.637 [Cloud] Queued cloud request.

2025-11-26T00:17:08.637 [Cloud] Dequeued cloud request.

2025-11-26T00:17:08.638 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-26T00:17:08.719 [Cloud] End of cloud request.

2025-11-26T00:17:08.765 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-26T00:17:08.765 [Cloud] End of cloud request.

2025-11-26T00:17:09.148 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T00:17:38.552 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\06709389-DAC2-4F60-9609-B34BFAA1722F4070.1dc5e6a11a93e9c

2025-11-26T00:17:38.584 Verifying engine and signature files (source: 0) ...

2025-11-26T00:17:38.584 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{73BB5CF7-D706-4178-9948-0AA63023B984}\mpengine.dll] due to PPL.

2025-11-26T00:17:38.584 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{73BB5CF7-D706-4178-9948-0AA63023B984}\mpasbase.vdm] (file in cache)

2025-11-26T00:17:38.584 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{73BB5CF7-D706-4178-9948-0AA63023B984}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-26T00:17:38.593 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{73BB5CF7-D706-4178-9948-0AA63023B984}\mpasdlta.vdm]

2025-11-26T00:17:38.594 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{73BB5CF7-D706-4178-9948-0AA63023B984}\mpavbase.vdm] (file in cache)

2025-11-26T00:17:38.594 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{73BB5CF7-D706-4178-9948-0AA63023B984}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-26T00:17:38.604 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{73BB5CF7-D706-4178-9948-0AA63023B984}\mpavdlta.vdm]

2025-11-26T00:17:38.675 [Engine] IsHybridMode: 0

2025-11-26T00:17:38.676 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-26T00:17:38.686 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-D9982FA8C20979F4A3F9731F727CBE7BBA9304D8.bin): 0x00000002

2025-11-26T00:17:38.688 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-D9982FA8C20979F4A3F9731F727CBE7BBA9304D8.bin)

2025-11-26T00:17:38.688 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-26T00:17:38.688 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-26T00:17:38.688 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-26T00:17:38.688 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-26T00:17:44.210 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-26T00:17:44.210 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-26T00:17:44.217 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7225A660, lRefCount: 5, hr=0

2025-11-26T00:17:44.217 [Engine] New active engine 00007FFE6F7CA660 replacing engine 00007FFE7225A660. Number of active engines: 2

2025-11-26T00:17:44.222 EngineInit:Global ASOC is enabled

2025-11-26T00:17:44.222 EngineInit:ASOO is enabled for developer volumes

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.253 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.254 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T00:17:44.255 MpWriteUupSignatureVersion 1.441.492.0, hr = 0

2025-11-26T00:17:44.257 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-26T00:17:44.270 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-26T00:17:44.271 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-26T00:17:44.271 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-26T00:17:44.271 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-26T00:17:44.271 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-26T00:17:44.285 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-26T00:17:44.285 [Plugin] Initializing RTP plugin state...

2025-11-26T00:17:44.285 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-26T00:17:44.285 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 25 - 2025 18:49:24

Last Perf: 11 - 25 - 2025 18:49:24

First RTP Scan: 11 - 25 - 2025 18:49:24

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:799

  Misses:5747

BM Queue:0,46,0

  Proc:0,37,0

  File:0,46,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,2,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:305402

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1634007770

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:18

  TotalStreamCon:12493

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:1342026

   TotalHits:2232719

   InstanceCacheInserts:101205

   InstanceCacheUpdates:0

   InstanceCacheDeletes:77465

   InstanceCacheHits:4836

   InstanceCacheMisses:392637

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (935/971)

   Success: 971, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-26T00:17:44.285 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{73BB5CF7-D706-4178-9948-0AA63023B984}

2025-11-26T00:17:44.286 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B24AC3F-8833-4C83-916A-FE6049A12D7A}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B24AC3F-8833-4C83-916A-FE6049A12D7A}\mpasbase.vdm in use, hr=0x80070020

2025-11-26T00:17:44.286 [SCC][CID=801493734_25164] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-26T00:17:44.286 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-26T00:17:44.286 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-26T00:17:44.286 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-26T00:17:44.287 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-26T00:17:44.287 MdCoreSvc is supported in this platform and OS

2025-11-26T00:17:44.287 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-26-2025 00:17:44

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-26-2025 00:17:44

2025-11-26T00:17:44.290 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-26T00:17:44.290 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-26T00:17:44.291 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-26T00:17:44.291 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-26-2025 00:17:44

END TDT(U) telemetry



2025-11-26T00:17:44.293 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T00:17:44.293 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-26T00:17:44.293 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-26T00:17:44.293 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-26T00:17:44.293 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-26T00:17:44.294 MdCoreSvc is supported in this platform and OS

Signature updated on 11-26-2025 00:17:44

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.492.0

AV Signature Version: 1.441.492.0

************************************************************

2025-11-26T00:17:44.295 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-26T00:17:44.295 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\06709389-DAC2-4F60-9609-B34BFAA1722F4070.1dc5e6a11a93e9c

2025-11-26T00:17:44.313 Process scan (postsignatureupdatescan) started.

2025-11-26T00:17:44.341 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-26T00:17:44.342 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

Signature updated via MicrosoftUpdateServer on 11-26-2025 00:17:44

************************************************************

2025-11-26T00:17:44.379 Job Notification: Process exited from job (8368)

2025-11-26T00:17:44.380 Job Notification: Process exited from job (14436)

2025-11-26T00:17:44.411 Job Notification: Process exited from job (17680)

2025-11-26T00:17:44.412 Job Notification: Process exited from job (5160)

2025-11-26T00:17:44.484 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-26T00:17:44.484 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-26T00:17:44.485 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-26T00:17:44.485 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-26T00:17:44.485 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-26T00:17:44.486 [Engine] Engine 00007FFE7225A660 no longer in use. Number of active engines: 1

2025-11-26T00:17:44.486 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-26T00:17:44.486 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-26T00:17:44.652 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 5310, Count: 666, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-26T00:17:44.652 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3876, Count: 280, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\c494c4c9-2eae-41a3-8913-93397517ac32.tmp, EstimatedImpact: 0%

2025-11-26T00:17:44.652 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2577, Count: 173, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\4891e36a-69d5-4a65-b896-183fa85e4345.tmp, EstimatedImpact: 0%

2025-11-26T00:17:44.652 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1653, Count: 75, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 93%

2025-11-26T00:17:44.652 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1081, Count: 146, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\cache\httpclient\0fb243ded9649ae6d18059c674a4ae00, EstimatedImpact: 0%

2025-11-26T00:17:44.652 ProcessImageName: WmiPrvSE.exe, Pid: 6860, TotalTime: 601, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89%

2025-11-26T00:17:44.652 ProcessImageName: RuntimeBroker.exe, Pid: 18756, TotalTime: 588, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 30%

2025-11-26T00:17:44.652 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 360, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6CC6FFDB826FC7EA06ED87CB7060C764, EstimatedImpact: 0%

2025-11-26T00:17:44.652 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 302, Count: 27, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T00:17:44.652 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 285, Count: 163, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-26T00:17:44.652 ProcessImageName: SecurityHealthHost.exe, Pid: 9956, TotalTime: 255, Count: 48, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 95%

2025-11-26T00:17:44.652 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 226, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-26T00:17:44.652 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 211, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\Nucleus-2025-11-25.2021.26396.1.odl, EstimatedImpact: 0%

2025-11-26T00:17:44.652 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 211, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-26T00:17:44.652 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 197, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-26T00:17:44.652 ProcessImageName: taskhostw.exe, Pid: 17088, TotalTime: 195, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 10%

2025-11-26T00:17:44.666 [Engine] RSIG_UNLOADENGINE, 00007FFE7225A660, err=0x0

2025-11-26T00:17:44.685 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B24AC3F-8833-4C83-916A-FE6049A12D7A} removed

2025-11-26T00:17:44.776 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-26T00:17:44.784 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-26T00:17:44.784 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-26T00:17:44.784 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-26T00:17:44.785 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-26T00:17:44.785 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-26T00:17:44.785 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-26T00:17:44.787 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-26T00:17:44.787 [RTP] Duplicating the current plugin configuration object...

2025-11-26T00:17:44.787 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-26T00:17:44.787 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-26T00:17:44.787 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-26T00:17:44.788 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-26T00:17:44.788 [RTP] No config change detected. Not updating plugin configuration.

2025-11-26T00:17:44.788 [RTP] No config changes found. No configuration switch.

2025-11-26T00:17:44.788 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-26T00:17:44.788 [RTP] Duplicating the current plugin configuration object...

2025-11-26T00:17:44.788 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-26T00:17:44.788 [RTP] Updating plugin configuration due to recent config changes (0x2) ...

2025-11-26T00:17:44.788 [RTP] No config change detected. Not updating plugin configuration.

2025-11-26T00:17:44.788 [RTP] No config changes found. No configuration switch.

2025-11-26T00:17:44.788 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0

2025-11-26T00:17:44.788 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-26T00:17:44.788 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-26T00:17:44.788 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-26T00:17:44.788 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-26T00:17:44.788 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-26T00:17:44.788 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-26T00:17:44.788 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-26T00:17:44.788 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-26T00:17:44.788 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-26T00:17:44.788 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-26T00:17:44.788 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-26T00:17:44.788 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-26T00:17:44.788 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-26T00:17:44.788 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-26T00:17:44.788 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-26T00:17:44.788 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-26T00:17:44.789 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T00:17:44.790 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T00:17:44.792 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T00:17:44.795 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T00:17:44.798 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 12171845(ms) from now at 04:40 (03:40 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-26T00:17:44.798 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T00:17:46.315 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-26T00:17:46.318 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-26T00:17:46.319 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-26T00:17:47.321 [RTP] Duplicating the current plugin configuration object...

2025-11-26T00:17:47.321 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-26T00:17:47.321 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-26T00:17:47.321 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-26T00:17:47.321 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-26T00:17:49.686 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-26T00:17:49.686 [Cloud] Start of cloud request. Passive mode: 0

2025-11-26T00:17:49.686 [Cloud] Queued cloud request.

2025-11-26T00:17:49.686 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-26T00:17:49.687 [Cloud] Dequeued cloud request.

2025-11-26T00:17:49.687 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-26T00:17:50.058 [Cloud] End of cloud request.

2025-11-26T00:17:50.569 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T00:17:58.802 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-26T00:17:58.803 Process scan (postsignatureupdatescan) completed.

2025-11-26T00:20:51.250 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #305663, FileId: 0x14000000023312, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T00:22:44.254 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-26T00:30:52.794 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T00:35:51.887 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #306209, FileId: 0x1a00000006aaa8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T00:45:57.788 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T00:50:52.631 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #306367, FileId: 0x1b00000006ae63, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T00:52:07.231 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #306383, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T00:52:07.235 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #306384, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T00:52:17.238 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #306389, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T00:52:17.242 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #306390, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T01:01:02.783 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T01:05:53.241 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #306561, FileId: 0x2a000000068b5d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T01:16:07.780 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T01:20:54.207 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #306950, FileId: 0x85000000027a35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T01:21:43.542 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T01:31:12.774 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T01:35:54.603 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #307052, FileId: 0x2900000006dedc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T01:39:45.621 [AutoPurge] Verification Routine tasks have started.

2025-11-26T01:39:45.621 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-26T01:39:45.629 [AutoPurge] Routine task for Cache Maintenance has started.

2025-11-26T01:39:45.629 [AutoPurge] Routine task for Cache Maintenance ...

2025-11-26T01:39:45.629 [AutoPurge] Routine task for MpSFCBuild ...

2025-11-26T01:39:45.629 [AutoPurge] MpCmIsBuildCompleted() - S_OK

2025-11-26T01:39:45.629 [AutoPurge] MpSignalMaintenanceMode ...

2025-11-26T01:39:45.631 [AutoPurge] Cleanup Routine tasks have started.

2025-11-26T01:39:45.635 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0)

2025-11-26T01:39:45.635 [AutoPurge] Purged 0 expired detection item(s) from a total of 0.

2025-11-26T01:39:45.635 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds)

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:65538

Start time:11-26-2025 01:39:45

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-26-2025 01:39:45

2025-11-26T01:39:45.636 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:70967AD6-8780-4EBF-9A92-55F2386D2B42, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1)

2025-11-26T01:39:45.636 Scheduled scan with Id 70967AD6-8780-4EBF-9A92-55F2386D2B42 configured CPU priority: normal (LowCpuPriority: 0)

2025-11-26T01:39:45.638 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build.

2025-11-26T01:39:45.638 [SFC] System file cache build is not needed (already completed)

2025-11-26T01:39:45.639 QuickScan:ScanID:70967AD6-8780-4EBF-9A92-55F2386D2B42: Quick Scan skipped since it already ran during the past 7 days

2025-11-26T01:39:45.639 QuickScan:ScanID:70967AD6-8780-4EBF-9A92-55F2386D2B42: Quick scan finished with error 1223

2025-11-26T01:39:45.639 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ...

2025-11-26T01:39:45.639 OnDemandScanWorker: Scan Cancelled! scanId:70967AD6-8780-4EBF-9A92-55F2386D2B42, hr = 0x80508018

2025-11-26T01:39:45.639 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0 ...

2025-11-26T01:39:45.639 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0 ...

!ERROR

Begin Quick Scan

Scan ID:{70967AD6-8780-4EBF-9A92-55F2386D2B42}

Scan Source:1

Start Time:11-26-2025 01:39:45

Unsuccessful Scan

Return Code:1223

************************************************************



2025-11-26T01:39:45.640 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ...

2025-11-26T01:39:45.642 [AutoPurge] Cleanup Routine tasks have ended.

2025-11-26T01:39:45.691 EnsureProtectedFolderAcls(), hr = 0x0

2025-11-26T01:39:45.693 [AutoPurge] MpReinforceServiceAcls: 0

2025-11-26T01:39:45.699 Engine:Setting original file name "WIARPC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiarpc.dll.mui_0c913b87", hr=0x0

2025-11-26T01:39:45.704 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0

2025-11-26T01:39:45.706 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed.

2025-11-26T01:39:45.708 [AutoPurge] Verification Routine tasks have ended.

2025-11-26T01:39:45.722 Engine:Setting original file name "nlsbres.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..ocale-nls.resources_31bf3856ad364e35_10.0.26100.4484_nb-no_339b02f7f61c146e\winnlsres.dll.mui", hr=0x0

2025-11-26T01:39:45.966 Engine:Setting original file name "IEXPLORE.EXE" for "c:\program files (x86)\internet explorer\en-us\iexplore.exe.mui", hr=0x0

2025-11-26T01:39:45.995 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_en-us_1258b52c940aadb7_winload.efi.mui_35ee487d", hr=0x0

2025-11-26T01:39:46.441 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sr-..-rs_d1943ecc8317ab66_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-26T01:39:46.578 Engine:Setting original file name " " for "c:\program files (x86)\steam\bin\cef\cef.win7x64\dxcompiler.dll", hr=0x0

2025-11-26T01:39:46.622 Engine:Setting original file name "dual_engine_adapter.dll" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\dual_engine_adapter_x64.dll", hr=0x0

2025-11-26T01:39:46.752 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\winsxs\wow64_microsoft-windows-bcp47languages_31bf3856ad364e35_10.0.26100.7019_none_40ac55a9bb1ab239\bcp47langs.dll", hr=0x0

2025-11-26T01:39:46.764 Engine:Setting original file name "MAPI32.DLL.MUI" for "c:\windows\system32\nb-no\mapistub.dll.mui", hr=0x0

2025-11-26T01:39:46.912 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-26T01:39:46.946 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_ar-sa_af75f4ef024a79a1_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-26T01:39:47.012 Engine:Setting original file name "Apphelp" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a4bb088d5aa4193f97a4bdef0c1f8c71\apphelp.dll.mui", hr=0x0

2025-11-26T01:39:47.061 Engine:Setting original file name "F12Chooser.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-ie-iechooser.resources_31bf3856ad364e35_11.0.26100.1_nb-no_a7630c027f26ac69\iechooser.exe.mui", hr=0x0

2025-11-26T01:39:47.095 Engine:Setting original file name "THEMESERVICE.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-themeservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_5e5bf64d5b3ca824_themeservice.dll.mui_9e71f1ab", hr=0x0

2025-11-26T01:39:47.125 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_ad141a64b8fd6038_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:47.201 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\wow64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.26100.712_none_5cfec91758ee0662\windows.security.credentials.ui.credentialpicker.dll", hr=0x0

2025-11-26T01:39:47.251 Engine:Setting original file name "mavinject32.exe" for "c:\windows\winsxs\wow64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_592d553ad6e77100\mavinject.exe", hr=0x0

2025-11-26T01:39:47.375 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_bfcde09794ad7074_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-26T01:39:47.381 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\zh-cn\memtest.efi.mui", hr=0x0

2025-11-26T01:39:47.488 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_nb-no_022ea2e874b2cab6_winresume.efi.mui_f412814e", hr=0x0

2025-11-26T01:39:47.547 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lt-lt_11cd7cc1c62eb609_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:47.654 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-26T01:39:47.659 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-26T01:39:47.659 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-26T01:39:47.813 Engine:Setting original file name "WmiApSrv.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiapsrv.exe.mui_b1567840", hr=0x0

2025-11-26T01:39:47.866 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kk-kz_bb9a512b689c9b87_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:47.892 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_b5793645604cae79_memtest.efi.mui_71e15c22", hr=0x0

2025-11-26T01:39:47.906 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_he-il_3abd6f82e93c03e5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:47.914 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.26100.1_en-us_c3d82ef5c0380efa_wudfpf.sys.mui_f61e9e86", hr=0x0

2025-11-26T01:39:48.156 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaihdrx.dll", hr=0x0

2025-11-26T01:39:48.286 Engine:Setting original file name "l3codec.acm.mui" for "c:\windows\system32\nb-no\l3codeca.acm.mui", hr=0x0

2025-11-26T01:39:48.394 Engine:Setting original file name "w32topl.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_10.0.26100.1_none_cbd0eec659c2eb5c_w32topl.dll_1a0f388b", hr=0x0

2025-11-26T01:39:48.408 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ms-my_6f80e6fda2cebe8f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:48.675 Engine:Setting original file name "NVPTXJITCOMPILER32.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvptxjitcompiler64.dll", hr=0x0

2025-11-26T01:39:48.710 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5de87d4a39ffc584310f0b06dff9fcd0\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-26T01:39:48.782 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_38f499759ea365c4_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:48.841 Engine:Setting original file name "ddputils.lib.mui" for "c:\windows\system32\nb-no\ddputils.dll.mui", hr=0x0

2025-11-26T01:39:48.945 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kn-in_6e7a81f857a45cbe_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:48.976 Engine:Setting original file name "officeimm.odf" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\office.odf", hr=0x0

2025-11-26T01:39:49.165 Engine:Setting original file name ""AcGenral.dll"" for "c:\windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_10.0.26100.7019_none_a8119654a230db44\acgenral.dll", hr=0x0

2025-11-26T01:39:49.242 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sr-..-rs_7327597d7718c882_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:49.254 Engine:Setting original file name "Hyper-V Host Compute Service Diagnostics Tool" for "c:\windows\winsxs\amd64_hyperv-compute-cont..sticstool.resources_31bf3856ad364e35_10.0.26100.1_en-us_61074b8c7d2f38cf\hcsdiag.exe.mui", hr=0x0

2025-11-26T01:39:49.269 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.32530.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-26T01:39:49.304 Engine:Setting original file name "davsvc.dll.mui" for "c:\windows\system32\nb-no\webclnt.dll.mui", hr=0x0

2025-11-26T01:39:49.334 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\nb-no\wsepno.dll.mui", hr=0x0

2025-11-26T01:39:49.346 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x0

2025-11-26T01:39:49.381 Engine:Setting original file name "bootstr.exe.mui" for "c:\windows\system32\nb-no\bootstr.dll.mui", hr=0x0

2025-11-26T01:39:49.398 Engine:Setting original file name "msvcp140_2_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_2_app.dll", hr=0x0

2025-11-26T01:39:49.618 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-libraryloader-l1-1-0.dll", hr=0x0

2025-11-26T01:39:49.624 Engine:Setting original file name "dvsvc.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..rationsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_5c873aff49ea76e6\dcsvc.dll.mui", hr=0x0

2025-11-26T01:39:49.653 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_qps-ploc_5c9773f9ea1ce396_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:49.655 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_cs-cz_7086b4650c9e547c_memtest.efi.mui_71e15c22", hr=0x0

2025-11-26T01:39:49.677 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-26T01:39:49.680 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-26T01:39:49.680 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-26T01:39:49.754 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa78d0db4729269ff4beb393d45ca94a\dnsapi.dll.mui", hr=0x0

2025-11-26T01:39:49.770 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hr-hr_86baa9ad7eed6d52_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:49.810 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ja-jp_ed01f249e53f7235_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-26T01:39:49.813 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-file-l1-1-0.dll", hr=0x0

2025-11-26T01:39:49.839 Engine:Setting original file name "D3DX10.dll" for "c:\windows\system32\d3dx10_43.dll", hr=0x0

2025-11-26T01:39:49.910 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_da-dk_f5abc0a0339bc397_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:50.000 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-conio-l1-1-0.dll", hr=0x0

2025-11-26T01:39:50.124 Engine:Setting original file name "Auto Enrollment DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..utoenroll.resources_31bf3856ad364e35_10.0.26100.1_en-us_b82b35a9c2228d6b\pautoenr.dll.mui", hr=0x0

2025-11-26T01:39:50.215 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\windows\winsxs\amd64_microsoft-textinput-helpers.resources_31bf3856ad364e35_10.0.26100.1_nb-no_2c9a52bac4b766e3\ime_textinputhelpers.dll.mui", hr=0x0

2025-11-26T01:39:50.228 Engine:Setting original file name "Ribbons" for "c:\windows\winsxs\amd64_microsoft-windows-ribbons.resources_31bf3856ad364e35_10.0.26100.1_en-us_f85e1124efc279b5\ribbons.scr.mui", hr=0x0

2025-11-26T01:39:50.268 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_18153ede37451276\memtest.exe.mui", hr=0x0

2025-11-26T01:39:50.312 Engine:Setting original file name "scecli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\978b70ff94ed14c641fe52c5237facec\scecli.dll.mui", hr=0x0

2025-11-26T01:39:50.332 Engine:Setting original file name "mpsdrv.sys.mui" for "c:\windows\winsxs\backup\amd64_networking-mpssvc-drv.resources_31bf3856ad364e35_10.0.26100.1_nb-no_05849dc2762f9d2d_mpsdrv.sys.mui_b2aea3b6", hr=0x0

2025-11-26T01:39:50.351 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-tw_21b451d70c8c2957_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-26T01:39:50.512 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_2b309b875a6f3e1e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:50.580 Engine:Setting original file name "Vulkan Runtime" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\vulkan-1.dll", hr=0x0

2025-11-26T01:39:50.619 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-p..i-ntprint.resources_31bf3856ad364e35_10.0.26100.1_en-us_6ff199c21e8ad886\ntprint.dll.mui", hr=0x0

2025-11-26T01:39:50.680 Engine:Setting original file name "bootstr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..environment-strings_31bf3856ad364e35_10.0.26100.1_none_f575b80d757af501\bootstr.dll", hr=0x0

2025-11-26T01:39:50.708 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_zh-cn_fd81e6b68df3d1a9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:50.881 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-26T01:39:50.963 Engine:Setting original file name "liblzma.dll" for "c:\program files\windowsapps\microsoft.6365217ce6eb4_102.2509.19002.0_x64__8wekyb3d8bbwe\lzma.dll", hr=0x0

2025-11-26T01:39:51.057 Engine:Setting original file name "wuapi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\uus\x86\nb-no\c120e79170c204b0e5f1ece795e86e83\wuapicore.dll.mui", hr=0x0

2025-11-26T01:39:51.120 Engine:Setting original file name "Ontology.dll" for "c:\users\serverpc\appdata\local\nvidia corporation\nvidia app\nvbackend\applicationontology\ontology64.dll", hr=0x0

2025-11-26T01:39:51.255 Engine:Setting original file name "VpnSohDesktop.dll" for "c:\windows\system32\windows.perception.stub.dll", hr=0x0

2025-11-26T01:39:51.332 Engine:Setting original file name "kernel32" for "c:\windows\syswow64\kernel32.dll", hr=0x0

2025-11-26T01:39:51.359 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.549981c3f5f10_4.2308.1005.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-26T01:39:51.548 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_b38289243d899c4c_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:51.621 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_82eb3d34cd19fa50_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:51.762 Engine:Setting original file name "Steamclient.dll" for "c:\program files (x86)\steam\steamclient64.dll", hr=0x0

2025-11-26T01:39:51.831 Engine:Setting original file name "VrdUmde.dll" for "c:\windows\winsxs\amd64_gpuvirtualizationumed_31bf3856ad364e35_10.0.26100.1150_none_17421023ba072774\vrdumed.dll", hr=0x0

2025-11-26T01:39:51.842 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.efi.mui", hr=0x0

2025-11-26T01:39:51.978 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.winmd", hr=0x0

2025-11-26T01:39:52.316 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_lt-lt_ba1ae95b692b9594_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-26T01:39:52.424 Engine:Setting original file name "windows.ui.xaml.resources.win81.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ctui-resourceswin81_31bf3856ad364e35_10.0.26100.1301_none_b7b52abe3d381205_windows.ui.xaml.resources.win81.dll_d426e245", hr=0x0

2025-11-26T01:39:52.565 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-timezone-l1-1-0.dll", hr=0x0

2025-11-26T01:39:52.608 Engine:Setting original file name "jscript9.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\c3275836e276aea69afa458336037853\jscript9legacy.dll.mui", hr=0x0

2025-11-26T01:39:52.921 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x0

2025-11-26T01:39:52.975 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-profile-l1-1-0.dll", hr=0x0

2025-11-26T01:39:53.206 Engine:Setting original file name "Windows.FileExplorer.Common.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\84c8a2171c12d91e854ffb6a27b39453\windows.fileexplorer.common.dll.mui", hr=0x0

2025-11-26T01:39:53.413 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.26100.1_en-us_99a73e6649d69102\ndisimplatcim.dll.mui", hr=0x0

2025-11-26T01:39:53.464 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-26T01:39:53.536 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-localization-l1-2-0.dll", hr=0x0

2025-11-26T01:39:53.596 Engine:Setting original file name "Placeholder.dll" for "c:\windows\winsxs\x86_netfx4-penimc_v0400_b03f5f7f11d50a3a_4.0.15920.102_none_21046749883d249b\penimc_v0400.dll", hr=0x0

2025-11-26T01:39:53.620 Engine:Setting original file name "NvCamera.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\nvcameraallowlisting32.dll", hr=0x0

2025-11-26T01:39:53.872 Engine:Setting original file name ".NET Host Policy -" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\hostpolicy.dll", hr=0x0

2025-11-26T01:39:54.269 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sv-se_cac4b549037c269f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:54.280 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-26T01:39:54.314 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-26T01:39:54.333 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\winsxs\amd64_microsoft-windows-appx-deployment-server_31bf3856ad364e35_10.0.26100.7171_none_fd3893d466902045\applytrustoffline.exe", hr=0x0

2025-11-26T01:39:54.476 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\wow64_microsoft-windows-a..on-logger.resources_31bf3856ad364e35_10.0.26100.1_en-us_a0e09b8ec526451d\aeevts.dll.mui", hr=0x0

2025-11-26T01:39:54.573 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-26T01:39:54.750 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\4f8d3bb436c7\apex_particleschecked_x86.dll", hr=0x0

2025-11-26T01:39:54.829 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_it-it_72537c4985790e22_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:54.951 Engine:Setting original file name "EsclWiaDriver.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_esclwiadriver.dll.mui_d4a5b959", hr=0x0

2025-11-26T01:39:55.071 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_da-dk_be356ba870c91e76\msprivs.dll.mui", hr=0x0

2025-11-26T01:39:55.074 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-26T01:39:55.086 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_es-es_bdfd06f72820647a_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-26T01:39:55.193 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pl-pl\msprivs.dll.mui", hr=0x0

2025-11-26T01:39:55.210 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-26T01:39:55.233 Engine:Setting original file name "rmactivate.exe.mui" for "c:\windows\syswow64\en-us\rmactivate_isv.exe.mui", hr=0x0

2025-11-26T01:39:55.469 Engine:Setting original file name "apex.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\73be2921551d\apex_turbulencefschecked_x86.dll", hr=0x0

2025-11-26T01:39:55.497 Engine:Setting original file name "ScrCons" for "c:\windows\winsxs\amd64_microsoft-windows-w..consumers.resources_31bf3856ad364e35_10.0.26100.1_en-us_5d0e2df387a86d5d\scrcons.exe.mui", hr=0x0

2025-11-26T01:39:55.504 Engine:Setting original file name "PtpProv" for "c:\windows\winsxs\amd64_microsoft-windows-t..-provider.resources_31bf3856ad364e35_10.0.26100.1_en-us_eec70481b215edf0\ptpprov.dll.mui", hr=0x0

2025-11-26T01:39:55.550 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\resources\themes\aero\nb-no\aerolite.msstyles.mui", hr=0x0

2025-11-26T01:39:55.724 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_cd255b4d1be69fe9_winload.efi.mui_35ee487d", hr=0x0

2025-11-26T01:39:55.755 Engine:Setting original file name "pegi.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_en-us_58f534214187451c\pegi.rs.mui", hr=0x0

2025-11-26T01:39:55.761 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-iexpress.resources_31bf3856ad364e35_11.0.26100.1_en-us_f84c0d683fdc407b\wextract.exe.mui", hr=0x0

2025-11-26T01:39:56.211 Engine:Setting original file name "updater.exe" for "c:\program files (x86)\google\update\googleupdate.exe", hr=0x0

2025-11-26T01:39:56.373 Engine:Setting original file name "ServicingBase.dll" for "c:\windows\system32\servicingcommon.dll", hr=0x0

2025-11-26T01:39:56.393 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.exe.mui", hr=0x0

2025-11-26T01:39:56.576 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\vulkan-1.dll", hr=0x0

2025-11-26T01:39:56.625 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_c77eb7b609c47f12\diagpackage.dll.mui", hr=0x0

2025-11-26T01:39:56.742 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\system32\wbem\en-us\netadaptercim.dll.mui", hr=0x0

2025-11-26T01:39:56.765 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\syswow64\nb-no\wextract.exe.mui", hr=0x0

2025-11-26T01:39:56.879 Engine:Setting original file name "NvTelemetry.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvinstallerutil.dll", hr=0x0

2025-11-26T01:39:56.927 Engine:Setting original file name "NvMessageBusBroadcast.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\localsystem\_nvmsgbusbroadcast.dll", hr=0x0

2025-11-26T01:39:57.142 Engine:Setting original file name "NVOPENCL.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvopencl64.dll", hr=0x0

2025-11-26T01:39:57.149 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x0

2025-11-26T01:39:57.221 Engine:Setting original file name "Ribbons" for "c:\windows\system32\nb-no\ribbons.scr.mui", hr=0x0

2025-11-26T01:39:57.376 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_de-de_bb6100e4729f7310\msprivs.dll.mui", hr=0x0

2025-11-26T01:39:57.538 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_en-gb_943f70b729277031_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:57.568 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570\dnsapi.dll.mui", hr=0x0

2025-11-26T01:39:57.570 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x0

2025-11-26T01:39:57.657 Engine:Setting original file name "expediteupdater" for "c:\program files\microsoft update health tools\expediteupdater.exe", hr=0x0

2025-11-26T01:39:57.705 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5fc58c6fab06ca1651cc2f24f6b3294e\dnsapi.dll.mui", hr=0x0

2025-11-26T01:39:57.813 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-26T01:39:57.852 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-26T01:39:57.924 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pt-br\msprivs.dll.mui", hr=0x0

2025-11-26T01:39:57.980 Engine:Setting original file name "vcomp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-26T01:39:58.029 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_pt-br_45b1cef334010120_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-26T01:39:58.076 Engine:Setting original file name "DismProvPS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..ing-management-core_31bf3856ad364e35_10.0.26100.7019_none_c721839bdaa557fd\dismcoreps.dll", hr=0x0

2025-11-26T01:39:58.180 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x0

2025-11-26T01:39:58.215 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.efi", hr=0x0

2025-11-26T01:39:58.218 Engine:Setting original file name "ProfSvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-profsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_63afbc426d007f3f_profsvc.dll.mui_32482e9e", hr=0x0

2025-11-26T01:39:58.323 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2cfe4c864d785675f415b7e6aa962e4\msinfo32.exe.mui", hr=0x0

2025-11-26T01:39:58.543 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\6dfad87d7e49db84e1a96c1c1b32fef6\msidntld.dll.mui", hr=0x0

2025-11-26T01:39:58.558 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7\memtest.exe.mui", hr=0x0

2025-11-26T01:39:58.659 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pa-in_9c6b14ad918eaffd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:58.678 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ar-sa_51090f9ff64b96bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:58.723 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.26100.1_en-us_c94c280205b42295\bubbles.scr.mui", hr=0x0

2025-11-26T01:39:58.945 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\nb-no\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x0

2025-11-26T01:39:58.967 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-console-l1-2-0.dll", hr=0x0

2025-11-26T01:39:58.981 Engine:Setting original file name "SETUP.EXE.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-wow64-legacy.resources_31bf3856ad364e35_10.0.26100.1_nb-no_735ab890ce560efa\setup16.exe.mui", hr=0x0

2025-11-26T01:39:59.133 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x0

2025-11-26T01:39:59.168 Engine:Setting original file name "RarExt.dll" for "c:\program files\winrar\rarext32.dll", hr=0x0

2025-11-26T01:39:59.206 Engine:Setting original file name "pcw.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-pcw_31bf3856ad364e35_10.0.26100.1150_none_4bf8e6d5066a4f9f_pcw.sys_dbeb0bbd", hr=0x0

2025-11-26T01:39:59.299 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\syswow64\nb-no\ieadvpack.dll.mui", hr=0x0

2025-11-26T01:39:59.332 Engine:Setting original file name "EmbyServer.dll" for "c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe", hr=0x0

2025-11-26T01:39:59.440 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-environment-l1-1-0.dll", hr=0x0

2025-11-26T01:39:59.583 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2535f07be6867822893c0bd7f299affd\dwmcore.dll.mui", hr=0x0

2025-11-26T01:39:59.596 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_am-et_12002fbedc3ad139_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:39:59.638 Engine:Setting original file name "mavinject64.exe" for "c:\windows\winsxs\amd64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_4ed8aae8a286af05\mavinject.exe", hr=0x0

2025-11-26T01:39:59.807 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_b1cb38b404e84204\seclogon.dll.mui", hr=0x0

2025-11-26T01:39:59.850 Engine:Setting original file name "AuditPolicyGP.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\1e37baae98dce76981781b53776e70b9\auditpolicygpinterop.dll.mui", hr=0x0

2025-11-26T01:39:59.927 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9c4e95300400790b8d8a05d9bf7e1f5c\winnlsres.dll.mui", hr=0x0

2025-11-26T01:39:59.937 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e981bfd75ae177a858ec5c78a5cfda25\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-26T01:39:59.995 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-26T01:40:00.180 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ru-ru_e71c93fcf7d6f33e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:00.229 Engine:Setting original file name "qualityupdateassistant" for "c:\windows\system32\qualityupdateassistant.dll", hr=0x0

2025-11-26T01:40:00.240 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ro-ro_2c617f480dd85974_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:00.366 Engine:Setting original file name "wersvc" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2f884580919ab799dbe1ecd0f275799\wersvc.dll.mui", hr=0x0

2025-11-26T01:40:00.453 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_fa-ir_f7555235024374d9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:00.483 Engine:Setting original file name "ClrCompression" for "c:\program files\windowsapps\microsoft.net.native.runtime.1.7_1.7.25531.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-26T01:40:00.517 Engine:Setting original file name "WIASERVC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiaservc.dll.mui_54051b53", hr=0x0

2025-11-26T01:40:00.520 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-26T01:40:00.550 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ru-ru_0752c1c778fe6e7c_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-26T01:40:00.656 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-26T01:40:01.042 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_id-id_6be80829898706a2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:01.046 Engine:Setting original file name "STI.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_en-us_d64b3cbf22b2a8d1_sti.dll.mui_00a4f15b", hr=0x0

2025-11-26T01:40:01.053 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9035fe481934c33719e75dea902d1698\bcastdvruserservice.dll.mui", hr=0x0

2025-11-26T01:40:01.084 Engine:Setting original file name "NVIDIA Debug Dump" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvdebugdump.exe", hr=0x0

2025-11-26T01:40:01.111 Engine:Setting original file name "acpiex.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-acpiex_31bf3856ad364e35_10.0.26100.1150_none_d0b1f61a88e2f0e9_acpiex.sys_6a8b9aed", hr=0x0

2025-11-26T01:40:01.129 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_60b47cf61af27adc_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-26T01:40:01.147 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x0

2025-11-26T01:40:01.335 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sv-se_29319a980f7b0983_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-26T01:40:01.436 Engine:Setting original file name "pshed.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-pshed_31bf3856ad364e35_10.0.26100.1_none_633b3602ca01eb94_pshed.dll_f6ac239e", hr=0x0

2025-11-26T01:40:01.525 Engine:Setting original file name "ClipSVC.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-client-li..m-service.resources_31bf3856ad364e35_10.0.26100.1_en-us_3f436cbd520195fd_clipsvc.dll.mui_18823613", hr=0x0

2025-11-26T01:40:01.549 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_cy-gb_976c80cbdb5c65c1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:01.765 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_uk-ua_c5d15aec526b5235_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:01.828 Engine:Setting original file name "msfltr32.acm" for "c:\windows\winsxs\wow64_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_10.0.26100.1_none_e82ddbd17df6cb5b\msacm32.dll", hr=0x0

2025-11-26T01:40:01.879 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-26T01:40:01.894 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-26T01:40:01.944 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_6dcfa7c5391fe7a2_dnsapi.dll.mui_97465f8a", hr=0x0

2025-11-26T01:40:02.076 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_3cda2262e7ef70ab_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:02.177 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_10.0.26100.7171_none_f70fffd91c8f0404\winload.exe", hr=0x0

2025-11-26T01:40:02.340 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_et-ee_9786a4bcaafec5cb_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:02.637 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files\mozilla firefox\dxcompiler.dll", hr=0x0

2025-11-26T01:40:02.705 Engine:Setting original file name "Device_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\device\nb-no\edb83efa185c0a23d97fafe6a71cd608\diagpackage.dll.mui", hr=0x0

2025-11-26T01:40:02.726 Engine:Setting original file name "rtutils.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasrtutils_31bf3856ad364e35_10.0.26100.3037_none_a90518339a5ed736_rtutils.dll_243724ab", hr=0x0

2025-11-26T01:40:02.843 Engine:Setting original file name "udiapi.dll" for "c:\windows\system32\udiapiclient.dll", hr=0x0

2025-11-26T01:40:02.863 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-26T01:40:02.921 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaidvc.dll", hr=0x0

2025-11-26T01:40:02.926 Engine:Setting original file name "DWrite" for "c:\windows\winsxs\amd64_microsoft-windows-directwrite.resources_31bf3856ad364e35_10.0.26100.1_en-us_8e75f00536c95f8c\dwrite.dll.mui", hr=0x0

2025-11-26T01:40:02.934 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\windows\syswow64\nb-no\mfc40u.dll.mui", hr=0x0

2025-11-26T01:40:03.050 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.26100.1_en-us_12a038f1fa40c367_wlrmdr.exe.mui_ee563c83", hr=0x0

2025-11-26T01:40:03.143 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.xaml.winmd", hr=0x0

2025-11-26T01:40:03.220 Engine:Setting original file name "raspptp.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasbase-raspptp_31bf3856ad364e35_10.0.26100.1882_none_358d932997f7087d_raspptp.sys_25e89db1", hr=0x0

2025-11-26T01:40:03.314 Engine:Setting original file name "l3codec.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\17e7113a56f3171dc40844c9d3ee9e47\l3codeca.acm.mui", hr=0x0

2025-11-26T01:40:03.346 Engine:Setting original file name "bridgeres.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-networkbridge_31bf3856ad364e35_10.0.26100.2454_none_a3b07853b6183928_bridgeres.dll_55e40455", hr=0x0

2025-11-26T01:40:03.582 Engine:Setting original file name "mf.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..oundation.resources_31bf3856ad364e35_10.0.26100.1_en-us_8b9cc1ab2476fea1\mfpmp.exe.mui", hr=0x0

2025-11-26T01:40:03.674 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-processthreads-l1-1-1.dll", hr=0x0

2025-11-26T01:40:03.739 Engine:Setting original file name "FreeImage.dll" for "c:\program files (x86)\steam\steamapps\common\wallpaper_engine\bin\freeimage64.dll", hr=0x0

2025-11-26T01:40:03.744 Engine:Setting original file name "tier0_s.dll" for "c:\program files (x86)\steam\tier0_s64.dll", hr=0x0

2025-11-26T01:40:03.759 Engine:Setting original file name "nvaudcap.dll" for "c:\windows\syswow64\nvaudcap32v.dll", hr=0x0

2025-11-26T01:40:03.796 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mi-nz_b80bad72b6b0ee53_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:03.824 Engine:Setting original file name "CertCli" for "c:\windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_10.0.26100.1_en-us_61b2ff4b086153b8\certcli.dll.mui", hr=0x0

2025-11-26T01:40:03.828 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\en-us\wsepno.dll.mui", hr=0x0

2025-11-26T01:40:03.852 Engine:Setting original file name "ConfigurationRemotingServer.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\configurationremotingserver.exe", hr=0x0

2025-11-26T01:40:03.864 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_sr-..-rs_e67ffd847af5d250_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:03.867 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\power\en-us\diagpackage.dll.mui", hr=0x0

2025-11-26T01:40:03.890 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay8-payload_31bf3856ad364e35_1.0.26100.4202_none_bb7ce817a226517c\dpnaddr.dll", hr=0x0

2025-11-26T01:40:04.131 Engine:Setting original file name "msfltr32.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8836c193640d589410b5cc3dbe67e146\msacm32.dll.mui", hr=0x0

2025-11-26T01:40:04.228 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_6a24110114ad15ad_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-26T01:40:04.250 Engine:Setting original file name "usk.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\7c8e526d244ad657f882f8bbba0149ec\usk.rs.mui", hr=0x0

2025-11-26T01:40:04.263 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-26T01:40:04.283 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay4-payload_31bf3856ad364e35_1.0.26100.4202_none_186a372066698d60\dpmodemx.dll", hr=0x0

2025-11-26T01:40:04.468 Engine:Setting original file name "Register-CimProvider2.exe.mui" for "c:\windows\syswow64\en-us\register-cimprovider.exe.mui", hr=0x0

2025-11-26T01:40:04.567 Engine:Setting original file name "metabase.dll.mui" for "c:\windows\winsxs\wow64_microsoft-windows-iis-metabase.resources_31bf3856ad364e35_10.0.26100.1_en-us_8ff50fedc8451a7b\metadata.dll.mui", hr=0x0

2025-11-26T01:40:04.571 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x0

2025-11-26T01:40:04.649 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_de-de_ab2a1f0520f5ef2b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:04.717 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_6fced6fbf4c0e3e0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:04.848 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\en-us\diagpackage.dll.mui", hr=0x0

2025-11-26T01:40:04.868 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_7478bb53490dd7a8_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-26T01:40:04.918 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\windows\system32\nb-no\msidntld.dll.mui", hr=0x0

2025-11-26T01:40:04.923 Engine:Setting original file name "glu32" for "c:\windows\winsxs\amd64_microsoft-windows-opengl.resources_31bf3856ad364e35_10.0.26100.1_en-us_9c3b296d3d668ac3\glu32.dll.mui", hr=0x0

2025-11-26T01:40:04.943 Engine:Setting original file name "mf.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mediafoundation_31bf3856ad364e35_10.0.26100.7171_none_384874e2bca9ce3f\mfpmp.exe", hr=0x0

2025-11-26T01:40:04.975 Engine:Setting original file name "scesrv" for "c:\windows\system32\nb-no\scesrv.dll.mui", hr=0x0

2025-11-26T01:40:04.987 Engine:Setting original file name "DWWIN" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ae2b7dc24859d1fa2a509d5b642451b4\dwwin.exe.mui", hr=0x0

2025-11-26T01:40:05.132 Engine:Setting original file name "nvcuvid.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcuvid64.dll", hr=0x0

2025-11-26T01:40:05.165 Engine:Setting original file name "AppHostNameRegistrationVerifier.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\baf91a75f57ca8730dd9a6f926a58dd0\apphostregistrationverifier.exe.mui", hr=0x0

2025-11-26T01:40:05.175 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_en-gb_9672c12aaba943d2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:05.288 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-rtlsupport-l1-1-0.dll", hr=0x0

2025-11-26T01:40:05.307 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-26T01:40:05.334 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_gu-in_97d53b15f69aaeca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:05.384 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_84875939fc6b99b1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:05.401 Engine:Setting original file name "ServDeps.exe.mui" for "c:\windows\syswow64\wbem\nb-no\servdeps.dll.mui", hr=0x0

2025-11-26T01:40:05.431 Engine:Setting original file name "schtasks.exe" for "c:\windows\winsxs\amd64_microsoft-windows-sctasks_31bf3856ad364e35_10.0.26100.6725_none_25e27f3a6574108c\schtasks.exe", hr=0x0

2025-11-26T01:40:05.443 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_e38364b045f31518_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:05.490 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_el-gr_b382575af3d00da3_memtest.efi.mui_71e15c22", hr=0x0

2025-11-26T01:40:05.654 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.26100.1_en-us_0e875971ea5fda56\ieadvpack.dll.mui", hr=0x0

2025-11-26T01:40:05.694 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-datetime-l1-1-0.dll", hr=0x0

2025-11-26T01:40:05.717 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-26T01:40:05.756 Engine:Setting original file name "user32" for "c:\windows\system32\user32.dll", hr=0x0

2025-11-26T01:40:05.827 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.642.119.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-26T01:40:05.837 Engine:Setting original file name "shutdownui" for "c:\windows\winsxs\amd64_microsoft-windows-shutdownext.resources_31bf3856ad364e35_10.0.26100.1_en-us_9bd0f22e3578c871\shutdownext.dll.mui", hr=0x0

2025-11-26T01:40:05.986 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4\memtest.exe.mui", hr=0x0

2025-11-26T01:40:06.028 Engine:Setting original file name ".NET Host Resolver - 8.0.20" for "c:\users\serverpc\appdata\local\temp\emby-server-updater\hostfxr.dll", hr=0x0

2025-11-26T01:40:06.046 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_bs-..-ba_3017f7e2648d7e73_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:06.125 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_quz-pe_0266e81632046792_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:06.229 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lb-lu_cb546bb0b0d79a98_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:06.263 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\amd64_microsoft-windows-a..perience-ait-static_31bf3856ad364e35_10.0.26100.7019_none_ccd1f49f5e2b3b28\aitstatic.exe", hr=0x0

2025-11-26T01:40:06.354 Engine:Setting original file name "UNPShared.dll" for "c:\windows\winsxs\amd64_microsoft-windows-update-upshared_31bf3856ad364e35_10.0.26100.5074_none_29764f36135e6d4c\upshared.dll", hr=0x0

2025-11-26T01:40:06.428 Engine:Setting original file name "messagin.dll" for "c:\program files\bitdefender agent\27.1.1.23\messaging.dll", hr=0x0

2025-11-26T01:40:06.497 Engine:Setting original file name "WindowsCodecs" for "c:\windows\syswow64\windowscodecs.dll", hr=0x0

2025-11-26T01:40:06.532 Engine:Setting original file name "WerMgr" for "c:\windows\system32\wermgr.exe", hr=0x0

2025-11-26T01:40:06.587 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d\memtest.exe.mui", hr=0x0

2025-11-26T01:40:06.590 Engine:Setting original file name "imapi.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bd7c223153b9576fe4c4e66ebf1c6ece\imapi.dll.mui", hr=0x0

2025-11-26T01:40:06.711 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hi-in_8555c5797fc8795e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:06.788 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\esrb.rs.mui", hr=0x0

2025-11-26T01:40:06.801 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\updated\nmhproxy.exe", hr=0x0

2025-11-26T01:40:06.882 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-26T01:40:06.903 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_zh-tw_ff4ad39908e2da78_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:06.907 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-26T01:40:06.955 Engine:Setting original file name "microsoftedgedevtools.exe" for "c:\windows\system32\microsoftedgecp.exe", hr=0x0

2025-11-26T01:40:06.977 Engine:Setting original file name "la57setup.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ec428185df2994f7d7954c1efe1b2738\la57setup.exe.mui", hr=0x0

2025-11-26T01:40:06.984 Engine:Setting original file name "wuapi.dll" for "c:\windows\uus\x86\wuapicore.dll", hr=0x0

2025-11-26T01:40:07.054 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\system32\en-us\dsprop.dll.mui", hr=0x0

2025-11-26T01:40:07.306 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-26T01:40:07.326 Engine:Setting original file name "etweseproviderresources.dll" for "c:\windows\winsxs\backup\amd64_microsoft-etw-ese_31bf3856ad364e35_10.0.26100.1_none_cc4e7afeeee8d3b1_etweseproviderresources.dll_f21e8ea7", hr=0x0

2025-11-26T01:40:07.387 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_2821a024e044bada_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:07.389 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-26T01:40:07.427 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bf8ce2a53903d9e6d302aee07de95dd9\mfc40u.dll.mui", hr=0x0

2025-11-26T01:40:07.440 Engine:Setting original file name "TAPISRV.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-tapiservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_83c985f74a352be9\tapisrv.dll.mui", hr=0x0

2025-11-26T01:40:07.636 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lo-la_099683f3cb70d44f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:07.639 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x0

2025-11-26T01:40:07.729 Engine:Setting original file name "wininet.dll" for "c:\windows\systemresources\wininet.dll.mun", hr=0x0

2025-11-26T01:40:07.757 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\nb-no\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x0

2025-11-26T01:40:07.776 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_hu-hu_9dd052ebcaf187fd_memtest.efi.mui_71e15c22", hr=0x0

2025-11-26T01:40:07.778 Engine:Setting original file name "PrintBrmEng.exe.mui" for "c:\windows\system32\spool\tools\en-us\printbrmengine.exe.mui", hr=0x0

2025-11-26T01:40:07.780 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_it-it_4087c8eabdc39e5f_memtest.efi.mui_71e15c22", hr=0x0

2025-11-26T01:40:07.811 Engine:Setting original file name "audioadg.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f411807b0749e7d602e77baf3c1c4e60\audiodg.exe.mui", hr=0x0

2025-11-26T01:40:07.881 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x0

2025-11-26T01:40:07.959 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-t..iprovider.resources_31bf3856ad364e35_10.0.26100.1_en-us_41b711b4f2db4fe7\rdpsign.exe.mui", hr=0x0

2025-11-26T01:40:08.084 Engine:Setting original file name "Video_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\video\nb-no\2ca5a0690699da595bd35a22420a1c04\diagpackage.dll.mui", hr=0x0

2025-11-26T01:40:08.092 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-26T01:40:08.112 Engine:Setting original file name "FvSDKTestClientPublic" for "c:\program files\nvidia corporation\frameviewsdk\sdk\fvsdktestclient_public.exe", hr=0x0

2025-11-26T01:40:08.153 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\qps-ploc\msprivs.dll.mui", hr=0x0

2025-11-26T01:40:08.154 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-26T01:40:08.334 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files\mozilla firefox\updated\dxcompiler.dll", hr=0x0

2025-11-26T01:40:08.446 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\windows\system32\nb-no\pnpclean.dll.mui", hr=0x0

2025-11-26T01:40:08.457 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_or-in_f89501f89f876dc5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:08.487 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.26100.7171_none_4ad020869b677502\taskmgr.exe.mun", hr=0x0

2025-11-26T01:40:08.536 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_ca98740be1962356_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:08.593 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x0

2025-11-26T01:40:08.647 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_it-it_f0fca0072ba86c5a\msprivs.dll.mui", hr=0x0

2025-11-26T01:40:08.687 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps-ploc_7ccda1c46b445ed4\memtest.exe.mui", hr=0x0

2025-11-26T01:40:08.705 Engine:Setting original file name "NETBIOS.SYS" for "c:\windows\winsxs\backup\amd64_microsoft-windows-netbios_31bf3856ad364e35_10.0.26100.1_none_56d5608ad3abe945_netbios.sys_6f23c4df", hr=0x0

2025-11-26T01:40:08.759 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-process-l1-1-0.dll", hr=0x0

2025-11-26T01:40:08.885 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\systemresources\etwcoreuicomponentsresources.dll.mun", hr=0x0

2025-11-26T01:40:08.896 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pt-br_55b72b827c87f88f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:09.045 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_0dc0948c02e4507b_memtest.efi.mui_71e15c22", hr=0x0

2025-11-26T01:40:09.058 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mt-mt_b4ebaa02b8bfece3_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:09.090 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.devices.winmd", hr=0x0

2025-11-26T01:40:09.126 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_576ce8a1070e9744_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:09.137 Engine:Setting original file name "FileInfo.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-fileinfominifilter_31bf3856ad364e35_10.0.26100.1150_none_729c4b9be137bb96_fileinfo.sys_9be2dfcd", hr=0x0

2025-11-26T01:40:09.213 Engine:Setting original file name "aclui.dll" for "c:\windows\winsxs\amd64_microsoft-windows-aclui_31bf3856ad364e35_10.0.26100.7019_none_f0f7bbb4638cf785\aclui.dll.mun", hr=0x0

2025-11-26T01:40:09.217 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\73be2921551d\apex_fieldsamplerchecked_x86.dll", hr=0x0

2025-11-26T01:40:09.276 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.777.2143.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-26T01:40:09.338 Engine:Setting original file name "qualityupdateassistant" for "c:\program files\microsoft update health tools\qualityupdateassistant.dll", hr=0x0

2025-11-26T01:40:09.362 Engine:Setting original file name "NVPPE.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvppex.dll", hr=0x0

2025-11-26T01:40:09.437 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_en-us_4761fcc7ecd6d884_winresume.efi.mui_f412814e", hr=0x0

2025-11-26T01:40:09.618 Engine:Setting original file name "NVPrxy.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvprxy32.dll", hr=0x0

2025-11-26T01:40:09.719 Engine:Setting original file name "Mystify" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\589bec7339e102473dc7566c3b9b0f45\mystify.scr.mui", hr=0x0

2025-11-26T01:40:09.744 Engine:Setting original file name "volmgrx.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..memanager.resources_31bf3856ad364e35_10.0.26100.1_en-us_a18734abf077f9b4_volmgrx.sys.mui_b0c205d7", hr=0x0

2025-11-26T01:40:09.780 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-26T01:40:09.877 Engine:Setting original file name "libcrypto" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\libcrypto-3-x64.dll", hr=0x0

2025-11-26T01:40:09.899 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-string-l1-1-0.dll", hr=0x0

2025-11-26T01:40:09.930 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hi-in_83227505fd46a5bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:09.971 Engine:Setting original file name "CertCa" for "c:\windows\winsxs\amd64_microsoft-windows-c..ertca-dll.resources_31bf3856ad364e35_10.0.26100.1_nb-no_25e015431023bb9b\certca.dll.mui", hr=0x0

2025-11-26T01:40:10.071 Engine:Setting original file name "PCW_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_ddc581f4a364804b\diagpackage.dll.mui", hr=0x0

2025-11-26T01:40:10.155 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..subsystem.resources_31bf3856ad364e35_10.0.26100.1_nb-no_ab8620bc0ed41a36\scardsvr.dll.mui", hr=0x0

2025-11-26T01:40:10.173 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_6.0.3624.51421.dll", hr=0x0

2025-11-26T01:40:10.250 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-26T01:40:10.285 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_06d4a9c0547686dc\msprivs.dll.mui", hr=0x0

2025-11-26T01:40:10.432 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mapi_31bf3856ad364e35_10.0.26100.7019_none_473a9ee5c9a5ebee\mapistub.dll", hr=0x0

2025-11-26T01:40:10.548 Engine:Setting original file name "mofcomp.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_nb-no_8c87dcbbb8114be3_mofcomp.exe.mui_35badf56", hr=0x0

2025-11-26T01:40:10.553 Engine:Setting original file name "MspsProv.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..oning-wmi.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd6de3cbb42de1cb\mspsprov.dll.mui", hr=0x0

2025-11-26T01:40:10.597 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x0

2025-11-26T01:40:10.697 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.26100.7019_none_4a484d6501b73a17\wwanapi.dll", hr=0x0

2025-11-26T01:40:10.767 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ne-np_591939d32e7d4223_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:10.838 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.xboxidentityprovider_12.130.16001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-26T01:40:10.994 Engine:Setting original file name "Operativsystemet Microsoft� Windows�" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e2a170892be5347a116ae0806fb5309d\pcalua.exe.mui", hr=0x0

2025-11-26T01:40:11.067 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x0

2025-11-26T01:40:11.083 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x0

2025-11-26T01:40:11.361 Engine:Setting original file name "imageres.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-imageres_31bf3856ad364e35_10.0.26100.1_none_d9b14b936072a0bc\imageres.dll.mun", hr=0x0

2025-11-26T01:40:11.570 Engine:Setting original file name "vcruntime140.dll" for "c:\config.msi\1c742.rbf", hr=0x0

2025-11-26T01:40:11.611 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-26T01:40:11.653 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_kk-kz_71b9c9e0d19e9ee0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:11.843 Engine:Setting original file name "Apps_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\apps\nb-no\d2a92c7cfed83dc547a21508b5b0ea0f\diagpackage.dll.mui", hr=0x0

2025-11-26T01:40:11.860 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32.dll", hr=0x0

2025-11-26T01:40:11.914 Engine:Setting original file name "CertPKICmdlet" for "c:\windows\system32\en-us\certpkicmdlet.dll.mui", hr=0x0

2025-11-26T01:40:11.966 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ed4232cecc06e9efb72d2a7c142b63b4\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x0

2025-11-26T01:40:11.976 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.424.1611.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-26T01:40:12.038 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_0cb2119581e88ce0\diagpackage.dll.mui", hr=0x0

2025-11-26T01:40:12.200 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\system32\bcp47langs.dll", hr=0x0

2025-11-26T01:40:12.274 Engine:Setting original file name "gpapi.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-g..licy-base.resources_31bf3856ad364e35_10.0.26100.1_en-us_be2843fbd972ca37_gpapi.dll.mui_ef0a9748", hr=0x0

2025-11-26T01:40:12.276 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-math-l1-1-0.dll", hr=0x0

2025-11-26T01:40:12.333 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x0

2025-11-26T01:40:12.342 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\winsxs\amd64_microsoft-windows-aerolite.resources_31bf3856ad364e35_10.0.26100.1_en-us_bc993ceae8fc48bf\aerolite.msstyles.mui", hr=0x0

2025-11-26T01:40:12.624 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\en-us\utilman.exe.mui", hr=0x0

2025-11-26T01:40:12.767 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x0

2025-11-26T01:40:12.881 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-26T01:40:12.889 Engine:Setting original file name "sqlite3" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\sqlite3.dll", hr=0x0

2025-11-26T01:40:12.953 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x0

2025-11-26T01:40:12.999 Engine:Setting original file name "w32time.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-time-tool.resources_31bf3856ad364e35_10.0.26100.1_en-us_7b897a2738f484fc\w32tm.exe.mui", hr=0x0

2025-11-26T01:40:13.003 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd473133072db5bb\diagpackage.dll.mui", hr=0x0

2025-11-26T01:40:13.028 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_80a1d04cb31f8eca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:13.034 Engine:Setting original file name "ERC" for "c:\windows\system32\nb-no\wercplsupport.dll.mui", hr=0x0

2025-11-26T01:40:13.066 Engine:Setting original file name "vdsutil.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-v..skservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_59d12af3dce743c1_vdsutil.dll.mui_0caf9b0e", hr=0x0

2025-11-26T01:40:13.152 Engine:Setting original file name "AppLockerCSP.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appidcore.resources_31bf3856ad364e35_10.0.26100.1_en-us_564c6ad9b132641f_applockercsp.dll.mui_d2a0df70", hr=0x0

2025-11-26T01:40:13.211 Engine:Setting original file name "dnsrslvr.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570_dnsrslvr.dll.mui_1e1a1ed1", hr=0x0

2025-11-26T01:40:13.276 Engine:Setting original file name "PSAPI" for "c:\windows\winsxs\backup\wow64_microsoft-windows-basedependencies_31bf3856ad364e35_10.0.26100.1_none_09ea4476c5bcc4c0_psapi.dll_e8b5b4d1", hr=0x0

2025-11-26T01:40:13.301 Engine:Setting original file name "AcPlugin.dll" for "c:\program files\windowsapps\microsoft.applicationcompatibilityenhancements_1.2511.9.0_x64__8wekyb3d8bbwe\amd64\acplugin_test.dll", hr=0x0

2025-11-26T01:40:13.312 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\426c2b1101abec586136a4bbd67a716e\narrator.exe.mui", hr=0x0

2025-11-26T01:40:13.329 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..tiator_ui.resources_31bf3856ad364e35_10.0.26100.1_en-us_7967a83a130d426e\iscsicpl.dll.mui", hr=0x0

2025-11-26T01:40:13.420 Engine:Setting original file name "WindowsMediaPlayerPlayDVD_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_587c1f8aa98a4a71\diagpackage.dll.mui", hr=0x0

2025-11-26T01:40:13.607 Engine:Setting original file name "scecli" for "c:\windows\system32\nb-no\scecli.dll.mui", hr=0x0

2025-11-26T01:40:13.627 Engine:Setting original file name "scesrv" for "c:\windows\winsxs\amd64_microsoft-windows-s..ionengine.resources_31bf3856ad364e35_10.0.26100.1_en-us_e63bd45b831a32e3\scesrv.dll.mui", hr=0x0

2025-11-26T01:40:13.657 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_bg-bg_af9bba51d24fbf0e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:13.714 Engine:Setting original file name "nvhda.sys" for "c:\windows\system32\driverstore\filerepository\nvhda.inf_amd64_c32d8360d192a82e\nvhda64v.sys", hr=0x0

2025-11-26T01:40:13.725 Engine:Setting original file name "wmiutils.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiutils.dll.mui_42583eaf", hr=0x0

2025-11-26T01:40:13.740 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_te-in_e10bae4a47776b9f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:13.768 Engine:Setting original file name "BdncProxy.dll" for "c:\program files\bitdefender agent\27.1.1.23\crash_handler\bdnc.dll", hr=0x0

2025-11-26T01:40:13.845 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.26100.1_nb-no_e175a2f7bf27ee8d_ws2ifsl.sys.mui_b672c7b4", hr=0x0

2025-11-26T01:40:13.907 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_eu-es_e55e702bbb854a24_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:13.942 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-msinfo32-exe.resources_31bf3856ad364e35_10.0.26100.1_en-us_53ae64398a08feba\msinfo32.exe.mui", hr=0x0

2025-11-26T01:40:13.989 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-26T01:40:14.085 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x86__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-26T01:40:14.107 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x0

2025-11-26T01:40:14.202 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x0

2025-11-26T01:40:14.210 Engine:Setting original file name "NxCooking.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\v2.7.6\physxcooking.dll", hr=0x0

2025-11-26T01:40:14.238 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-26T01:40:14.379 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x0

2025-11-26T01:40:14.453 Engine:Setting original file name "filterLib.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\4fffc8576907b0b5da815790887fb244\fltlib.dll.mui", hr=0x0

2025-11-26T01:40:14.481 Engine:Setting original file name "srpuxgp.dll" for "c:\windows\systemresources\srpuxnativesnapin.dll.mun", hr=0x0

2025-11-26T01:40:14.484 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-26T01:40:14.679 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_nl-nl_0d26e65c98dbf6f7_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:14.689 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sl-si_8549ba61ed8af84b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:14.694 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x0

2025-11-26T01:40:14.874 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_pl-pl_9d43c82914fc6152_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:14.896 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.web.winmd", hr=0x0

2025-11-26T01:40:14.960 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-26T01:40:15.072 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ca-es_584cefb2c144b7d8_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:15.083 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\winsxs\amd64_microsoft-windows-qedwipes_31bf3856ad364e35_10.0.26100.1_none_5473011012d79dc1\qedwipes.dll.mun", hr=0x0

2025-11-26T01:40:15.245 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_et-ee_4da61d721400c924_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:15.284 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_fb2fbffb5205c552_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:15.497 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..xe-common.resources_31bf3856ad364e35_10.0.26100.1_en-us_58b62bf54b9ae38a\msinfo32.exe.mui", hr=0x0

2025-11-26T01:40:15.615 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.70.1338.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-26T01:40:15.621 Engine:Setting original file name "netcfgx.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-tcpip.resources_31bf3856ad364e35_10.0.26100.1_en-us_c93621b935b09922_tcpipcfg.dll.mui_a5479fc1", hr=0x0

2025-11-26T01:40:15.672 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_f4c1513bcd79893e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:15.719 Engine:Setting original file name "nvxdsync.exe" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\session\nvxdsyncplugin.dll", hr=0x0

2025-11-26T01:40:15.852 Engine:Setting original file name "ReShade" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\reshadefxc64.exe", hr=0x0

2025-11-26T01:40:15.896 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-26T01:40:15.939 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_0fbfb1c9f2926e3e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:15.968 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\power\nb-no\2803551e72f3605cc0b181750700647e\diagpackage.dll.mui", hr=0x0

2025-11-26T01:40:16.029 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_th-th_25ee4fb15dc2e739_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:16.034 Engine:Setting original file name "Umpo.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-u..erservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_a887c532823d0a08_umpo.dll.mui_cac12e54", hr=0x0

2025-11-26T01:40:16.037 Engine:Setting original file name "bootres" for "c:\windows\boot\resources\nb-no\bootres.dll.mui", hr=0x0

2025-11-26T01:40:16.061 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\b74f41bc269d13282681d018820fb031\ddores.dll.mui", hr=0x0

2025-11-26T01:40:16.082 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x0

2025-11-26T01:40:16.095 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\mscordaccore_amd64_amd64_8.0.2125.47513.dll", hr=0x0

2025-11-26T01:40:16.121 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-namedpipe-l1-1-0.dll", hr=0x0

2025-11-26T01:40:16.220 Engine:Setting original file name "dxmasf.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_10.0.26100.7019_none_b1abcb083360b859\msdxm.ocx", hr=0x0

2025-11-26T01:40:16.349 Engine:Setting original file name "Bubbles" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ee15dd2b573766654f76694ac2f468d4\bubbles.scr.mui", hr=0x0

2025-11-26T01:40:16.387 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_tr-tr_2c24c8b8ddbbff8a_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:16.410 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_es-mx_9dca765f230af946_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-26T01:40:16.434 Engine:Setting original file name "CUDART64_65_19.DLL" for "c:\program files (x86)\nvidia corporation\physx\common\cudart64_65.dll", hr=0x0

2025-11-26T01:40:16.451 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-errorhandling-l1-1-0.dll", hr=0x0

2025-11-26T01:40:16.580 Engine:Setting original file name "wcp.dll" for "c:\windows\system32\ssshim.dll", hr=0x0

2025-11-26T01:40:16.685 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.exe", hr=0x0

2025-11-26T01:40:16.734 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-time-l1-1-0.dll", hr=0x0

2025-11-26T01:40:16.737 Engine:Setting original file name "SCardDlg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.26100.3323_en-us_fe960d41ea77a2e8_scarddlg.dll.mui_300ae9df", hr=0x0

2025-11-26T01:40:16.762 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-memory-l1-1-0.dll", hr=0x0

2025-11-26T01:40:16.772 Engine:Setting original file name "reg.exe" for "c:\windows\winsxs\wow64_microsoft-windows-r..-commandline-editor_31bf3856ad364e35_10.0.26100.5074_none_d7dcabbe0ef09540\reg.exe", hr=0x0

2025-11-26T01:40:16.785 Engine:Setting original file name "TrustedSignalCredProv.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..-credprov.resources_31bf3856ad364e35_10.0.26100.1_en-us_080e5e17ad23b7b4_trustedsignalcredprov.dll.mui_5edc427b", hr=0x0

2025-11-26T01:40:16.822 Engine:Setting original file name "fpb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\fpb.rs.mui", hr=0x0

2025-11-26T01:40:16.907 OriginalFileName Maintenance::11515 files in Moac, 0 skipped (cached), 435 filename set

2025-11-26T01:40:16.907 [AutoPurge] Routine task for Cache Maintenance has ended.

2025-11-26T01:46:17.765 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T01:50:55.477 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #307219, FileId: 0x22000000031ab1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T01:52:06.471 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #307246, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T01:52:06.475 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #307247, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T01:52:16.470 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #307254, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T01:52:16.474 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #307255, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T01:52:16.486 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #307256, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T01:52:16.489 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #307257, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T02:01:22.758 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T02:05:55.932 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #307498, FileId: 0x11600000000e841, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T02:07:08.282 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

2025-11-26T02:07:08.293 [DLP] DlpEngineConfigStorage::OnConfigChange DlpDwordSettingsMap:

2025-11-26T02:07:08.293 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-26T02:07:08.293 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-26T02:07:08.293 [RTP] Duplicating the current plugin configuration object...

2025-11-26T02:07:08.293 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-26T02:07:08.293 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-26T02:07:08.293 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-26T02:07:08.293 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-26T02:07:08.293 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-26T02:07:08.293 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-26T02:07:08.293 [RTP] No config change detected. Not updating plugin configuration.

2025-11-26T02:07:08.293 [RTP] No config changes found. No configuration switch.

2025-11-26T02:07:08.293 [RTP] [RtpConfig] Config change detected, type: 16

2025-11-26T02:07:08.293 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-26T02:07:08.293 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-26T02:07:08.293 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-26T02:07:08.293 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-26T02:07:08.294 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-26T02:07:08.294 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-26T02:07:08.294 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-26T02:07:08.294 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-26T02:07:08.294 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-26T02:07:08.294 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-26T02:07:08.294 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-26T02:07:08.294 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-26T02:07:08.294 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T02:07:08.294 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-26T02:07:08.295 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-26T02:07:08.295 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-26T02:07:08.296 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T02:07:08.298 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T02:07:08.299 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T02:07:08.301 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T02:07:08.302 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 3341419(ms) from now at 04:02 (03:02 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-26T02:07:10.840 [RTP] Duplicating the current plugin configuration object...

2025-11-26T02:07:10.840 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-26T02:07:10.840 [RTP] Updating plugin configuration due to recent config changes (0x41e) ...

2025-11-26T02:07:10.840 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-26T02:07:10.840 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x218

2025-11-26T02:09:55.197 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #307952, FileId: 0xbe00000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T02:16:27.754 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T02:17:44.191 ProcessImageName: updater.exe, Pid: 25804, TotalTime: 2097, Count: 45, MaxTime: 1343, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Mozilla Firefox\updated\xul.dll, EstimatedImpact: 37%

2025-11-26T02:17:44.191 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 826, Count: 88, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\90196e9d-057f-4e19-a1ce-ba0c2bb2edbd.tmp, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 646, Count: 54, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ad1132e8-dc8a-4bbf-8ce8-6d70ba97180f.tmp, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 616, Count: 123, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 15%

2025-11-26T02:17:44.191 ProcessImageName: RuntimeBroker.exe, Pid: 4268, TotalTime: 527, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 34%

2025-11-26T02:17:44.191 ProcessImageName: RuntimeBroker.exe, Pid: 17192, TotalTime: 467, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 26%

2025-11-26T02:17:44.191 ProcessImageName: DeviceCensus.exe, Pid: 6420, TotalTime: 357, Count: 13, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-26T02:17:44.191 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 210, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: taskhostw.exe, Pid: 10516, TotalTime: 195, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 11%

2025-11-26T02:17:44.191 ProcessImageName: taskhostw.exe, Pid: 12156, TotalTime: 181, Count: 74, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 8%

2025-11-26T02:17:44.191 ProcessImageName: maintenanceservice.exe, Pid: 20640, TotalTime: 180, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_7AA1872B10F7F2428A1288E96F0B99FA, EstimatedImpact: 3%

2025-11-26T02:17:44.191 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 123, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 45, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 30, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\OptimizationHints\573\optimization-hints.pb, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: updater.exe, Pid: 24824, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: StoreDesktopExtension.exe, Pid: 18780, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: HxTsr.exe, Pid: 18216, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 15%

2025-11-26T02:17:44.191 ProcessImageName: updater.exe, Pid: 27608, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_691320.acf, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping20108_829020913\manifest.fingerprint, EstimatedImpact: 0%

2025-11-26T02:17:44.191 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-26T02:20:56.749 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #308442, FileId: 0x2300000006e9ea, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T02:31:32.753 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T02:35:57.449 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #308580, FileId: 0x1b000000063583, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T02:46:37.751 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T02:50:58.144 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #308695, FileId: 0x4d00000005d57f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T02:52:06.374 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #308705, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T02:52:06.377 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #308706, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T02:52:16.377 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #308711, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T02:52:16.381 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #308712, FileId: 0xae000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T03:01:42.753 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T03:05:59.146 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #308836, FileId: 0x5b00000005d57f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T03:16:47.741 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T03:20:59.514 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #309277, FileId: 0x3600000006e9f6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T03:21:45.486 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T03:31:52.741 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T03:36:00.135 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #309353, FileId: 0x3200000006bbf0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T03:46:57.726 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T03:51:00.942 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #309527, FileId: 0x4a00000006e9f5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T03:52:05.782 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #309558, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000001, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T03:52:05.786 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #309559, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T03:52:15.797 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #309566, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T03:52:15.798 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #309567, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T03:52:15.801 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #309568, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T03:52:15.802 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #309569, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T04:02:02.722 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T04:06:01.786 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #309708, FileId: 0x5800000003a92c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T04:17:07.719 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T04:17:44.158 ProcessImageName: updater.exe, Pid: 25804, TotalTime: 2097, Count: 45, MaxTime: 1343, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Mozilla Firefox\updated\xul.dll, EstimatedImpact: 37%

2025-11-26T04:17:44.158 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1712, Count: 174, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\90196e9d-057f-4e19-a1ce-ba0c2bb2edbd.tmp, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1306, Count: 107, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ad1132e8-dc8a-4bbf-8ce8-6d70ba97180f.tmp, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 616, Count: 124, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: RuntimeBroker.exe, Pid: 4268, TotalTime: 527, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 34%

2025-11-26T04:17:44.158 ProcessImageName: RuntimeBroker.exe, Pid: 17192, TotalTime: 467, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 26%

2025-11-26T04:17:44.158 ProcessImageName: DeviceCensus.exe, Pid: 6420, TotalTime: 357, Count: 13, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-26T04:17:44.158 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 255, Count: 62, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 195, Count: 56, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: taskhostw.exe, Pid: 10516, TotalTime: 195, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 11%

2025-11-26T04:17:44.158 ProcessImageName: taskhostw.exe, Pid: 12156, TotalTime: 181, Count: 74, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 8%

2025-11-26T04:17:44.158 ProcessImageName: maintenanceservice.exe, Pid: 20640, TotalTime: 180, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_7AA1872B10F7F2428A1288E96F0B99FA, EstimatedImpact: 3%

2025-11-26T04:17:44.158 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 169, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 60, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 30, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\OptimizationHints\573\optimization-hints.pb, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: updater.exe, Pid: 24824, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: StoreDesktopExtension.exe, Pid: 24788, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 17%

2025-11-26T04:17:44.158 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: HxTsr.exe, Pid: 18216, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 15%

2025-11-26T04:17:44.158 ProcessImageName: StoreDesktopExtension.exe, Pid: 18780, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: updater.exe, Pid: 27608, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: taskhostw.exe, Pid: 5036, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-26T04:17:44.158 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_691320.acf, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping20108_829020913\manifest.fingerprint, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: updater.exe, Pid: 19188, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\14154464-3cca-4d7e-bbba-35e6228726dc.tmp, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: updater.exe, Pid: 17616, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ee47e37c-c081-4153-a497-dff15e313cfe.tmp, EstimatedImpact: 0%

2025-11-26T04:17:44.158 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-26T04:21:02.227 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #309984, FileId: 0x1c900000000b8a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T04:32:12.720 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T04:36:03.025 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #310103, FileId: 0x3e000000056362, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T04:47:17.722 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T04:51:04.039 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #310701, FileId: 0x8800000002635d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T04:52:06.547 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #310704, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T04:52:06.550 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #310705, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T04:52:16.563 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #310710, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T04:52:16.566 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #310711, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T05:02:22.716 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T05:06:04.834 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #310891, FileId: 0x6b000000049376, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T05:17:27.712 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T05:21:05.303 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #311839, FileId: 0x3f10000000015ba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T05:21:47.520 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T05:32:32.701 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T05:36:06.096 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #311985, FileId: 0x11000000031a71, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T05:47:37.698 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T05:51:06.837 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #312199, FileId: 0x18d0000000094d8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T05:52:06.473 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #312220, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T05:52:06.478 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #312221, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T05:52:16.488 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #312228, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T05:52:16.488 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #312229, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T05:52:16.492 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #312230, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T06:00:12.169 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\F770513D-D475-4A95-B6E7-1F697B9ABD1B4a98.1dc5e99ec9039ec

2025-11-26T06:00:12.199 Verifying engine and signature files (source: 0) ...

2025-11-26T06:00:12.199 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3513C622-E62F-4ED3-B7D5-58BC182A79A2}\mpengine.dll] due to PPL.

2025-11-26T06:00:12.199 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3513C622-E62F-4ED3-B7D5-58BC182A79A2}\mpasbase.vdm] (file in cache)

2025-11-26T06:00:12.199 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3513C622-E62F-4ED3-B7D5-58BC182A79A2}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-26T06:00:12.209 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3513C622-E62F-4ED3-B7D5-58BC182A79A2}\mpasdlta.vdm]

2025-11-26T06:00:12.209 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3513C622-E62F-4ED3-B7D5-58BC182A79A2}\mpavbase.vdm] (file in cache)

2025-11-26T06:00:12.209 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3513C622-E62F-4ED3-B7D5-58BC182A79A2}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-26T06:00:12.219 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3513C622-E62F-4ED3-B7D5-58BC182A79A2}\mpavdlta.vdm]

2025-11-26T06:00:12.291 [Engine] IsHybridMode: 0

2025-11-26T06:00:12.291 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-26T06:00:12.302 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B490119E2AB369AF82E66E8EBC7DE0EE7858658B.bin): 0x00000002

2025-11-26T06:00:12.303 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B490119E2AB369AF82E66E8EBC7DE0EE7858658B.bin)

2025-11-26T06:00:12.303 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-26T06:00:12.303 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-26T06:00:12.303 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-26T06:00:12.303 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-26T06:00:17.885 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-26T06:00:17.885 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-26T06:00:17.891 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE6F7CA660, lRefCount: 5, hr=0

2025-11-26T06:00:17.891 [Engine] New active engine 00007FFE7225A660 replacing engine 00007FFE6F7CA660. Number of active engines: 2

2025-11-26T06:00:17.899 EngineInit:Global ASOC is enabled

2025-11-26T06:00:17.899 EngineInit:ASOO is enabled for developer volumes

2025-11-26T06:00:17.931 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-26T06:00:17.931 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.931 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-26T06:00:17.932 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-26T06:00:17.932 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-26T06:00:17.932 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.932 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.933 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.933 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-26T06:00:17.933 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.933 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.933 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-26T06:00:17.935 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.935 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.935 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.935 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.936 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.936 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.936 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T06:00:17.936 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b30570a0bd07ef299df5e873ae4331a910955ee8

Dynamic Signature Compilation Timestamp:11-25-2025 01:39:53

Persistence Type:Duration

Time remaining:864000000

2025-11-26T06:00:17.937 Dynamic signature dropped

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0cde10c3c7a89f3395bc3d6917b759f095e80ea0

Dynamic Signature Compilation Timestamp:11-25-2025 05:07:15

Persistence Type:Duration

Time remaining:864000000

2025-11-26T06:00:17.937 Dynamic signature dropped

2025-11-26T06:00:17.938 MpWriteUupSignatureVersion 1.441.499.0, hr = 0

2025-11-26T06:00:17.940 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-26T06:00:17.952 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-26T06:00:17.953 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-26T06:00:17.953 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-26T06:00:17.953 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-26T06:00:17.953 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-26T06:00:17.967 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-26T06:00:17.967 [Plugin] Initializing RTP plugin state...

2025-11-26T06:00:17.967 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-26T06:00:17.967 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 26 - 2025 01:17:44

Last Perf: 11 - 26 - 2025 01:17:44

First RTP Scan: 11 - 26 - 2025 01:17:45

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1129

  Misses:4160

BM Queue:0,22,0

  Proc:0,22,0

  File:0,9,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:312417

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1659912242

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:18

  TotalStreamCon:12054

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:1370856

   TotalHits:2274774

   InstanceCacheInserts:103140

   InstanceCacheUpdates:0

   InstanceCacheDeletes:81530

   InstanceCacheHits:4845

   InstanceCacheMisses:396785

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (775/830)

   Success: 830, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-26T06:00:17.967 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3513C622-E62F-4ED3-B7D5-58BC182A79A2}

2025-11-26T06:00:17.967 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{73BB5CF7-D706-4178-9948-0AA63023B984}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{73BB5CF7-D706-4178-9948-0AA63023B984}\mpasbase.vdm in use, hr=0x80070020

2025-11-26T06:00:17.967 [SCC][CID=377344953_22456] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-26T06:00:17.968 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-26T06:00:17.968 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-26T06:00:17.968 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-26T06:00:17.968 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-26T06:00:17.968 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-26T06:00:17.970 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-26-2025 06:00:17

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-26-2025 06:00:17

2025-11-26T06:00:17.972 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-26T06:00:17.972 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-26T06:00:17.973 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-26T06:00:17.973 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-26-2025 06:00:17

END TDT(U) telemetry



2025-11-26T06:00:17.975 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T06:00:17.975 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-26T06:00:17.975 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-26T06:00:17.975 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-26T06:00:17.975 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-26T06:00:17.976 MdCoreSvc is supported in this platform and OS

Signature updated on 11-26-2025 06:00:17

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.499.0

AV Signature Version: 1.441.499.0

************************************************************

2025-11-26T06:00:17.977 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-26T06:00:17.977 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\F770513D-D475-4A95-B6E7-1F697B9ABD1B4a98.1dc5e99ec9039ec

2025-11-26T06:00:17.998 Process scan (postsignatureupdatescan) started.

2025-11-26T06:00:18.017 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-26T06:00:18.019 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-26T06:00:18.153 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-26T06:00:18.153 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-26T06:00:18.153 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-26T06:00:18.153 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-26T06:00:18.153 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-26T06:00:18.154 [Engine] Engine 00007FFE6F7CA660 no longer in use. Number of active engines: 1

2025-11-26T06:00:18.154 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-26T06:00:18.154 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-26T06:00:18.307 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2582, Count: 249, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\90196e9d-057f-4e19-a1ce-ba0c2bb2edbd.tmp, EstimatedImpact: 0%

2025-11-26T06:00:18.307 ProcessImageName: updater.exe, Pid: 25804, TotalTime: 2097, Count: 45, MaxTime: 1343, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Mozilla Firefox\updated\xul.dll, EstimatedImpact: 37%

2025-11-26T06:00:18.307 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1937, Count: 154, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ad1132e8-dc8a-4bbf-8ce8-6d70ba97180f.tmp, EstimatedImpact: 0%

2025-11-26T06:00:18.307 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1679, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 86%

2025-11-26T06:00:18.307 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 616, Count: 124, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-26T06:00:18.307 ProcessImageName: RuntimeBroker.exe, Pid: 4268, TotalTime: 527, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 34%

2025-11-26T06:00:18.307 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 495, Count: 130, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work, EstimatedImpact: 0%

2025-11-26T06:00:18.307 ProcessImageName: RuntimeBroker.exe, Pid: 17192, TotalTime: 467, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 26%

2025-11-26T06:00:18.307 ProcessImageName: DeviceCensus.exe, Pid: 6420, TotalTime: 357, Count: 13, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-26T06:00:18.307 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 315, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-26T06:00:18.307 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 225, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T06:00:18.307 ProcessImageName: taskhostw.exe, Pid: 10516, TotalTime: 195, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 11%

2025-11-26T06:00:18.307 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 184, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-26T06:00:18.307 ProcessImageName: taskhostw.exe, Pid: 12156, TotalTime: 181, Count: 74, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 8%

2025-11-26T06:00:18.307 ProcessImageName: maintenanceservice.exe, Pid: 20640, TotalTime: 180, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_7AA1872B10F7F2428A1288E96F0B99FA, EstimatedImpact: 3%

2025-11-26T06:00:18.307 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 90, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_B7ED31D77D311A56FDCB56A0083B3E0B, EstimatedImpact: 0%

2025-11-26T06:00:18.323 [Engine] RSIG_UNLOADENGINE, 00007FFE6F7CA660, err=0x0

2025-11-26T06:00:18.339 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{73BB5CF7-D706-4178-9948-0AA63023B984} removed

2025-11-26T06:00:18.455 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-26T06:00:18.461 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-26T06:00:18.461 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-26T06:00:18.461 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-26T06:00:18.462 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-26T06:00:18.462 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-26T06:00:18.462 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-26T06:00:18.466 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-26T06:00:18.466 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-26T06:00:18.466 [RTP] Duplicating the current plugin configuration object...

2025-11-26T06:00:18.466 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-26T06:00:18.466 [RTP] Updating plugin configuration due to recent config changes (0x22) ...

2025-11-26T06:00:18.466 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-26T06:00:18.466 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-26T06:00:18.466 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-26T06:00:18.466 [RTP] No config change detected. Not updating plugin configuration.

2025-11-26T06:00:18.466 [RTP] No config changes found. No configuration switch.

2025-11-26T06:00:18.466 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x22, Changed: 0

2025-11-26T06:00:18.466 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-26T06:00:18.466 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-26T06:00:18.466 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-26T06:00:18.466 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-26T06:00:18.466 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-26T06:00:18.467 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-26T06:00:18.467 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-26T06:00:18.467 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-26T06:00:18.467 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-26T06:00:18.467 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-26T06:00:18.467 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-26T06:00:18.467 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-26T06:00:18.467 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-26T06:00:18.467 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-26T06:00:18.467 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T06:00:18.469 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T06:00:18.470 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T06:00:18.471 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T06:00:18.473 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T06:00:18.474 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 76143823(ms) from now at 04:09 (03:09 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-26T06:00:19.990 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-26T06:00:19.993 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-26T06:00:19.995 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-26T06:00:21.015 [RTP] Duplicating the current plugin configuration object...

2025-11-26T06:00:21.015 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-26T06:00:21.015 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-26T06:00:21.015 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-26T06:00:21.015 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157ED7C270CE, sigsha=5eded354160aa060b3f2a16db0725661264de9cd, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF9518016, sigsha=8fa60ffaf004b3696b5767c35f78f1425d04eb09, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0xa85b3f00

2025-11-26T06:00:23.443 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-26T06:00:23.444 [Cloud] Start of cloud request. Passive mode: 0

2025-11-26T06:00:23.444 [Cloud] Queued cloud request.

2025-11-26T06:00:23.444 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-26T06:00:23.444 [Cloud] Dequeued cloud request.

2025-11-26T06:00:23.444 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\87e6adb3b89588e7b13ca6278a0f3add58d819a4

Dynamic Signature Compilation Timestamp:11-26-2025 06:00:23

Persistence Type:Duration

Time remaining:864000000

2025-11-26T06:00:23.792 Dynamic signature received

2025-11-26T06:00:23.792 [Cloud] End of cloud request.

2025-11-26T06:00:23.793 RTSD:RTSD recieved, rescanning impacted resources

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-26T06:00:24.299 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T06:00:25.150 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-26T06:00:25.150 [Cloud] Start of cloud request. Passive mode: 0

2025-11-26T06:00:25.150 [Cloud] Queued cloud request.

2025-11-26T06:00:25.150 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-26T06:00:25.150 [Cloud] Dequeued cloud request.

2025-11-26T06:00:25.150 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-26T06:00:25.458 [Cloud] End of cloud request.

2025-11-26T06:00:25.976 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T06:00:34.243 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-26T06:00:34.244 Process scan (postsignatureupdatescan) completed.

2025-11-26T06:02:42.692 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T06:05:17.920 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-26T06:06:07.581 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #312678, FileId: 0x56000000008ab0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T06:17:47.683 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T06:21:08.284 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #313287, FileId: 0x23b00000000cd07, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T06:32:52.687 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T06:36:08.688 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #313450, FileId: 0x8a000000011cb1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T06:47:57.678 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T06:51:09.570 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #313670, FileId: 0x3f000000056363, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T06:52:07.049 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #313688, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T06:52:07.051 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #313689, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T06:52:17.062 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #313695, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T06:52:17.067 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #313696, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T07:03:02.679 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T07:06:09.894 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #313897, FileId: 0x4c000000009533, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T07:18:07.665 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T07:21:10.446 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #314363, FileId: 0x1f8000000024263, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T07:21:49.485 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T07:33:12.662 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T07:36:11.092 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #314451, FileId: 0x3700000006aa2d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T07:48:17.658 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T07:51:11.739 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #314630, FileId: 0x25100000000cd07, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T07:52:05.555 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #314663, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T07:52:05.558 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #314664, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T07:52:15.565 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #314669, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T07:52:15.573 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #314670, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T08:00:17.861 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 975, Count: 86, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\23bad384-1ec7-48f4-92ed-d2869a4231fc.tmp, EstimatedImpact: 0%

2025-11-26T08:00:17.861 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 615, Count: 52, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\6ee149f7-7c8a-47c8-b524-6aedaefd038d.tmp, EstimatedImpact: 0%

2025-11-26T08:00:17.861 ProcessImageName: RuntimeBroker.exe, Pid: 26368, TotalTime: 588, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-26T08:00:17.861 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 300, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work, EstimatedImpact: 0%

2025-11-26T08:00:17.861 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 270, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-26T08:00:17.861 ProcessImageName: taskhostw.exe, Pid: 13804, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-26T08:00:17.861 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T08:00:17.861 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-26T08:00:17.861 ProcessImageName: StoreDesktopExtension.exe, Pid: 26300, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-26T08:00:17.861 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-26T08:00:17.861 ProcessImageName: taskhostw.exe, Pid: 22840, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 19%

2025-11-26T08:00:17.861 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\gamerecording.css, EstimatedImpact: 11%

2025-11-26T08:00:17.861 ProcessImageName: updater.exe, Pid: 26080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\fe2cd894-40c3-481b-af28-5153e0a6aa38.tmp, EstimatedImpact: 0%

2025-11-26T08:00:17.861 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 0, Count: 9, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.aggregators.json, EstimatedImpact: 0%

2025-11-26T08:01:47.616 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #314827, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T08:03:22.649 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T08:06:12.308 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #314852, FileId: 0x3d00000006de84, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T08:18:27.646 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T08:21:12.833 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #315094, FileId: 0x8700000003a940, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T08:33:32.643 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T08:36:13.290 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #315182, FileId: 0x7900000003a9d5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T08:48:37.638 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T08:51:13.904 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #315320, FileId: 0x3d000000068ce6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T08:52:08.358 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #315322, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T08:52:08.361 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #315323, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T08:52:18.358 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #315330, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T08:52:18.361 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #315331, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T09:03:42.630 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T09:06:14.631 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #315917, FileId: 0x1700000000d074, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T09:09:54.945 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #316060, FileId: 0xbf00000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T09:18:47.613 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T09:21:15.478 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #316142, FileId: 0x5200000001a723, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T09:21:51.570 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T09:33:52.611 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T09:36:16.611 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #316217, FileId: 0x95000000014a3b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T09:45:40.979 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #316336, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T09:48:57.609 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T09:51:17.357 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #316355, FileId: 0xa2000000014a3b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T09:52:06.656 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #316376, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T09:52:06.660 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #316377, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T09:52:16.671 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #316384, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T09:52:16.672 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #316385, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T09:52:16.674 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #316386, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T09:52:16.675 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #316387, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T10:00:17.822 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1815, Count: 171, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\23bad384-1ec7-48f4-92ed-d2869a4231fc.tmp, EstimatedImpact: 0%

2025-11-26T10:00:17.822 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1630, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 89%

2025-11-26T10:00:17.822 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1246, Count: 105, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\8645d48a-064b-4866-8a5c-0945327afbd2.tmp, EstimatedImpact: 0%

2025-11-26T10:00:17.822 ProcessImageName: RuntimeBroker.exe, Pid: 26368, TotalTime: 588, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-26T10:00:17.822 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 465, Count: 116, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work, EstimatedImpact: 0%

2025-11-26T10:00:17.822 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 315, Count: 57, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-26T10:00:17.822 ProcessImageName: taskhostw.exe, Pid: 13804, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-26T10:00:17.822 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T10:00:17.822 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-26T10:00:17.822 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-26T10:00:17.822 ProcessImageName: StoreDesktopExtension.exe, Pid: 26300, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-26T10:00:17.822 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-26T10:00:17.822 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-26T10:00:17.822 ProcessImageName: taskhostw.exe, Pid: 22840, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 19%

2025-11-26T10:00:17.822 ProcessImageName: updater.exe, Pid: 1464, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\38fb318b-84e3-44c0-bf9c-e37d72cc28ac.tmp, EstimatedImpact: 0%

2025-11-26T10:00:17.822 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\gamerecording.css, EstimatedImpact: 11%

2025-11-26T10:00:17.822 ProcessImageName: taskhostw.exe, Pid: 17956, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-26T10:00:17.822 ProcessImageName: updater.exe, Pid: 26080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\fe2cd894-40c3-481b-af28-5153e0a6aa38.tmp, EstimatedImpact: 0%

2025-11-26T10:04:02.599 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T10:06:18.087 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #316484, FileId: 0x70000000066827, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T10:19:07.596 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T10:21:18.660 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #316737, FileId: 0xbf000000012e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T10:34:12.589 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T10:36:19.051 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #316829, FileId: 0x880000000354da, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T10:49:17.584 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T10:51:19.424 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #316914, FileId: 0x4670000000122ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T10:52:06.974 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #316929, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T10:52:06.977 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #316930, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T10:52:16.981 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #316944, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T11:04:22.587 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T11:06:19.969 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #317168, FileId: 0x7800000003aa0f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T11:19:27.584 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T11:21:20.774 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #317415, FileId: 0x20c000000002262, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T11:21:53.609 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T11:34:32.579 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T11:36:21.163 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #317505, FileId: 0x8700000003aa19, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T11:49:37.562 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T11:51:21.964 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #317706, FileId: 0x3800000006e9fb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T11:52:07.943 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #317725, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T11:52:07.947 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #317726, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T11:52:17.946 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #317733, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T11:52:17.951 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #317734, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T12:00:17.795 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2731, Count: 259, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\90f6742b-bedd-45f8-ad7c-d6fe3d660b20.tmp, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1891, Count: 157, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\8645d48a-064b-4866-8a5c-0945327afbd2.tmp, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1630, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 89%

2025-11-26T12:00:17.795 ProcessImageName: RuntimeBroker.exe, Pid: 26368, TotalTime: 588, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-26T12:00:17.795 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 510, Count: 137, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 390, Count: 66, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 225, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: taskhostw.exe, Pid: 13804, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-26T12:00:17.795 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 120, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 90, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 4%

2025-11-26T12:00:17.795 ProcessImageName: StoreDesktopExtension.exe, Pid: 26300, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: taskhostw.exe, Pid: 22840, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 19%

2025-11-26T12:00:17.795 ProcessImageName: svchost.exe, Pid: 27240, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_637449242\BIT5FE6.tmp, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: updater.exe, Pid: 1464, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\38fb318b-84e3-44c0-bf9c-e37d72cc28ac.tmp, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\gamerecording.css, EstimatedImpact: 11%

2025-11-26T12:00:17.795 ProcessImageName: taskhostw.exe, Pid: 17956, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-26T12:00:17.795 ProcessImageName: taskhostw.exe, Pid: 22160, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 1%

2025-11-26T12:00:17.795 ProcessImageName: updater.exe, Pid: 26080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\fe2cd894-40c3-481b-af28-5153e0a6aa38.tmp, EstimatedImpact: 0%

2025-11-26T12:00:17.795 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-26T12:04:42.564 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T12:06:22.669 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #317999, FileId: 0x5e0000000433f8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T12:19:47.565 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T12:21:23.890 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #318352, FileId: 0x2400000006ea33, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T12:34:52.550 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T12:36:24.806 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #318431, FileId: 0x2600000006e9ef, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T12:49:57.548 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T12:51:25.809 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #318540, FileId: 0x9400000006e9f5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T12:52:06.405 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #318541, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T12:52:06.408 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #318542, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T12:52:16.419 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #318547, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T12:52:16.422 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #318548, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T13:05:02.550 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T13:06:26.781 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #318669, FileId: 0x28f00000000f9a4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T13:20:07.545 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T13:21:27.548 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #318922, FileId: 0x1f4000000003fe2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T13:21:55.460 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T13:35:12.531 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T13:36:28.665 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #318998, FileId: 0x730000000433f8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T13:50:17.526 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T13:51:29.612 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #319124, FileId: 0x81000000009a4e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T13:52:07.445 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #319149, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T13:52:07.449 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #319150, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T13:52:17.446 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #319159, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T13:52:17.450 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #319160, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T14:00:17.759 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3556, Count: 347, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\90f6742b-bedd-45f8-ad7c-d6fe3d660b20.tmp, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2581, Count: 209, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\8645d48a-064b-4866-8a5c-0945327afbd2.tmp, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1630, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 89%

2025-11-26T14:00:17.759 ProcessImageName: RuntimeBroker.exe, Pid: 26368, TotalTime: 588, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-26T14:00:17.759 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 540, Count: 152, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 435, Count: 72, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 330, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: taskhostw.exe, Pid: 13804, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-26T14:00:17.759 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 135, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 120, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 4%

2025-11-26T14:00:17.759 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\46f0646f-525e-40b5-9976-e244789e078c.tmp, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\favicon.ico, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: StoreDesktopExtension.exe, Pid: 26300, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: taskhostw.exe, Pid: 22840, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 19%

2025-11-26T14:00:17.759 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: svchost.exe, Pid: 27240, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_637449242\BIT5FE6.tmp, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: updater.exe, Pid: 1464, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\38fb318b-84e3-44c0-bf9c-e37d72cc28ac.tmp, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: taskhostw.exe, Pid: 17956, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-26T14:00:17.759 ProcessImageName: taskhostw.exe, Pid: 21056, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-26T14:00:17.759 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\gamerecording.css, EstimatedImpact: 11%

2025-11-26T14:00:17.759 ProcessImageName: taskhostw.exe, Pid: 22160, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 1%

2025-11-26T14:00:17.759 ProcessImageName: updater.exe, Pid: 26080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\fe2cd894-40c3-481b-af28-5153e0a6aa38.tmp, EstimatedImpact: 0%

2025-11-26T14:00:17.759 ProcessImageName: svchost.exe, Pid: 13360, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_20108_610853358\BITCC0F.tmp, EstimatedImpact: 0%

2025-11-26T14:03:51.178 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #319330, FileId: 0xc000000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T14:05:22.524 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T14:06:30.243 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #319341, FileId: 0x3600000003aa3e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T14:20:27.515 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T14:21:31.326 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #319949, FileId: 0x3f000000065770, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T14:35:32.515 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T14:36:32.334 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #320098, FileId: 0x38000000034745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T14:50:37.519 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T14:51:33.148 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #320265, FileId: 0x9000000003aa3b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T14:52:05.278 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #320268, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T14:52:05.282 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #320269, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T14:52:15.284 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #320275, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T14:52:15.285 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #320276, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T14:52:15.287 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #320277, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T14:52:15.288 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #320278, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T15:05:42.507 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T15:06:34.241 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #320547, FileId: 0x1da00000000b706, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T15:20:47.504 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T15:21:35.060 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #320815, FileId: 0x7700000003aa36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T15:21:57.539 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T15:35:52.492 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T15:36:36.005 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #320931, FileId: 0xc5000000012e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T15:41:11.819 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume4\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #321594, FileId: 0x43000000008e9e, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T15:50:57.501 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T15:51:36.833 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #321705, FileId: 0x22a000000002211, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T15:52:06.130 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #321724, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T15:52:06.133 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #321725, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T15:52:16.135 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #321732, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T15:52:16.138 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #321733, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T16:00:17.738 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 4397, Count: 434, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\90f6742b-bedd-45f8-ad7c-d6fe3d660b20.tmp, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3421, Count: 278, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\8645d48a-064b-4866-8a5c-0945327afbd2.tmp, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1630, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 89%

2025-11-26T16:00:17.738 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 660, Count: 184, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: RuntimeBroker.exe, Pid: 26368, TotalTime: 588, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-26T16:00:17.738 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 480, Count: 78, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 375, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 300, Count: 63, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: taskhostw.exe, Pid: 13804, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-26T16:00:17.738 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 165, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: ngentask.exe, Pid: 15676, TotalTime: 135, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 15%

2025-11-26T16:00:17.738 ProcessImageName: ngentask.exe, Pid: 22952, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 17%

2025-11-26T16:00:17.738 ProcessImageName: WmiPrvSE.exe, Pid: 8256, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 98%

2025-11-26T16:00:17.738 ProcessImageName: ngentask.exe, Pid: 5204, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 18%

2025-11-26T16:00:17.738 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: ngentask.exe, Pid: 18528, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 13%

2025-11-26T16:00:17.738 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\46f0646f-525e-40b5-9976-e244789e078c.tmp, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 4%

2025-11-26T16:00:17.738 ProcessImageName: ngentask.exe, Pid: 27240, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 54%

2025-11-26T16:00:17.738 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\favicon.ico, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: ngentask.exe, Pid: 3124, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 31%

2025-11-26T16:00:17.738 ProcessImageName: StoreDesktopExtension.exe, Pid: 26300, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: taskhostw.exe, Pid: 20484, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\BTHUSB.SYS, EstimatedImpact: 1%

2025-11-26T16:00:17.738 ProcessImageName: taskhostw.exe, Pid: 22840, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 19%

2025-11-26T16:00:17.738 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: svchost.exe, Pid: 27240, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_637449242\BIT5FE6.tmp, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: updater.exe, Pid: 1464, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\38fb318b-84e3-44c0-bf9c-e37d72cc28ac.tmp, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\gamerecording.css, EstimatedImpact: 11%

2025-11-26T16:00:17.738 ProcessImageName: taskhostw.exe, Pid: 21056, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-26T16:00:17.738 ProcessImageName: taskhostw.exe, Pid: 17956, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-26T16:00:17.738 ProcessImageName: taskhostw.exe, Pid: 22160, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 1%

2025-11-26T16:00:17.738 ProcessImageName: updater.exe, Pid: 26080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\fe2cd894-40c3-481b-af28-5153e0a6aa38.tmp, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: svchost.exe, Pid: 13360, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_20108_610853358\BITCC0F.tmp, EstimatedImpact: 0%

2025-11-26T16:00:17.738 ProcessImageName: updater.exe, Pid: 19872, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\4d8305d1-784f-45d8-9388-4e7875359567.tmp, EstimatedImpact: 0%

2025-11-26T16:06:02.493 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T16:06:38.000 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #321867, FileId: 0xc1000000011323, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T16:21:07.476 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T16:21:38.632 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #322115, FileId: 0x3600000000d0aa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T16:36:12.480 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T16:36:39.426 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #322202, FileId: 0xea000000008978, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T16:51:17.465 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T16:51:40.605 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #322320, FileId: 0x4700000001a949, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T16:52:06.755 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #322321, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T16:52:06.760 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #322322, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T16:52:16.756 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #322327, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T16:52:16.760 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #322328, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T17:06:22.456 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T17:06:41.705 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #322501, FileId: 0x4a00000001c3fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T17:21:27.451 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T17:21:42.920 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #322719, FileId: 0x2c400000000b554, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T17:21:59.544 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T17:29:17.750 Bm signature throttled:0x00002db31bed458f

2025-11-26T17:36:32.443 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T17:36:43.747 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #322869, FileId: 0x4e00000001c3fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T17:51:37.443 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T17:51:44.724 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #324363, FileId: 0xf100000001e1eb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T18:00:17.691 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 5298, Count: 521, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\90f6742b-bedd-45f8-ad7c-d6fe3d660b20.tmp, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4066, Count: 332, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\8645d48a-064b-4866-8a5c-0945327afbd2.tmp, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1630, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 89%

2025-11-26T18:00:17.691 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1306, Count: 187, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\7eb8c1d3e2e7f3e8df788864953ac8e3a2f2f9ea6c24360da73981ba66c054e5\Ontology64.dll, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 750, Count: 210, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: RuntimeBroker.exe, Pid: 26368, TotalTime: 588, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-26T18:00:17.691 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 480, Count: 85, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 450, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 315, Count: 71, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: taskhostw.exe, Pid: 13804, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-26T18:00:17.691 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 180, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 165, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\favicon.ico, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: ngentask.exe, Pid: 15676, TotalTime: 135, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 15%

2025-11-26T18:00:17.691 ProcessImageName: ngentask.exe, Pid: 22952, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 17%

2025-11-26T18:00:17.691 ProcessImageName: WmiPrvSE.exe, Pid: 8256, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 98%

2025-11-26T18:00:17.691 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\46f0646f-525e-40b5-9976-e244789e078c.tmp, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: ngentask.exe, Pid: 5204, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 18%

2025-11-26T18:00:17.691 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 1%

2025-11-26T18:00:17.691 ProcessImageName: ngentask.exe, Pid: 18528, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 13%

2025-11-26T18:00:17.691 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 31%

2025-11-26T18:00:17.691 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 4%

2025-11-26T18:00:17.691 ProcessImageName: ngentask.exe, Pid: 27240, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 54%

2025-11-26T18:00:17.691 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\Accounts\r_74DB6FURNR2TGPBK.bin, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: ngentask.exe, Pid: 3124, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 31%

2025-11-26T18:00:17.691 ProcessImageName: StoreDesktopExtension.exe, Pid: 26300, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: taskhostw.exe, Pid: 20484, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\BTHUSB.SYS, EstimatedImpact: 1%

2025-11-26T18:00:17.691 ProcessImageName: taskhostw.exe, Pid: 22840, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 19%

2025-11-26T18:00:17.691 ProcessImageName: nvngx_update.exe, Pid: 2264, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 5%

2025-11-26T18:00:17.691 ProcessImageName: svchost.exe, Pid: 27240, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_637449242\BIT5FE6.tmp, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: updater.exe, Pid: 1464, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\38fb318b-84e3-44c0-bf9c-e37d72cc28ac.tmp, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: taskhostw.exe, Pid: 21056, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-26T18:00:17.691 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\gamerecording.css, EstimatedImpact: 11%

2025-11-26T18:00:17.691 ProcessImageName: taskhostw.exe, Pid: 17956, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-26T18:00:17.691 ProcessImageName: taskhostw.exe, Pid: 22160, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 1%

2025-11-26T18:00:17.691 ProcessImageName: svchost.exe, Pid: 13360, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_20108_610853358\BITCC0F.tmp, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: updater.exe, Pid: 26080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\fe2cd894-40c3-481b-af28-5153e0a6aa38.tmp, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NvProfileUpdaterPlugin\optimus\metadata.json, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: nvngx_update.exe, Pid: 8172, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-26T18:00:17.691 ProcessImageName: updater.exe, Pid: 19872, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\4d8305d1-784f-45d8-9388-4e7875359567.tmp, EstimatedImpact: 0%

2025-11-26T18:01:37.638 Bm signature throttled:0x00002db31bed458f

2025-11-26T18:06:42.438 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T18:20:01.803 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\84DF2673-4FCC-4F7D-854F-245B235AA2EE5eb8.1dc5f0146d5d48c

2025-11-26T18:20:01.837 Verifying engine and signature files (source: 0) ...

2025-11-26T18:20:01.837 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5929965B-C42A-4FE3-8F57-D4BBC8D3C13C}\mpengine.dll] due to PPL.

2025-11-26T18:20:01.837 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5929965B-C42A-4FE3-8F57-D4BBC8D3C13C}\mpasbase.vdm] (file in cache)

2025-11-26T18:20:01.837 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5929965B-C42A-4FE3-8F57-D4BBC8D3C13C}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-26T18:20:01.847 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5929965B-C42A-4FE3-8F57-D4BBC8D3C13C}\mpasdlta.vdm]

2025-11-26T18:20:01.847 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5929965B-C42A-4FE3-8F57-D4BBC8D3C13C}\mpavbase.vdm] (file in cache)

2025-11-26T18:20:01.847 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5929965B-C42A-4FE3-8F57-D4BBC8D3C13C}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-26T18:20:01.857 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5929965B-C42A-4FE3-8F57-D4BBC8D3C13C}\mpavdlta.vdm]

2025-11-26T18:20:01.935 [Engine] IsHybridMode: 0

2025-11-26T18:20:01.936 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-26T18:20:01.946 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-8F193ECBE1A30E13094F8FDE7CAF669FD2917213.bin): 0x00000002

2025-11-26T18:20:01.948 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-8F193ECBE1A30E13094F8FDE7CAF669FD2917213.bin)

2025-11-26T18:20:01.948 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-26T18:20:01.948 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-26T18:20:01.948 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-26T18:20:01.948 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-26T18:20:07.498 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-26T18:20:07.498 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-26T18:20:07.504 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7225A660, lRefCount: 5, hr=0

2025-11-26T18:20:07.504 [Engine] New active engine 00007FFE4C3EA660 replacing engine 00007FFE7225A660. Number of active engines: 2

2025-11-26T18:20:07.511 EngineInit:Global ASOC is enabled

2025-11-26T18:20:07.511 EngineInit:ASOO is enabled for developer volumes

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.544 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-26T18:20:07.547 MpWriteUupSignatureVersion 1.441.513.0, hr = 0

2025-11-26T18:20:07.548 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-26T18:20:07.560 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-26T18:20:07.562 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-26T18:20:07.562 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-26T18:20:07.562 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-26T18:20:07.562 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-26T18:20:07.576 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-26T18:20:07.576 [Plugin] Initializing RTP plugin state...

2025-11-26T18:20:07.577 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-26T18:20:07.577 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 26 - 2025 07:00:18

Last Perf: 11 - 26 - 2025 07:00:17

First RTP Scan: 11 - 26 - 2025 07:00:18

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1060

  Misses:8075

BM Queue:0,37,0

  Proc:0,36,0

  File:0,13,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:324846

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1711612380

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:18

  TotalStreamCon:12322

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:1431121

   TotalHits:2358913

   InstanceCacheInserts:107508

   InstanceCacheUpdates:0

   InstanceCacheDeletes:82840

   InstanceCacheHits:4862

   InstanceCacheMisses:405262

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (1355/1732)

   Success: 1732, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-26T18:20:07.577 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5929965B-C42A-4FE3-8F57-D4BBC8D3C13C}

2025-11-26T18:20:07.577 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3513C622-E62F-4ED3-B7D5-58BC182A79A2}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3513C622-E62F-4ED3-B7D5-58BC182A79A2}\mpasbase.vdm in use, hr=0x80070020

2025-11-26T18:20:07.577 [SCC][CID=866437375_24104] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-26T18:20:07.578 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-26T18:20:07.578 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-26T18:20:07.578 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-26T18:20:07.578 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-26T18:20:07.579 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-26T18:20:07.579 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-26-2025 18:20:07

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-26-2025 18:20:07

2025-11-26T18:20:07.582 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-26T18:20:07.582 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-26T18:20:07.583 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-26T18:20:07.583 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-26-2025 18:20:07

END TDT(U) telemetry



2025-11-26T18:20:07.585 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T18:20:07.586 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-26T18:20:07.586 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-26T18:20:07.586 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-26T18:20:07.586 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-26T18:20:07.586 MdCoreSvc is supported in this platform and OS

Signature updated on 11-26-2025 18:20:07

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.513.0

AV Signature Version: 1.441.513.0

************************************************************

2025-11-26T18:20:07.587 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-26T18:20:07.587 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\84DF2673-4FCC-4F7D-854F-245B235AA2EE5eb8.1dc5f0146d5d48c

2025-11-26T18:20:07.594 Process scan (postsignatureupdatescan) started.

2025-11-26T18:20:07.628 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-26T18:20:07.629 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-26T18:20:07.765 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-26T18:20:07.765 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-26T18:20:07.765 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-26T18:20:07.765 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-26T18:20:07.765 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-26T18:20:07.766 [Engine] Engine 00007FFE7225A660 no longer in use. Number of active engines: 1

2025-11-26T18:20:07.767 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-26T18:20:07.767 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-26T18:20:07.922 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 5418, Count: 535, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\90f6742b-bedd-45f8-ad7c-d6fe3d660b20.tmp, EstimatedImpact: 0%

2025-11-26T18:20:07.922 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4171, Count: 340, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\8645d48a-064b-4866-8a5c-0945327afbd2.tmp, EstimatedImpact: 0%

2025-11-26T18:20:07.922 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1630, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 89%

2025-11-26T18:20:07.922 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1306, Count: 187, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\7eb8c1d3e2e7f3e8df788864953ac8e3a2f2f9ea6c24360da73981ba66c054e5\Ontology64.dll, EstimatedImpact: 0%

2025-11-26T18:20:07.922 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 765, Count: 224, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work, EstimatedImpact: 0%

2025-11-26T18:20:07.922 ProcessImageName: RuntimeBroker.exe, Pid: 26368, TotalTime: 588, Count: 22, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 31%

2025-11-26T18:20:07.922 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 480, Count: 85, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-26T18:20:07.922 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 465, Count: 50, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T18:20:07.922 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 315, Count: 71, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-26T18:20:07.922 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 195, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-26T18:20:07.922 ProcessImageName: taskhostw.exe, Pid: 13804, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-11-26T18:20:07.922 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 165, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-26T18:20:07.922 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\favicon.ico, EstimatedImpact: 0%

2025-11-26T18:20:07.922 ProcessImageName: ngentask.exe, Pid: 15676, TotalTime: 135, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 15%

2025-11-26T18:20:07.922 ProcessImageName: ngentask.exe, Pid: 22952, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 17%

2025-11-26T18:20:07.922 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-26T18:20:07.939 [Engine] RSIG_UNLOADENGINE, 00007FFE7225A660, err=0x0

2025-11-26T18:20:07.957 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3513C622-E62F-4ED3-B7D5-58BC182A79A2} removed

2025-11-26T18:20:08.074 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-26T18:20:08.082 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-26T18:20:08.082 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-26T18:20:08.082 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-26T18:20:08.082 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-26T18:20:08.082 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-26T18:20:08.082 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-26T18:20:08.085 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-26T18:20:08.085 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-26T18:20:08.085 [RTP] Duplicating the current plugin configuration object...

2025-11-26T18:20:08.085 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-26T18:20:08.085 [RTP] Updating plugin configuration due to recent config changes (0x22) ...

2025-11-26T18:20:08.085 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-26T18:20:08.085 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-26T18:20:08.085 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-26T18:20:08.085 [RTP] No config change detected. Not updating plugin configuration.

2025-11-26T18:20:08.085 [RTP] No config changes found. No configuration switch.

2025-11-26T18:20:08.085 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x22, Changed: 0

2025-11-26T18:20:08.085 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-26T18:20:08.085 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-26T18:20:08.085 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-26T18:20:08.085 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-26T18:20:08.085 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-26T18:20:08.085 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-26T18:20:08.085 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-26T18:20:08.085 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-26T18:20:08.085 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-26T18:20:08.085 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-26T18:20:08.085 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-26T18:20:08.086 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-26T18:20:08.086 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-26T18:20:08.086 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-26T18:20:08.086 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T18:20:08.088 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T18:20:08.089 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T18:20:08.091 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T18:20:08.092 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T18:20:08.093 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 24325020(ms) from now at 02:05 (01:05 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-26T18:20:09.594 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-26T18:20:09.598 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-26T18:20:09.599 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-26T18:20:10.618 [RTP] Duplicating the current plugin configuration object...

2025-11-26T18:20:10.618 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-26T18:20:10.618 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-26T18:20:10.618 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-26T18:20:10.618 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-26T18:20:12.988 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-26T18:20:12.988 [Cloud] Start of cloud request. Passive mode: 0

2025-11-26T18:20:12.988 [Cloud] Queued cloud request.

2025-11-26T18:20:12.988 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-26T18:20:12.988 [Cloud] Dequeued cloud request.

2025-11-26T18:20:12.989 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-26T18:20:13.432 [Cloud] End of cloud request.

2025-11-26T18:20:13.943 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-26T18:20:22.145 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-26T18:20:22.146 Process scan (postsignatureupdatescan) completed.

2025-11-26T18:21:45.832 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #324892, FileId: 0x76000000009229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T18:21:47.424 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T18:25:07.534 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-26T18:36:46.609 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #325604, FileId: 0xa000000015a26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T18:36:52.427 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T18:51:46.711 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #326170, FileId: 0x36000000003a27, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T18:51:57.426 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T18:52:06.657 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #326182, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T18:52:06.662 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #326183, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T18:52:16.660 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #326188, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T18:52:16.664 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #326190, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T19:06:47.301 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #326898, FileId: 0x1df00000000b8a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T19:07:02.413 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T19:21:48.129 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #327232, FileId: 0xfc000000015030, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T19:22:01.569 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T19:22:07.402 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T19:36:48.998 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #327372, FileId: 0x17000000015a54, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T19:37:12.404 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T19:51:50.023 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #327570, FileId: 0x42000000015a34, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T19:52:06.193 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #327602, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T19:52:06.196 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #327603, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T19:52:16.201 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #327610, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T19:52:16.202 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #327611, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T19:52:16.204 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #327612, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T19:52:16.205 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #327613, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T19:52:17.404 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T20:01:50.741 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #327764, FileId: 0xfc000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T20:06:50.827 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #327790, FileId: 0x1d000000000e076, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T20:07:22.398 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T20:20:07.476 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1381, Count: 75, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 82%

2025-11-26T20:20:07.476 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 859, Count: 144, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\1080p\Mona Lisa Smile 2003 BDRip ITA ENG 1080p x265 Paso77.mkv, EstimatedImpact: 2%

2025-11-26T20:20:07.476 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 766, Count: 83, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7626700b-431a-4255-a5a2-034b9a3abc60.tmp, EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 645, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\29aef894-2f65-45a4-beb3-db62f0d5c26e.tmp, EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: RuntimeBroker.exe, Pid: 16852, TotalTime: 601, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-26T20:20:07.476 ProcessImageName: WmiPrvSE.exe, Pid: 14496, TotalTime: 505, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 82%

2025-11-26T20:20:07.476 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 285, Count: 56, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: WmiPrvSE.exe, Pid: 8152, TotalTime: 270, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.LanguageExperiencePacknb-NO_26100.121.219.0_neutral__8wekyb3d8bbwe\Windows\System32\driverstore\nb-NO\wstorvsp.inf_loc->(UTF-16LE), EstimatedImpact: 25%

2025-11-26T20:20:07.476 ProcessImageName: taskhostw.exe, Pid: 26568, TotalTime: 180, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\ctac.json, EstimatedImpact: 12%

2025-11-26T20:20:07.476 ProcessImageName: WmiPrvSE.exe, Pid: 25708, TotalTime: 122, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\portcls.sys, EstimatedImpact: 100%

2025-11-26T20:20:07.476 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 120, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 105, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\DirectXApps.sdb, EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 45, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\532001fc78e4e796.customDestinations-ms, EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 3%

2025-11-26T20:20:07.476 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 1%

2025-11-26T20:20:07.476 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: StoreDesktopExtension.exe, Pid: 25776, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\gamerecording.css, EstimatedImpact: 24%

2025-11-26T20:20:07.476 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context->(Base64), EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: taskhostw.exe, Pid: 21340, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-26T20:20:07.476 ProcessImageName: updater.exe, Pid: 13324, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\8a3bb9bc-34a9-4441-8718-db748c05cde6.tmp, EstimatedImpact: 0%

2025-11-26T20:20:07.476 ProcessImageName: updater.exe, Pid: 8692, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\a6fe5447-e99c-4aad-a482-3ff3e55d2afd.tmp, EstimatedImpact: 0%

2025-11-26T20:21:27.749 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T20:21:51.718 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #328135, FileId: 0x1d900000000e076, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T20:22:27.382 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T20:34:37.905 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #328520, FileId: 0xc100000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T20:36:52.435 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #328530, FileId: 0x750000000145e0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T20:37:32.379 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T20:51:53.264 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #328769, FileId: 0x1700000006f05c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T20:52:06.428 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #328770, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T20:52:06.433 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #328771, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T20:52:16.430 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #328776, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T20:52:16.434 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #328777, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T20:52:37.381 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T20:53:03.774 Bm signature throttled:0x00002db31bed458f

2025-11-26T20:53:42.746 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #329181, FileId: 0xfd000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T20:54:37.307 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T20:55:12.663 Bm signature throttled:0x00002db31bed458f

2025-11-26T21:06:53.395 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #329437, FileId: 0x1900000006f892, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T21:07:42.367 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T21:21:53.629 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #329675, FileId: 0x14000000070359, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T21:22:47.366 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T21:36:54.327 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #329822, FileId: 0x12000000071907, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T21:37:52.359 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T21:41:48.667 Bm signature throttled:0x00002db31bed458f

2025-11-26T21:45:41.103 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #330074, FileId: 0xc200000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T21:51:55.066 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #330105, FileId: 0x14000000072acd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T21:52:05.520 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #330124, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T21:52:05.529 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #330125, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T21:52:15.516 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #330132, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T21:52:15.549 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #330135, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T21:52:57.360 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T22:00:21.931 Bm signature throttled:0x00002db31bed458f

2025-11-26T22:06:55.610 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #330396, FileId: 0x11000000075bf5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T22:08:02.360 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T22:10:20.050 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #330630, FileId: 0xfe000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T22:20:07.440 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1840, Count: 165, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7626700b-431a-4255-a5a2-034b9a3abc60.tmp, EstimatedImpact: 0%

2025-11-26T22:20:07.440 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1477, Count: 112, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\523db795-d077-4dc6-8788-0e8b71360067.tmp, EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1381, Count: 75, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 82%

2025-11-26T22:20:07.442 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 935, Count: 152, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\1080p\Mona Lisa Smile 2003 BDRip ITA ENG 1080p x265 Paso77.mkv, EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: RuntimeBroker.exe, Pid: 16852, TotalTime: 601, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-26T22:20:07.442 ProcessImageName: WmiPrvSE.exe, Pid: 14496, TotalTime: 505, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 82%

2025-11-26T22:20:07.442 ProcessImageName: powershell.exe, Pid: 23392, TotalTime: 411, Count: 45, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Pb378ec07#\9ec8e34db0f9a276fd69cc40d223721a\Microsoft.PowerShell.ConsoleHost.ni.dll, EstimatedImpact: 33%

2025-11-26T22:20:07.442 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 390, Count: 69, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 300, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: WmiPrvSE.exe, Pid: 8152, TotalTime: 270, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.LanguageExperiencePacknb-NO_26100.121.219.0_neutral__8wekyb3d8bbwe\Windows\System32\driverstore\nb-NO\wstorvsp.inf_loc->(UTF-16LE), EstimatedImpact: 25%

2025-11-26T22:20:07.442 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 225, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: taskhostw.exe, Pid: 26568, TotalTime: 180, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\ctac.json, EstimatedImpact: 12%

2025-11-26T22:20:07.442 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\Public\Desktop\Microsoft Edge.lnk, EstimatedImpact: 17%

2025-11-26T22:20:07.442 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 151, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: WmiPrvSE.exe, Pid: 25708, TotalTime: 122, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\portcls.sys, EstimatedImpact: 100%

2025-11-26T22:20:07.442 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 105, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\532001fc78e4e796.customDestinations-ms, EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 105, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\DirectXApps.sdb, EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 90, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 75, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 1%

2025-11-26T22:20:07.442 ProcessImageName: StoreDesktopExtension.exe, Pid: 25776, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\gamerecording.css, EstimatedImpact: 24%

2025-11-26T22:20:07.442 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\43eb1c4c-99e1-4249-b969-bbecc3def84d.tmp, EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context->(Base64), EstimatedImpact: 0%

2025-11-26T22:20:07.442 ProcessImageName: taskhostw.exe, Pid: 6536, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 9%

2025-11-26T22:20:07.442 ProcessImageName: taskhostw.exe, Pid: 21340, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-26T22:20:07.442 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 3096, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 1%

2025-11-26T22:20:07.442 ProcessImageName: ffdetect.exe, Pid: 25368, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 4%

2025-11-26T22:20:07.442 ProcessImageName: updater.exe, Pid: 13324, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\8a3bb9bc-34a9-4441-8718-db748c05cde6.tmp, EstimatedImpact: 0%

2025-11-26T22:20:07.443 ProcessImageName: updater.exe, Pid: 8692, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\a6fe5447-e99c-4aad-a482-3ff3e55d2afd.tmp, EstimatedImpact: 0%

2025-11-26T22:20:07.443 ProcessImageName: powershell.exe, Pid: 27716, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\__PSScriptPolicyTest_o5v2wkbv.upn.psm1, EstimatedImpact: 0%

2025-11-26T22:20:07.443 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 0%

2025-11-26T22:21:56.325 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #330746, FileId: 0x12000000076462, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T22:22:04.548 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T22:23:07.352 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T22:36:57.311 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #331168, FileId: 0x5000000076ce6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T22:38:12.345 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T22:40:36.806 Bm signature throttled:0x00002db31bed458f

2025-11-26T22:43:09.963 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\setup\logs\Install_2025-11-25_202126_26396-5248.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #331348, FileId: 0x160000000624cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T22:43:10.031 Bm signature throttled:0x0000fab3228bcd4d

2025-11-26T22:45:40.998 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #331498, FileId: 0xc300000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T22:51:58.176 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #331519, FileId: 0x44d000000000429, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T22:52:06.188 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #331521, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T22:52:06.191 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #331522, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T22:52:16.191 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #331527, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T22:52:16.197 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #331528, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T22:53:17.336 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T23:06:59.044 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #331789, FileId: 0x2e0000000779a7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T23:08:22.337 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T23:21:59.679 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #332037, FileId: 0x10000000078223, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T23:23:27.328 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T23:37:00.270 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #332118, FileId: 0x14000000077aee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T23:38:32.318 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-26T23:52:01.210 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #332235, FileId: 0x14000000077ddf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T23:52:06.981 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #332253, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T23:52:06.986 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #332254, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T23:52:16.992 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #332261, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T23:52:16.998 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #332262, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-26T23:53:37.312 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T00:00:39.907 Bm signature throttled:0x00002db31bed458f

2025-11-27T00:07:02.238 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #332848, FileId: 0x38000000077c76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T00:08:42.310 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T00:17:07.315 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3

2025-11-27T00:17:07.325 Job Notification: New process added to job (18292)

2025-11-27T00:17:07.338 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched

2025-11-27T00:17:07.343 Aggressive catchup quick scan threshold: 1678420787514 / 25920000000000

2025-11-27T00:17:07.352 Job Notification: New process added to job (11396)

2025-11-27T00:17:07.365 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:18292] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:11396]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-27T00:17:07.413 Job Notification: New process added to job (28348)

2025-11-27T00:17:07.415 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched

2025-11-27T00:17:07.417 Job Notification: New process added to job (24864)

2025-11-27T00:17:07.423 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:28348] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:24864]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-27T00:17:07.457 Job Notification: New process added to job (11172)

2025-11-27T00:17:07.459 Task(GetDeviceTicket -AccessKey E0A6DE93-E05E-EB91-F5F7-17975C0AC6A7 ) launched as network service

2025-11-27T00:17:07.864 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-27T00:17:07.864 [RTP] Duplicating the current plugin configuration object...

2025-11-27T00:17:07.864 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-27T00:17:07.864 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-27T00:17:07.864 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-27T00:17:07.864 [RTP] No config change detected. Not updating plugin configuration.

2025-11-27T00:17:07.864 [RTP] No config changes found. No configuration switch.

2025-11-27T00:17:07.864 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-27T00:17:07.949 Job Notification: Process exited from job (11172)

2025-11-27T00:17:08.160 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-27T00:17:08.160 [Cloud] Start of cloud request. Passive mode: 0

2025-11-27T00:17:08.160 [Cloud] Queued cloud request.

2025-11-27T00:17:08.160 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-27T00:17:08.161 [Cloud] Dequeued cloud request.

2025-11-27T00:17:08.161 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-27T00:17:08.161 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0

2025-11-27T00:17:08.161 [Cloud] Start of cloud request. Passive mode: 0

2025-11-27T00:17:08.161 [Cloud] Queued cloud request.

2025-11-27T00:17:08.161 [Cloud] Dequeued cloud request.

2025-11-27T00:17:08.163 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-27T00:17:08.241 [Cloud] End of cloud request.

2025-11-27T00:17:08.281 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-27T00:17:08.282 [Cloud] End of cloud request.

2025-11-27T00:17:08.700 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T00:17:24.900 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\84C44836-9875-4AE6-9939-D2A4309460A74e5c.1dc5f3333ebb189

2025-11-27T00:17:24.932 Verifying engine and signature files (source: 0) ...

2025-11-27T00:17:24.932 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{272CE70C-4C85-47DE-9CF6-C66154ECAF9B}\mpengine.dll] due to PPL.

2025-11-27T00:17:24.932 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{272CE70C-4C85-47DE-9CF6-C66154ECAF9B}\mpasbase.vdm] (file in cache)

2025-11-27T00:17:24.932 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{272CE70C-4C85-47DE-9CF6-C66154ECAF9B}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-27T00:17:24.942 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{272CE70C-4C85-47DE-9CF6-C66154ECAF9B}\mpasdlta.vdm]

2025-11-27T00:17:24.942 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{272CE70C-4C85-47DE-9CF6-C66154ECAF9B}\mpavbase.vdm] (file in cache)

2025-11-27T00:17:24.942 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{272CE70C-4C85-47DE-9CF6-C66154ECAF9B}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-27T00:17:24.952 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{272CE70C-4C85-47DE-9CF6-C66154ECAF9B}\mpavdlta.vdm]

2025-11-27T00:17:25.023 [Engine] IsHybridMode: 0

2025-11-27T00:17:25.024 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-27T00:17:25.034 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-FC2F982FEDAF16FD87582976C55A9AE8F2BC8E5E.bin): 0x00000002

2025-11-27T00:17:25.036 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-FC2F982FEDAF16FD87582976C55A9AE8F2BC8E5E.bin)

2025-11-27T00:17:25.036 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-27T00:17:25.036 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-27T00:17:25.036 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-27T00:17:25.036 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-27T00:17:30.409 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-27T00:17:30.409 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-27T00:17:30.415 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE4C3EA660, lRefCount: 5, hr=0

2025-11-27T00:17:30.415 [Engine] New active engine 00007FFE6F7CA660 replacing engine 00007FFE4C3EA660. Number of active engines: 2

2025-11-27T00:17:30.417 EngineInit:Global ASOC is enabled

2025-11-27T00:17:30.417 EngineInit:ASOO is enabled for developer volumes

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-27T00:17:30.448 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.449 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.449 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.449 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.449 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.449 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.449 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.449 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T00:17:30.450 MpWriteUupSignatureVersion 1.441.518.0, hr = 0

2025-11-27T00:17:30.451 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-27T00:17:30.464 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-27T00:17:30.465 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-27T00:17:30.465 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-27T00:17:30.465 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-27T00:17:30.465 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-27T00:17:30.479 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-27T00:17:30.479 [Plugin] Initializing RTP plugin state...

2025-11-27T00:17:30.479 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-27T00:17:30.479 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 26 - 2025 19:20:07

Last Perf: 11 - 26 - 2025 19:20:07

First RTP Scan: 11 - 26 - 2025 19:20:07

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:991

  Misses:5382

BM Queue:0,184,0

  Proc:0,179,0

  File:0,105,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:333124

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1798925586

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:18

  TotalStreamCon:10096

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:1498835

   TotalHits:2419317

   InstanceCacheInserts:110230

   InstanceCacheUpdates:0

   InstanceCacheDeletes:87191

   InstanceCacheHits:4995

   InstanceCacheMisses:420893

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (847/879)

   Success: 879, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-27T00:17:30.480 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{272CE70C-4C85-47DE-9CF6-C66154ECAF9B}

2025-11-27T00:17:30.480 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5929965B-C42A-4FE3-8F57-D4BBC8D3C13C}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5929965B-C42A-4FE3-8F57-D4BBC8D3C13C}\mpasbase.vdm in use, hr=0x80070020

2025-11-27T00:17:30.480 [SCC][CID=887880390_14484] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-27T00:17:30.481 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-27T00:17:30.481 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-27T00:17:30.481 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-27T00:17:30.481 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-27T00:17:30.481 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-27T00:17:30.481 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-27-2025 00:17:30

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-27-2025 00:17:30

2025-11-27T00:17:30.484 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-27T00:17:30.484 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-27T00:17:30.484 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-27T00:17:30.484 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-27-2025 00:17:30

END TDT(U) telemetry



2025-11-27T00:17:30.486 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T00:17:30.487 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-27T00:17:30.487 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-27T00:17:30.487 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-27T00:17:30.487 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-27T00:17:30.487 MdCoreSvc is supported in this platform and OS

Signature updated on 11-27-2025 00:17:30

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.518.0

AV Signature Version: 1.441.518.0

************************************************************

2025-11-27T00:17:30.488 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-27T00:17:30.488 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\84C44836-9875-4AE6-9939-D2A4309460A74e5c.1dc5f3333ebb189

2025-11-27T00:17:30.498 Process scan (postsignatureupdatescan) started.

2025-11-27T00:17:30.528 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-27T00:17:30.529 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

Signature updated via MicrosoftUpdateServer on 11-27-2025 00:17:30

************************************************************

2025-11-27T00:17:30.567 Job Notification: Process exited from job (28348)

2025-11-27T00:17:30.568 Job Notification: Process exited from job (24864)

2025-11-27T00:17:30.602 Job Notification: Process exited from job (18292)

2025-11-27T00:17:30.603 Job Notification: Process exited from job (11396)

2025-11-27T00:17:30.666 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-27T00:17:30.666 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-27T00:17:30.667 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-27T00:17:30.667 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-27T00:17:30.667 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-27T00:17:30.668 [Engine] Engine 00007FFE4C3EA660 no longer in use. Number of active engines: 1

2025-11-27T00:17:30.668 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-27T00:17:30.668 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-27T00:17:30.808 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3065, Count: 247, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\7626700b-431a-4255-a5a2-034b9a3abc60.tmp, EstimatedImpact: 0%

2025-11-27T00:17:30.808 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2338, Count: 164, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\3b3624a7-833f-4034-a660-9a85d6dd3f2e.tmp, EstimatedImpact: 0%

2025-11-27T00:17:30.808 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1381, Count: 75, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 82%

2025-11-27T00:17:30.808 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 965, Count: 154, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\1080p\Mona Lisa Smile 2003 BDRip ITA ENG 1080p x265 Paso77.mkv, EstimatedImpact: 0%

2025-11-27T00:17:30.808 ProcessImageName: RuntimeBroker.exe, Pid: 16852, TotalTime: 601, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-27T00:17:30.808 ProcessImageName: WmiPrvSE.exe, Pid: 14496, TotalTime: 505, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 82%

2025-11-27T00:17:30.808 ProcessImageName: powershell.exe, Pid: 23392, TotalTime: 411, Count: 45, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Pb378ec07#\9ec8e34db0f9a276fd69cc40d223721a\Microsoft.PowerShell.ConsoleHost.ni.dll, EstimatedImpact: 33%

2025-11-27T00:17:30.808 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 26396, TotalTime: 390, Count: 71, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-27T00:17:30.808 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 315, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T00:17:30.808 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 300, Count: 125, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work->(UTF-16LE), EstimatedImpact: 0%

2025-11-27T00:17:30.808 ProcessImageName: WmiPrvSE.exe, Pid: 8152, TotalTime: 270, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.LanguageExperiencePacknb-NO_26100.121.219.0_neutral__8wekyb3d8bbwe\Windows\System32\driverstore\nb-NO\wstorvsp.inf_loc->(UTF-16LE), EstimatedImpact: 25%

2025-11-27T00:17:30.808 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 227, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T00:17:30.808 ProcessImageName: taskhostw.exe, Pid: 26568, TotalTime: 180, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\ctac.json, EstimatedImpact: 12%

2025-11-27T00:17:30.808 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\Public\Desktop\Microsoft Edge.lnk, EstimatedImpact: 17%

2025-11-27T00:17:30.808 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 166, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-27T00:17:30.808 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-27T00:17:30.823 [Engine] RSIG_UNLOADENGINE, 00007FFE4C3EA660, err=0x0

2025-11-27T00:17:30.838 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5929965B-C42A-4FE3-8F57-D4BBC8D3C13C} removed

2025-11-27T00:17:30.978 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-27T00:17:30.984 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-27T00:17:30.984 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-27T00:17:30.985 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-27T00:17:30.985 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-27T00:17:30.985 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-27T00:17:30.985 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-27T00:17:30.988 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-27T00:17:30.988 [RTP] Duplicating the current plugin configuration object...

2025-11-27T00:17:30.988 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-27T00:17:30.988 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-27T00:17:30.988 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-27T00:17:30.988 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-27T00:17:30.988 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-27T00:17:30.988 [RTP] No config change detected. Not updating plugin configuration.

2025-11-27T00:17:30.988 [RTP] No config changes found. No configuration switch.

2025-11-27T00:17:30.988 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-27T00:17:30.988 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-27T00:17:30.988 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-27T00:17:30.988 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-27T00:17:30.988 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-27T00:17:30.988 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-27T00:17:30.988 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-27T00:17:30.988 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-27T00:17:30.988 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-27T00:17:30.988 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-27T00:17:30.988 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-27T00:17:30.988 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-27T00:17:30.988 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-27T00:17:30.988 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-27T00:17:30.988 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-27T00:17:30.988 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-27T00:17:30.989 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T00:17:30.990 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T00:17:30.992 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T00:17:30.994 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T00:17:30.995 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T00:17:30.997 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 6668913(ms) from now at 03:08 (02:08 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-27T00:17:32.498 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-27T00:17:32.502 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-27T00:17:32.503 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-27T00:17:33.549 [RTP] Duplicating the current plugin configuration object...

2025-11-27T00:17:33.549 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-27T00:17:33.549 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-27T00:17:33.549 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-27T00:17:33.549 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-27T00:17:35.737 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-27T00:17:35.737 [Cloud] Start of cloud request. Passive mode: 0

2025-11-27T00:17:35.737 [Cloud] Queued cloud request.

2025-11-27T00:17:35.737 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-27T00:17:35.737 [Cloud] Dequeued cloud request.

2025-11-27T00:17:35.737 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-27T00:17:36.061 [Cloud] End of cloud request.

2025-11-27T00:17:36.577 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T00:17:44.627 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-27T00:17:44.628 Process scan (postsignatureupdatescan) completed.

2025-11-27T00:22:03.678 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #333378, FileId: 0x8c000000037c6f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T00:22:30.466 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-27T00:23:39.470 [RTP] 31 newly mounted volumes accumulated, forcing a config update ...

2025-11-27T00:23:39.470 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy17\pagefile.sys

2025-11-27T00:23:39.470 [RTP] Duplicating the current plugin configuration object...

2025-11-27T00:23:39.470 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-27T00:23:39.470 [RTP] Updating plugin configuration due to recent config changes (0x1) ...

2025-11-27T00:23:39.470 [RTP] Calling GenerateEngineConfigStruct (0) ...

2025-11-27T00:23:39.470 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200

2025-11-27T00:23:41.336 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy17\pagefile.sys

2025-11-27T00:23:47.311 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T00:23:50.815 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy18\pagefile.sys

2025-11-27T00:23:52.824 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy18\pagefile.sys

2025-11-27T00:24:02.262 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy19\pagefile.sys

2025-11-27T00:24:04.167 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy19\pagefile.sys

Internal signature match:subtype=Lowfi, sigseq=0x0000157EE0FE8DC8, sigsha=f5846efe9949451de5145a9eacbdc8c7f901eab3, cached=false, source=2, resourceid=0x169e3e31

Internal signature match:subtype=Lowfi, sigseq=0x0000157E50AA0757, sigsha=f6d1ff14a6f5c5438ada4e530996c660ec877fa1, cached=false, source=2, resourceid=0x169e3e31

Internal signature match:subtype=Lowfi, sigseq=0x0000157ED4763E79, sigsha=b62b847555f2db81af8b15e89b574189c0edd86e, cached=false, source=2, resourceid=0x169e3e31

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=2, resourceid=0x169e3e31

Internal signature match:subtype=Lowfi, sigseq=0x00000555498DA744, sigsha=f9fe7263cd98e932bfa7989bfe514ab1a1359a57, cached=false, source=2, resourceid=0x169e3e31

Internal signature match:subtype=Lowfi, sigseq=0x0000DBE7E136D7DE, sigsha=1e15556f033e026f78e8816adff4c585631f3502, cached=false, source=2, resourceid=0x169e3e31

2025-11-27T00:24:13.126 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-27T00:24:13.126 [Cloud] Start of cloud request. Passive mode: 0

2025-11-27T00:24:13.126 [Cloud] Queued cloud request.

2025-11-27T00:24:13.126 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-27T00:24:13.126 [Cloud] Dequeued cloud request.

2025-11-27T00:24:13.126 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-27T00:24:13.452 Dynamic signature received

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\34f53f8d131da8b69ca1d13ec8e89c91e9256c6f

Dynamic Signature Compilation Timestamp:11-27-2025 00:24:13

Persistence Type:Duration

Time remaining:150196224

2025-11-27T00:24:13.453 [Cloud] End of cloud request.

2025-11-27T00:24:13.454 RTSD:RTSD recieved, rescanning impacted resources

2025-11-27T00:24:13.967 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T00:37:05.095 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #340109, FileId: 0x14000000076b18, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T00:38:52.307 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T00:52:05.810 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #340485, FileId: 0x39000000077c6c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T00:52:06.639 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #340486, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T00:52:06.643 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #340487, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T00:52:16.641 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #340493, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T00:52:16.644 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #340494, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T00:52:16.645 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #340495, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T00:53:57.308 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T01:07:06.238 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #340683, FileId: 0x4400000007779b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T01:09:02.291 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T01:22:06.621 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #341047, FileId: 0x36000000077d2f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T01:24:07.292 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T01:37:08.021 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #341308, FileId: 0x19000000077f58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T01:39:12.276 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T01:39:45.903 [AutoPurge] Verification Routine tasks have started.

2025-11-27T01:39:45.903 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-27T01:39:45.906 [AutoPurge] Routine task for Cache Maintenance has started.

2025-11-27T01:39:45.907 [AutoPurge] Routine task for Cache Maintenance ...

2025-11-27T01:39:45.907 [AutoPurge] Routine task for MpSFCBuild ...

2025-11-27T01:39:45.907 [AutoPurge] MpCmIsBuildCompleted() - S_OK

2025-11-27T01:39:45.907 [AutoPurge] MpSignalMaintenanceMode ...

2025-11-27T01:39:45.911 [AutoPurge] Cleanup Routine tasks have started.

2025-11-27T01:39:45.916 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:DC890A05-915B-46C9-816D-6A3C5F80B715, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1)

2025-11-27T01:39:45.916 Scheduled scan with Id DC890A05-915B-46C9-816D-6A3C5F80B715 configured CPU priority: normal (LowCpuPriority: 0)

2025-11-27T01:39:45.917 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0)

2025-11-27T01:39:45.917 [AutoPurge] Purged 0 expired detection item(s) from a total of 0.

2025-11-27T01:39:45.917 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds)

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:65538

Start time:11-27-2025 01:39:45

2025-11-27T01:39:45.917 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build.

2025-11-27T01:39:45.917 [SFC] System file cache build is not needed (already completed)

2025-11-27T01:39:45.917 QuickScan:ScanID:DC890A05-915B-46C9-816D-6A3C5F80B715: Quick Scan skipped since it already ran during the past 7 days

2025-11-27T01:39:45.918 QuickScan:ScanID:DC890A05-915B-46C9-816D-6A3C5F80B715: Quick scan finished with error 1223

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-27-2025 01:39:45

2025-11-27T01:39:45.918 OnDemandScanWorker: Scan Cancelled! scanId:DC890A05-915B-46C9-816D-6A3C5F80B715, hr = 0x80508018

!ERROR

Begin Quick Scan

Scan ID:{DC890A05-915B-46C9-816D-6A3C5F80B715}

Scan Source:1

Start Time:11-27-2025 01:39:45

Unsuccessful Scan

Return Code:1223

************************************************************



2025-11-27T01:39:45.921 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ...

2025-11-27T01:39:45.921 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0 ...

2025-11-27T01:39:45.921 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0 ...

2025-11-27T01:39:45.921 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ...

2025-11-27T01:39:45.924 [AutoPurge] Cleanup Routine tasks have ended.

2025-11-27T01:39:45.975 EnsureProtectedFolderAcls(), hr = 0x0

2025-11-27T01:39:45.977 [AutoPurge] MpReinforceServiceAcls: 0

2025-11-27T01:39:45.989 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0

2025-11-27T01:39:45.991 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed.

2025-11-27T01:39:45.992 [AutoPurge] Verification Routine tasks have ended.

2025-11-27T01:39:47.923 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-27T01:39:47.927 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-27T01:39:47.927 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-27T01:39:49.943 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-27T01:39:49.947 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-27T01:39:49.947 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-27T01:40:02.902 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-27T01:40:02.902 [Cloud] Start of cloud request. Passive mode: 0

2025-11-27T01:40:02.902 [Cloud] Queued cloud request.

2025-11-27T01:40:02.902 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-27T01:40:02.902 [Cloud] Dequeued cloud request.

2025-11-27T01:40:02.903 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-27T01:40:02.965 Engine:Setting original file name "WIARPC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiarpc.dll.mui_0c913b87", hr=0x0

2025-11-27T01:40:02.992 Engine:Setting original file name "nlsbres.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..ocale-nls.resources_31bf3856ad364e35_10.0.26100.4484_nb-no_339b02f7f61c146e\winnlsres.dll.mui", hr=0x0

2025-11-27T01:40:03.318 [Cloud] End of cloud request.

2025-11-27T01:40:03.340 Engine:Setting original file name "IEXPLORE.EXE" for "c:\program files (x86)\internet explorer\en-us\iexplore.exe.mui", hr=0x0

2025-11-27T01:40:03.370 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_en-us_1258b52c940aadb7_winload.efi.mui_35ee487d", hr=0x0

2025-11-27T01:40:03.842 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

2025-11-27T01:40:03.847 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sr-..-rs_d1943ecc8317ab66_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-27T01:40:03.853 [DLP] DlpEngineConfigStorage::OnConfigChange DlpDwordSettingsMap:

2025-11-27T01:40:03.853 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-27T01:40:03.853 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-27T01:40:03.853 [RTP] Duplicating the current plugin configuration object...

2025-11-27T01:40:03.853 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-27T01:40:03.853 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-27T01:40:03.853 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-27T01:40:03.853 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-27T01:40:03.853 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-27T01:40:03.853 [RTP] No config change detected. Not updating plugin configuration.

2025-11-27T01:40:03.853 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-27T01:40:03.853 [RTP] No config changes found. No configuration switch.

2025-11-27T01:40:03.853 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-27T01:40:03.853 [RTP] [RtpConfig] Config change detected, type: 16

2025-11-27T01:40:03.853 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-27T01:40:03.853 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-27T01:40:03.853 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-27T01:40:03.853 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-27T01:40:03.853 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-27T01:40:03.854 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-27T01:40:03.854 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-27T01:40:03.854 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-27T01:40:03.854 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-27T01:40:03.854 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-27T01:40:03.854 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-27T01:40:03.854 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T01:40:03.854 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-27T01:40:03.854 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-27T01:40:03.855 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-27T01:40:03.856 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T01:40:03.857 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T01:40:03.859 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T01:40:03.860 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T01:40:03.862 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 9672880(ms) from now at 05:21 (04:21 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-27T01:40:03.987 Engine:Setting original file name " " for "c:\program files (x86)\steam\bin\cef\cef.win7x64\dxcompiler.dll", hr=0x0

2025-11-27T01:40:04.034 Engine:Setting original file name "dual_engine_adapter.dll" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\dual_engine_adapter_x64.dll", hr=0x0

2025-11-27T01:40:04.179 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\winsxs\wow64_microsoft-windows-bcp47languages_31bf3856ad364e35_10.0.26100.7019_none_40ac55a9bb1ab239\bcp47langs.dll", hr=0x0

2025-11-27T01:40:04.192 Engine:Setting original file name "MAPI32.DLL.MUI" for "c:\windows\system32\nb-no\mapistub.dll.mui", hr=0x0

2025-11-27T01:40:04.367 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-27T01:40:04.407 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_ar-sa_af75f4ef024a79a1_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-27T01:40:04.475 Engine:Setting original file name "Apphelp" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a4bb088d5aa4193f97a4bdef0c1f8c71\apphelp.dll.mui", hr=0x0

2025-11-27T01:40:04.527 Engine:Setting original file name "F12Chooser.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-ie-iechooser.resources_31bf3856ad364e35_11.0.26100.1_nb-no_a7630c027f26ac69\iechooser.exe.mui", hr=0x0

2025-11-27T01:40:04.566 Engine:Setting original file name "THEMESERVICE.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-themeservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_5e5bf64d5b3ca824_themeservice.dll.mui_9e71f1ab", hr=0x0

2025-11-27T01:40:04.597 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_ad141a64b8fd6038_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:04.679 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\wow64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.26100.712_none_5cfec91758ee0662\windows.security.credentials.ui.credentialpicker.dll", hr=0x0

2025-11-27T01:40:04.735 Engine:Setting original file name "mavinject32.exe" for "c:\windows\winsxs\wow64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_592d553ad6e77100\mavinject.exe", hr=0x0

2025-11-27T01:40:04.861 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_bfcde09794ad7074_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-27T01:40:04.871 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\zh-cn\memtest.efi.mui", hr=0x0

2025-11-27T01:40:04.983 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_nb-no_022ea2e874b2cab6_winresume.efi.mui_f412814e", hr=0x0

2025-11-27T01:40:05.044 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lt-lt_11cd7cc1c62eb609_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:05.332 Engine:Setting original file name "WmiApSrv.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiapsrv.exe.mui_b1567840", hr=0x0

2025-11-27T01:40:05.391 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kk-kz_bb9a512b689c9b87_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:05.419 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_b5793645604cae79_memtest.efi.mui_71e15c22", hr=0x0

2025-11-27T01:40:05.434 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_he-il_3abd6f82e93c03e5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:05.442 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.26100.1_en-us_c3d82ef5c0380efa_wudfpf.sys.mui_f61e9e86", hr=0x0

2025-11-27T01:40:05.700 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaihdrx.dll", hr=0x0

2025-11-27T01:40:05.842 Engine:Setting original file name "l3codec.acm.mui" for "c:\windows\system32\nb-no\l3codeca.acm.mui", hr=0x0

2025-11-27T01:40:05.951 Engine:Setting original file name "w32topl.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_10.0.26100.1_none_cbd0eec659c2eb5c_w32topl.dll_1a0f388b", hr=0x0

2025-11-27T01:40:05.966 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ms-my_6f80e6fda2cebe8f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:06.243 Engine:Setting original file name "NVPTXJITCOMPILER32.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvptxjitcompiler64.dll", hr=0x0

2025-11-27T01:40:06.286 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5de87d4a39ffc584310f0b06dff9fcd0\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-27T01:40:06.370 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_38f499759ea365c4_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:06.398 [RTP] Duplicating the current plugin configuration object...

2025-11-27T01:40:06.398 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-27T01:40:06.398 [RTP] Updating plugin configuration due to recent config changes (0x41e) ...

2025-11-27T01:40:06.398 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-27T01:40:06.398 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x218

2025-11-27T01:40:06.424 Engine:Setting original file name "ddputils.lib.mui" for "c:\windows\system32\nb-no\ddputils.dll.mui", hr=0x0

2025-11-27T01:40:06.540 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kn-in_6e7a81f857a45cbe_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:06.576 Engine:Setting original file name "officeimm.odf" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\office.odf", hr=0x0

2025-11-27T01:40:06.785 Engine:Setting original file name ""AcGenral.dll"" for "c:\windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_10.0.26100.7019_none_a8119654a230db44\acgenral.dll", hr=0x0

2025-11-27T01:40:06.868 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sr-..-rs_7327597d7718c882_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:06.882 Engine:Setting original file name "Hyper-V Host Compute Service Diagnostics Tool" for "c:\windows\winsxs\amd64_hyperv-compute-cont..sticstool.resources_31bf3856ad364e35_10.0.26100.1_en-us_61074b8c7d2f38cf\hcsdiag.exe.mui", hr=0x0

2025-11-27T01:40:06.899 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.32530.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-27T01:40:06.939 Engine:Setting original file name "davsvc.dll.mui" for "c:\windows\system32\nb-no\webclnt.dll.mui", hr=0x0

2025-11-27T01:40:06.970 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\nb-no\wsepno.dll.mui", hr=0x0

2025-11-27T01:40:06.983 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x0

2025-11-27T01:40:07.019 Engine:Setting original file name "bootstr.exe.mui" for "c:\windows\system32\nb-no\bootstr.dll.mui", hr=0x0

2025-11-27T01:40:07.036 Engine:Setting original file name "msvcp140_2_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_2_app.dll", hr=0x0

2025-11-27T01:40:07.290 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-libraryloader-l1-1-0.dll", hr=0x0

2025-11-27T01:40:07.297 Engine:Setting original file name "dvsvc.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..rationsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_5c873aff49ea76e6\dcsvc.dll.mui", hr=0x0

2025-11-27T01:40:07.332 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_qps-ploc_5c9773f9ea1ce396_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:07.335 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_cs-cz_7086b4650c9e547c_memtest.efi.mui_71e15c22", hr=0x0

2025-11-27T01:40:07.441 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa78d0db4729269ff4beb393d45ca94a\dnsapi.dll.mui", hr=0x0

2025-11-27T01:40:07.457 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hr-hr_86baa9ad7eed6d52_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:07.500 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ja-jp_ed01f249e53f7235_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-27T01:40:07.504 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-file-l1-1-0.dll", hr=0x0

2025-11-27T01:40:07.532 Engine:Setting original file name "D3DX10.dll" for "c:\windows\system32\d3dx10_43.dll", hr=0x0

2025-11-27T01:40:07.612 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_da-dk_f5abc0a0339bc397_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:07.842 Engine:Setting original file name "Auto Enrollment DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..utoenroll.resources_31bf3856ad364e35_10.0.26100.1_en-us_b82b35a9c2228d6b\pautoenr.dll.mui", hr=0x0

2025-11-27T01:40:07.935 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\windows\winsxs\amd64_microsoft-textinput-helpers.resources_31bf3856ad364e35_10.0.26100.1_nb-no_2c9a52bac4b766e3\ime_textinputhelpers.dll.mui", hr=0x0

2025-11-27T01:40:07.952 Engine:Setting original file name "Ribbons" for "c:\windows\winsxs\amd64_microsoft-windows-ribbons.resources_31bf3856ad364e35_10.0.26100.1_en-us_f85e1124efc279b5\ribbons.scr.mui", hr=0x0

2025-11-27T01:40:08.002 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_18153ede37451276\memtest.exe.mui", hr=0x0

2025-11-27T01:40:08.049 Engine:Setting original file name "scecli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\978b70ff94ed14c641fe52c5237facec\scecli.dll.mui", hr=0x0

2025-11-27T01:40:08.070 Engine:Setting original file name "mpsdrv.sys.mui" for "c:\windows\winsxs\backup\amd64_networking-mpssvc-drv.resources_31bf3856ad364e35_10.0.26100.1_nb-no_05849dc2762f9d2d_mpsdrv.sys.mui_b2aea3b6", hr=0x0

2025-11-27T01:40:08.090 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-tw_21b451d70c8c2957_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-27T01:40:08.260 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_2b309b875a6f3e1e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:08.335 Engine:Setting original file name "Vulkan Runtime" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\vulkan-1.dll", hr=0x0

2025-11-27T01:40:08.378 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-p..i-ntprint.resources_31bf3856ad364e35_10.0.26100.1_en-us_6ff199c21e8ad886\ntprint.dll.mui", hr=0x0

2025-11-27T01:40:08.446 Engine:Setting original file name "bootstr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..environment-strings_31bf3856ad364e35_10.0.26100.1_none_f575b80d757af501\bootstr.dll", hr=0x0

2025-11-27T01:40:08.475 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_zh-cn_fd81e6b68df3d1a9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:08.658 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-27T01:40:08.797 Engine:Setting original file name "liblzma.dll" for "c:\program files\windowsapps\microsoft.6365217ce6eb4_102.2509.19002.0_x64__8wekyb3d8bbwe\lzma.dll", hr=0x0

2025-11-27T01:40:08.902 Engine:Setting original file name "wuapi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\uus\x86\nb-no\c120e79170c204b0e5f1ece795e86e83\wuapicore.dll.mui", hr=0x0

2025-11-27T01:40:08.984 Engine:Setting original file name "Ontology.dll" for "c:\users\serverpc\appdata\local\nvidia corporation\nvidia app\nvbackend\applicationontology\ontology64.dll", hr=0x0

2025-11-27T01:40:09.129 Engine:Setting original file name "VpnSohDesktop.dll" for "c:\windows\system32\windows.perception.stub.dll", hr=0x0

2025-11-27T01:40:09.214 Engine:Setting original file name "kernel32" for "c:\windows\syswow64\kernel32.dll", hr=0x0

2025-11-27T01:40:09.244 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.549981c3f5f10_4.2308.1005.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-27T01:40:09.450 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_b38289243d899c4c_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:09.524 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_82eb3d34cd19fa50_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:09.667 Engine:Setting original file name "Steamclient.dll" for "c:\program files (x86)\steam\steamclient64.dll", hr=0x0

2025-11-27T01:40:09.742 Engine:Setting original file name "VrdUmde.dll" for "c:\windows\winsxs\amd64_gpuvirtualizationumed_31bf3856ad364e35_10.0.26100.1150_none_17421023ba072774\vrdumed.dll", hr=0x0

2025-11-27T01:40:09.755 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.efi.mui", hr=0x0

2025-11-27T01:40:09.870 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25102.64.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x0

2025-11-27T01:40:09.909 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.winmd", hr=0x0

2025-11-27T01:40:10.278 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_lt-lt_ba1ae95b692b9594_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-27T01:40:10.399 Engine:Setting original file name "windows.ui.xaml.resources.win81.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ctui-resourceswin81_31bf3856ad364e35_10.0.26100.1301_none_b7b52abe3d381205_windows.ui.xaml.resources.win81.dll_d426e245", hr=0x0

2025-11-27T01:40:10.536 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-timezone-l1-1-0.dll", hr=0x0

2025-11-27T01:40:10.586 Engine:Setting original file name "jscript9.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\c3275836e276aea69afa458336037853\jscript9legacy.dll.mui", hr=0x0

2025-11-27T01:40:10.935 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x0

2025-11-27T01:40:10.995 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-profile-l1-1-0.dll", hr=0x0

2025-11-27T01:40:11.235 Engine:Setting original file name "Windows.FileExplorer.Common.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\84c8a2171c12d91e854ffb6a27b39453\windows.fileexplorer.common.dll.mui", hr=0x0

2025-11-27T01:40:11.453 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.26100.1_en-us_99a73e6649d69102\ndisimplatcim.dll.mui", hr=0x0

2025-11-27T01:40:11.502 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-27T01:40:11.695 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-localization-l1-2-0.dll", hr=0x0

2025-11-27T01:40:11.766 Engine:Setting original file name "Placeholder.dll" for "c:\windows\winsxs\x86_netfx4-penimc_v0400_b03f5f7f11d50a3a_4.0.15920.102_none_21046749883d249b\penimc_v0400.dll", hr=0x0

2025-11-27T01:40:11.792 Engine:Setting original file name "NvCamera.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\nvcameraallowlisting32.dll", hr=0x0

2025-11-27T01:40:12.062 Engine:Setting original file name ".NET Host Policy -" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\hostpolicy.dll", hr=0x0

2025-11-27T01:40:12.487 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sv-se_cac4b549037c269f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:12.493 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-27T01:40:12.527 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-27T01:40:12.547 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\winsxs\amd64_microsoft-windows-appx-deployment-server_31bf3856ad364e35_10.0.26100.7171_none_fd3893d466902045\applytrustoffline.exe", hr=0x0

2025-11-27T01:40:12.702 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\wow64_microsoft-windows-a..on-logger.resources_31bf3856ad364e35_10.0.26100.1_en-us_a0e09b8ec526451d\aeevts.dll.mui", hr=0x0

2025-11-27T01:40:12.806 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-27T01:40:13.000 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\4f8d3bb436c7\apex_particleschecked_x86.dll", hr=0x0

2025-11-27T01:40:13.084 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_it-it_72537c4985790e22_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:13.211 Engine:Setting original file name "EsclWiaDriver.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_esclwiadriver.dll.mui_d4a5b959", hr=0x0

2025-11-27T01:40:13.342 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_da-dk_be356ba870c91e76\msprivs.dll.mui", hr=0x0

2025-11-27T01:40:13.344 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-27T01:40:13.359 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_es-es_bdfd06f72820647a_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-27T01:40:13.480 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pl-pl\msprivs.dll.mui", hr=0x0

2025-11-27T01:40:13.497 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-27T01:40:13.521 Engine:Setting original file name "rmactivate.exe.mui" for "c:\windows\syswow64\en-us\rmactivate_isv.exe.mui", hr=0x0

2025-11-27T01:40:13.773 Engine:Setting original file name "apex.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\73be2921551d\apex_turbulencefschecked_x86.dll", hr=0x0

2025-11-27T01:40:13.801 Engine:Setting original file name "ScrCons" for "c:\windows\winsxs\amd64_microsoft-windows-w..consumers.resources_31bf3856ad364e35_10.0.26100.1_en-us_5d0e2df387a86d5d\scrcons.exe.mui", hr=0x0

2025-11-27T01:40:13.809 Engine:Setting original file name "PtpProv" for "c:\windows\winsxs\amd64_microsoft-windows-t..-provider.resources_31bf3856ad364e35_10.0.26100.1_en-us_eec70481b215edf0\ptpprov.dll.mui", hr=0x0

2025-11-27T01:40:13.857 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\resources\themes\aero\nb-no\aerolite.msstyles.mui", hr=0x0

2025-11-27T01:40:14.039 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_cd255b4d1be69fe9_winload.efi.mui_35ee487d", hr=0x0

2025-11-27T01:40:14.072 Engine:Setting original file name "pegi.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_en-us_58f534214187451c\pegi.rs.mui", hr=0x0

2025-11-27T01:40:14.078 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-iexpress.resources_31bf3856ad364e35_11.0.26100.1_en-us_f84c0d683fdc407b\wextract.exe.mui", hr=0x0

2025-11-27T01:40:14.559 Engine:Setting original file name "updater.exe" for "c:\program files (x86)\google\update\googleupdate.exe", hr=0x0

2025-11-27T01:40:14.725 Engine:Setting original file name "ServicingBase.dll" for "c:\windows\system32\servicingcommon.dll", hr=0x0

2025-11-27T01:40:14.751 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.exe.mui", hr=0x0

2025-11-27T01:40:14.950 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\vulkan-1.dll", hr=0x0

2025-11-27T01:40:14.999 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_c77eb7b609c47f12\diagpackage.dll.mui", hr=0x0

2025-11-27T01:40:15.125 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\system32\wbem\en-us\netadaptercim.dll.mui", hr=0x0

2025-11-27T01:40:15.152 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\syswow64\nb-no\wextract.exe.mui", hr=0x0

2025-11-27T01:40:15.271 Engine:Setting original file name "NvTelemetry.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvinstallerutil.dll", hr=0x0

2025-11-27T01:40:15.317 Engine:Setting original file name "NvMessageBusBroadcast.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\localsystem\_nvmsgbusbroadcast.dll", hr=0x0

2025-11-27T01:40:15.531 Engine:Setting original file name "NVOPENCL.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvopencl64.dll", hr=0x0

2025-11-27T01:40:15.539 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x0

2025-11-27T01:40:15.616 Engine:Setting original file name "Ribbons" for "c:\windows\system32\nb-no\ribbons.scr.mui", hr=0x0

2025-11-27T01:40:15.785 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_de-de_bb6100e4729f7310\msprivs.dll.mui", hr=0x0

2025-11-27T01:40:15.937 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_en-gb_943f70b729277031_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:15.969 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570\dnsapi.dll.mui", hr=0x0

2025-11-27T01:40:15.973 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x0

2025-11-27T01:40:16.071 Engine:Setting original file name "expediteupdater" for "c:\program files\microsoft update health tools\expediteupdater.exe", hr=0x0

2025-11-27T01:40:16.121 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5fc58c6fab06ca1651cc2f24f6b3294e\dnsapi.dll.mui", hr=0x0

2025-11-27T01:40:16.241 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-27T01:40:16.284 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-27T01:40:16.365 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pt-br\msprivs.dll.mui", hr=0x0

2025-11-27T01:40:16.426 Engine:Setting original file name "vcomp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-27T01:40:16.480 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_pt-br_45b1cef334010120_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-27T01:40:16.535 Engine:Setting original file name "DismProvPS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..ing-management-core_31bf3856ad364e35_10.0.26100.7019_none_c721839bdaa557fd\dismcoreps.dll", hr=0x0

2025-11-27T01:40:16.670 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x0

2025-11-27T01:40:16.707 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.efi", hr=0x0

2025-11-27T01:40:16.710 Engine:Setting original file name "ProfSvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-profsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_63afbc426d007f3f_profsvc.dll.mui_32482e9e", hr=0x0

2025-11-27T01:40:16.820 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2cfe4c864d785675f415b7e6aa962e4\msinfo32.exe.mui", hr=0x0

2025-11-27T01:40:17.060 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\6dfad87d7e49db84e1a96c1c1b32fef6\msidntld.dll.mui", hr=0x0

2025-11-27T01:40:17.077 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7\memtest.exe.mui", hr=0x0

2025-11-27T01:40:17.187 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pa-in_9c6b14ad918eaffd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:17.207 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ar-sa_51090f9ff64b96bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:17.255 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.26100.1_en-us_c94c280205b42295\bubbles.scr.mui", hr=0x0

2025-11-27T01:40:17.502 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\nb-no\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x0

2025-11-27T01:40:17.526 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-console-l1-2-0.dll", hr=0x0

2025-11-27T01:40:17.542 Engine:Setting original file name "SETUP.EXE.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-wow64-legacy.resources_31bf3856ad364e35_10.0.26100.1_nb-no_735ab890ce560efa\setup16.exe.mui", hr=0x0

2025-11-27T01:40:17.698 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x0

2025-11-27T01:40:17.732 Engine:Setting original file name "RarExt.dll" for "c:\program files\winrar\rarext32.dll", hr=0x0

2025-11-27T01:40:17.776 Engine:Setting original file name "pcw.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-pcw_31bf3856ad364e35_10.0.26100.1150_none_4bf8e6d5066a4f9f_pcw.sys_dbeb0bbd", hr=0x0

2025-11-27T01:40:17.869 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\syswow64\nb-no\ieadvpack.dll.mui", hr=0x0

2025-11-27T01:40:17.905 Engine:Setting original file name "EmbyServer.dll" for "c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe", hr=0x0

2025-11-27T01:40:18.019 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-environment-l1-1-0.dll", hr=0x0

2025-11-27T01:40:18.175 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2535f07be6867822893c0bd7f299affd\dwmcore.dll.mui", hr=0x0

2025-11-27T01:40:18.188 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_am-et_12002fbedc3ad139_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:18.229 Engine:Setting original file name "mavinject64.exe" for "c:\windows\winsxs\amd64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_4ed8aae8a286af05\mavinject.exe", hr=0x0

2025-11-27T01:40:18.403 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_b1cb38b404e84204\seclogon.dll.mui", hr=0x0

2025-11-27T01:40:18.447 Engine:Setting original file name "AuditPolicyGP.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\1e37baae98dce76981781b53776e70b9\auditpolicygpinterop.dll.mui", hr=0x0

2025-11-27T01:40:18.531 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9c4e95300400790b8d8a05d9bf7e1f5c\winnlsres.dll.mui", hr=0x0

2025-11-27T01:40:18.544 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e981bfd75ae177a858ec5c78a5cfda25\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-27T01:40:18.603 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-27T01:40:18.802 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ru-ru_e71c93fcf7d6f33e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:18.867 Engine:Setting original file name "qualityupdateassistant" for "c:\windows\system32\qualityupdateassistant.dll", hr=0x0

2025-11-27T01:40:18.878 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ro-ro_2c617f480dd85974_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:19.011 Engine:Setting original file name "wersvc" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2f884580919ab799dbe1ecd0f275799\wersvc.dll.mui", hr=0x0

2025-11-27T01:40:19.100 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_fa-ir_f7555235024374d9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:19.131 Engine:Setting original file name "ClrCompression" for "c:\program files\windowsapps\microsoft.net.native.runtime.1.7_1.7.25531.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-27T01:40:19.168 Engine:Setting original file name "WIASERVC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiaservc.dll.mui_54051b53", hr=0x0

2025-11-27T01:40:19.171 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-27T01:40:19.205 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ru-ru_0752c1c778fe6e7c_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-27T01:40:19.320 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-27T01:40:19.727 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_id-id_6be80829898706a2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:19.733 Engine:Setting original file name "STI.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_en-us_d64b3cbf22b2a8d1_sti.dll.mui_00a4f15b", hr=0x0

2025-11-27T01:40:19.742 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9035fe481934c33719e75dea902d1698\bcastdvruserservice.dll.mui", hr=0x0

2025-11-27T01:40:19.778 Engine:Setting original file name "NVIDIA Debug Dump" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvdebugdump.exe", hr=0x0

2025-11-27T01:40:19.798 Engine:Setting original file name "acpiex.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-acpiex_31bf3856ad364e35_10.0.26100.1150_none_d0b1f61a88e2f0e9_acpiex.sys_6a8b9aed", hr=0x0

2025-11-27T01:40:19.821 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_60b47cf61af27adc_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-27T01:40:19.839 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x0

2025-11-27T01:40:20.043 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sv-se_29319a980f7b0983_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-27T01:40:20.155 Engine:Setting original file name "pshed.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-pshed_31bf3856ad364e35_10.0.26100.1_none_633b3602ca01eb94_pshed.dll_f6ac239e", hr=0x0

2025-11-27T01:40:20.244 Engine:Setting original file name "ClipSVC.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-client-li..m-service.resources_31bf3856ad364e35_10.0.26100.1_en-us_3f436cbd520195fd_clipsvc.dll.mui_18823613", hr=0x0

2025-11-27T01:40:20.270 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_cy-gb_976c80cbdb5c65c1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:20.562 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_uk-ua_c5d15aec526b5235_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:20.635 Engine:Setting original file name "msfltr32.acm" for "c:\windows\winsxs\wow64_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_10.0.26100.1_none_e82ddbd17df6cb5b\msacm32.dll", hr=0x0

2025-11-27T01:40:20.694 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-27T01:40:20.710 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-27T01:40:20.765 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_6dcfa7c5391fe7a2_dnsapi.dll.mui_97465f8a", hr=0x0

2025-11-27T01:40:20.905 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_3cda2262e7ef70ab_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:21.014 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_10.0.26100.7171_none_f70fffd91c8f0404\winload.exe", hr=0x0

2025-11-27T01:40:21.183 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_et-ee_9786a4bcaafec5cb_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:21.463 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files\mozilla firefox\dxcompiler.dll", hr=0x0

2025-11-27T01:40:21.530 Engine:Setting original file name "Device_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\device\nb-no\edb83efa185c0a23d97fafe6a71cd608\diagpackage.dll.mui", hr=0x0

2025-11-27T01:40:21.555 Engine:Setting original file name "rtutils.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasrtutils_31bf3856ad364e35_10.0.26100.3037_none_a90518339a5ed736_rtutils.dll_243724ab", hr=0x0

2025-11-27T01:40:21.676 Engine:Setting original file name "udiapi.dll" for "c:\windows\system32\udiapiclient.dll", hr=0x0

2025-11-27T01:40:21.696 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-27T01:40:21.759 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaidvc.dll", hr=0x0

2025-11-27T01:40:21.764 Engine:Setting original file name "DWrite" for "c:\windows\winsxs\amd64_microsoft-windows-directwrite.resources_31bf3856ad364e35_10.0.26100.1_en-us_8e75f00536c95f8c\dwrite.dll.mui", hr=0x0

2025-11-27T01:40:21.773 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\windows\syswow64\nb-no\mfc40u.dll.mui", hr=0x0

2025-11-27T01:40:21.889 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.26100.1_en-us_12a038f1fa40c367_wlrmdr.exe.mui_ee563c83", hr=0x0

2025-11-27T01:40:21.984 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.xaml.winmd", hr=0x0

2025-11-27T01:40:22.067 Engine:Setting original file name "raspptp.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasbase-raspptp_31bf3856ad364e35_10.0.26100.1882_none_358d932997f7087d_raspptp.sys_25e89db1", hr=0x0

2025-11-27T01:40:22.173 Engine:Setting original file name "l3codec.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\17e7113a56f3171dc40844c9d3ee9e47\l3codeca.acm.mui", hr=0x0

2025-11-27T01:40:22.206 Engine:Setting original file name "bridgeres.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-networkbridge_31bf3856ad364e35_10.0.26100.2454_none_a3b07853b6183928_bridgeres.dll_55e40455", hr=0x0

2025-11-27T01:40:22.460 Engine:Setting original file name "mf.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..oundation.resources_31bf3856ad364e35_10.0.26100.1_en-us_8b9cc1ab2476fea1\mfpmp.exe.mui", hr=0x0

2025-11-27T01:40:22.566 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-processthreads-l1-1-1.dll", hr=0x0

2025-11-27T01:40:22.634 Engine:Setting original file name "FreeImage.dll" for "c:\program files (x86)\steam\steamapps\common\wallpaper_engine\bin\freeimage64.dll", hr=0x0

2025-11-27T01:40:22.639 Engine:Setting original file name "tier0_s.dll" for "c:\program files (x86)\steam\tier0_s64.dll", hr=0x0

2025-11-27T01:40:22.656 Engine:Setting original file name "nvaudcap.dll" for "c:\windows\syswow64\nvaudcap32v.dll", hr=0x0

2025-11-27T01:40:22.698 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mi-nz_b80bad72b6b0ee53_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:22.727 Engine:Setting original file name "CertCli" for "c:\windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_10.0.26100.1_en-us_61b2ff4b086153b8\certcli.dll.mui", hr=0x0

2025-11-27T01:40:22.732 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\en-us\wsepno.dll.mui", hr=0x0

2025-11-27T01:40:22.761 Engine:Setting original file name "ConfigurationRemotingServer.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\configurationremotingserver.exe", hr=0x0

2025-11-27T01:40:22.772 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_sr-..-rs_e67ffd847af5d250_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:22.776 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\power\en-us\diagpackage.dll.mui", hr=0x0

2025-11-27T01:40:22.801 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay8-payload_31bf3856ad364e35_1.0.26100.4202_none_bb7ce817a226517c\dpnaddr.dll", hr=0x0

2025-11-27T01:40:23.052 Engine:Setting original file name "msfltr32.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8836c193640d589410b5cc3dbe67e146\msacm32.dll.mui", hr=0x0

2025-11-27T01:40:23.157 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_6a24110114ad15ad_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-27T01:40:23.182 Engine:Setting original file name "usk.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\7c8e526d244ad657f882f8bbba0149ec\usk.rs.mui", hr=0x0

2025-11-27T01:40:23.195 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-27T01:40:23.215 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay4-payload_31bf3856ad364e35_1.0.26100.4202_none_186a372066698d60\dpmodemx.dll", hr=0x0

2025-11-27T01:40:23.408 Engine:Setting original file name "Register-CimProvider2.exe.mui" for "c:\windows\syswow64\en-us\register-cimprovider.exe.mui", hr=0x0

2025-11-27T01:40:23.515 Engine:Setting original file name "metabase.dll.mui" for "c:\windows\winsxs\wow64_microsoft-windows-iis-metabase.resources_31bf3856ad364e35_10.0.26100.1_en-us_8ff50fedc8451a7b\metadata.dll.mui", hr=0x0

2025-11-27T01:40:23.519 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x0

2025-11-27T01:40:23.608 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_de-de_ab2a1f0520f5ef2b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:23.679 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_6fced6fbf4c0e3e0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:23.821 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\en-us\diagpackage.dll.mui", hr=0x0

2025-11-27T01:40:23.843 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_7478bb53490dd7a8_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-27T01:40:23.898 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\windows\system32\nb-no\msidntld.dll.mui", hr=0x0

2025-11-27T01:40:23.903 Engine:Setting original file name "glu32" for "c:\windows\winsxs\amd64_microsoft-windows-opengl.resources_31bf3856ad364e35_10.0.26100.1_en-us_9c3b296d3d668ac3\glu32.dll.mui", hr=0x0

2025-11-27T01:40:23.925 Engine:Setting original file name "mf.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mediafoundation_31bf3856ad364e35_10.0.26100.7171_none_384874e2bca9ce3f\mfpmp.exe", hr=0x0

2025-11-27T01:40:23.963 Engine:Setting original file name "scesrv" for "c:\windows\system32\nb-no\scesrv.dll.mui", hr=0x0

2025-11-27T01:40:23.977 Engine:Setting original file name "DWWIN" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ae2b7dc24859d1fa2a509d5b642451b4\dwwin.exe.mui", hr=0x0

2025-11-27T01:40:24.121 Engine:Setting original file name "nvcuvid.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcuvid64.dll", hr=0x0

2025-11-27T01:40:24.157 Engine:Setting original file name "AppHostNameRegistrationVerifier.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\baf91a75f57ca8730dd9a6f926a58dd0\apphostregistrationverifier.exe.mui", hr=0x0

2025-11-27T01:40:24.169 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_en-gb_9672c12aaba943d2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:24.281 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-rtlsupport-l1-1-0.dll", hr=0x0

2025-11-27T01:40:24.302 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-27T01:40:24.330 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_gu-in_97d53b15f69aaeca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:24.382 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_84875939fc6b99b1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:24.400 Engine:Setting original file name "ServDeps.exe.mui" for "c:\windows\syswow64\wbem\nb-no\servdeps.dll.mui", hr=0x0

2025-11-27T01:40:24.436 Engine:Setting original file name "schtasks.exe" for "c:\windows\winsxs\amd64_microsoft-windows-sctasks_31bf3856ad364e35_10.0.26100.6725_none_25e27f3a6574108c\schtasks.exe", hr=0x0

2025-11-27T01:40:24.447 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_e38364b045f31518_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:24.501 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_el-gr_b382575af3d00da3_memtest.efi.mui_71e15c22", hr=0x0

2025-11-27T01:40:24.663 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.26100.1_en-us_0e875971ea5fda56\ieadvpack.dll.mui", hr=0x0

2025-11-27T01:40:24.707 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-datetime-l1-1-0.dll", hr=0x0

2025-11-27T01:40:24.732 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-27T01:40:24.759 Engine:Setting original file name "user32" for "c:\windows\system32\user32.dll", hr=0x0

2025-11-27T01:40:24.831 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.642.119.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-27T01:40:24.842 Engine:Setting original file name "shutdownui" for "c:\windows\winsxs\amd64_microsoft-windows-shutdownext.resources_31bf3856ad364e35_10.0.26100.1_en-us_9bd0f22e3578c871\shutdownext.dll.mui", hr=0x0

2025-11-27T01:40:25.002 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4\memtest.exe.mui", hr=0x0

2025-11-27T01:40:25.046 Engine:Setting original file name ".NET Host Resolver - 8.0.20" for "c:\users\serverpc\appdata\local\temp\emby-server-updater\hostfxr.dll", hr=0x0

2025-11-27T01:40:25.064 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_bs-..-ba_3017f7e2648d7e73_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:25.145 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_quz-pe_0266e81632046792_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:25.250 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lb-lu_cb546bb0b0d79a98_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:25.286 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\amd64_microsoft-windows-a..perience-ait-static_31bf3856ad364e35_10.0.26100.7019_none_ccd1f49f5e2b3b28\aitstatic.exe", hr=0x0

2025-11-27T01:40:25.379 Engine:Setting original file name "UNPShared.dll" for "c:\windows\winsxs\amd64_microsoft-windows-update-upshared_31bf3856ad364e35_10.0.26100.5074_none_29764f36135e6d4c\upshared.dll", hr=0x0

2025-11-27T01:40:25.460 Engine:Setting original file name "messagin.dll" for "c:\program files\bitdefender agent\27.1.1.23\messaging.dll", hr=0x0

2025-11-27T01:40:25.539 Engine:Setting original file name "WindowsCodecs" for "c:\windows\syswow64\windowscodecs.dll", hr=0x0

2025-11-27T01:40:25.577 Engine:Setting original file name "WerMgr" for "c:\windows\system32\wermgr.exe", hr=0x0

2025-11-27T01:40:25.622 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d\memtest.exe.mui", hr=0x0

2025-11-27T01:40:25.625 Engine:Setting original file name "imapi.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bd7c223153b9576fe4c4e66ebf1c6ece\imapi.dll.mui", hr=0x0

2025-11-27T01:40:25.745 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hi-in_8555c5797fc8795e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:25.819 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\esrb.rs.mui", hr=0x0

2025-11-27T01:40:25.832 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\updated\nmhproxy.exe", hr=0x0

2025-11-27T01:40:25.911 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-27T01:40:25.932 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_zh-tw_ff4ad39908e2da78_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:25.936 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-27T01:40:25.983 Engine:Setting original file name "microsoftedgedevtools.exe" for "c:\windows\system32\microsoftedgecp.exe", hr=0x0

2025-11-27T01:40:26.003 Engine:Setting original file name "la57setup.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ec428185df2994f7d7954c1efe1b2738\la57setup.exe.mui", hr=0x0

2025-11-27T01:40:26.010 Engine:Setting original file name "wuapi.dll" for "c:\windows\uus\x86\wuapicore.dll", hr=0x0

2025-11-27T01:40:26.079 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\system32\en-us\dsprop.dll.mui", hr=0x0

2025-11-27T01:40:26.326 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-27T01:40:26.345 Engine:Setting original file name "etweseproviderresources.dll" for "c:\windows\winsxs\backup\amd64_microsoft-etw-ese_31bf3856ad364e35_10.0.26100.1_none_cc4e7afeeee8d3b1_etweseproviderresources.dll_f21e8ea7", hr=0x0

2025-11-27T01:40:26.409 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_2821a024e044bada_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:26.411 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-27T01:40:26.450 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bf8ce2a53903d9e6d302aee07de95dd9\mfc40u.dll.mui", hr=0x0

2025-11-27T01:40:26.465 Engine:Setting original file name "TAPISRV.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-tapiservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_83c985f74a352be9\tapisrv.dll.mui", hr=0x0

2025-11-27T01:40:26.660 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lo-la_099683f3cb70d44f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:26.662 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x0

2025-11-27T01:40:26.753 Engine:Setting original file name "wininet.dll" for "c:\windows\systemresources\wininet.dll.mun", hr=0x0

2025-11-27T01:40:26.781 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\nb-no\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x0

2025-11-27T01:40:26.799 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_hu-hu_9dd052ebcaf187fd_memtest.efi.mui_71e15c22", hr=0x0

2025-11-27T01:40:26.802 Engine:Setting original file name "PrintBrmEng.exe.mui" for "c:\windows\system32\spool\tools\en-us\printbrmengine.exe.mui", hr=0x0

2025-11-27T01:40:26.804 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_it-it_4087c8eabdc39e5f_memtest.efi.mui_71e15c22", hr=0x0

2025-11-27T01:40:26.835 Engine:Setting original file name "audioadg.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f411807b0749e7d602e77baf3c1c4e60\audiodg.exe.mui", hr=0x0

2025-11-27T01:40:26.903 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x0

2025-11-27T01:40:26.974 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-t..iprovider.resources_31bf3856ad364e35_10.0.26100.1_en-us_41b711b4f2db4fe7\rdpsign.exe.mui", hr=0x0

2025-11-27T01:40:27.102 Engine:Setting original file name "Video_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\video\nb-no\2ca5a0690699da595bd35a22420a1c04\diagpackage.dll.mui", hr=0x0

2025-11-27T01:40:27.110 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-27T01:40:27.130 Engine:Setting original file name "FvSDKTestClientPublic" for "c:\program files\nvidia corporation\frameviewsdk\sdk\fvsdktestclient_public.exe", hr=0x0

2025-11-27T01:40:27.172 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\qps-ploc\msprivs.dll.mui", hr=0x0

2025-11-27T01:40:27.174 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-27T01:40:27.354 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files\mozilla firefox\updated\dxcompiler.dll", hr=0x0

2025-11-27T01:40:27.460 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\windows\system32\nb-no\pnpclean.dll.mui", hr=0x0

2025-11-27T01:40:27.473 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_or-in_f89501f89f876dc5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:27.507 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.26100.7171_none_4ad020869b677502\taskmgr.exe.mun", hr=0x0

2025-11-27T01:40:27.557 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_ca98740be1962356_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:27.613 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x0

2025-11-27T01:40:27.672 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_it-it_f0fca0072ba86c5a\msprivs.dll.mui", hr=0x0

2025-11-27T01:40:27.717 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps-ploc_7ccda1c46b445ed4\memtest.exe.mui", hr=0x0

2025-11-27T01:40:27.737 Engine:Setting original file name "NETBIOS.SYS" for "c:\windows\winsxs\backup\amd64_microsoft-windows-netbios_31bf3856ad364e35_10.0.26100.1_none_56d5608ad3abe945_netbios.sys_6f23c4df", hr=0x0

2025-11-27T01:40:27.800 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-process-l1-1-0.dll", hr=0x0

2025-11-27T01:40:27.936 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\systemresources\etwcoreuicomponentsresources.dll.mun", hr=0x0

2025-11-27T01:40:27.948 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pt-br_55b72b827c87f88f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:28.063 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_0dc0948c02e4507b_memtest.efi.mui_71e15c22", hr=0x0

2025-11-27T01:40:28.076 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mt-mt_b4ebaa02b8bfece3_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:28.108 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.devices.winmd", hr=0x0

2025-11-27T01:40:28.144 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_576ce8a1070e9744_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:28.157 Engine:Setting original file name "FileInfo.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-fileinfominifilter_31bf3856ad364e35_10.0.26100.1150_none_729c4b9be137bb96_fileinfo.sys_9be2dfcd", hr=0x0

2025-11-27T01:40:28.235 Engine:Setting original file name "aclui.dll" for "c:\windows\winsxs\amd64_microsoft-windows-aclui_31bf3856ad364e35_10.0.26100.7019_none_f0f7bbb4638cf785\aclui.dll.mun", hr=0x0

2025-11-27T01:40:28.239 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\73be2921551d\apex_fieldsamplerchecked_x86.dll", hr=0x0

2025-11-27T01:40:28.296 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.777.2143.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-27T01:40:28.366 Engine:Setting original file name "qualityupdateassistant" for "c:\program files\microsoft update health tools\qualityupdateassistant.dll", hr=0x0

2025-11-27T01:40:28.389 Engine:Setting original file name "NVPPE.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvppex.dll", hr=0x0

2025-11-27T01:40:28.471 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_en-us_4761fcc7ecd6d884_winresume.efi.mui_f412814e", hr=0x0

2025-11-27T01:40:28.650 Engine:Setting original file name "NVPrxy.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvprxy32.dll", hr=0x0

2025-11-27T01:40:28.754 Engine:Setting original file name "Mystify" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\589bec7339e102473dc7566c3b9b0f45\mystify.scr.mui", hr=0x0

2025-11-27T01:40:28.778 Engine:Setting original file name "volmgrx.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..memanager.resources_31bf3856ad364e35_10.0.26100.1_en-us_a18734abf077f9b4_volmgrx.sys.mui_b0c205d7", hr=0x0

2025-11-27T01:40:28.813 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-27T01:40:28.915 Engine:Setting original file name "libcrypto" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\libcrypto-3-x64.dll", hr=0x0

2025-11-27T01:40:28.936 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-string-l1-1-0.dll", hr=0x0

2025-11-27T01:40:28.969 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hi-in_83227505fd46a5bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:29.009 Engine:Setting original file name "CertCa" for "c:\windows\winsxs\amd64_microsoft-windows-c..ertca-dll.resources_31bf3856ad364e35_10.0.26100.1_nb-no_25e015431023bb9b\certca.dll.mui", hr=0x0

2025-11-27T01:40:29.108 Engine:Setting original file name "PCW_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_ddc581f4a364804b\diagpackage.dll.mui", hr=0x0

2025-11-27T01:40:29.206 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..subsystem.resources_31bf3856ad364e35_10.0.26100.1_nb-no_ab8620bc0ed41a36\scardsvr.dll.mui", hr=0x0

2025-11-27T01:40:29.223 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_6.0.3624.51421.dll", hr=0x0

2025-11-27T01:40:29.301 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-27T01:40:29.334 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_06d4a9c0547686dc\msprivs.dll.mui", hr=0x0

2025-11-27T01:40:29.486 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mapi_31bf3856ad364e35_10.0.26100.7019_none_473a9ee5c9a5ebee\mapistub.dll", hr=0x0

2025-11-27T01:40:29.604 Engine:Setting original file name "mofcomp.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_nb-no_8c87dcbbb8114be3_mofcomp.exe.mui_35badf56", hr=0x0

2025-11-27T01:40:29.608 Engine:Setting original file name "MspsProv.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..oning-wmi.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd6de3cbb42de1cb\mspsprov.dll.mui", hr=0x0

2025-11-27T01:40:29.653 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x0

2025-11-27T01:40:29.750 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.26100.7019_none_4a484d6501b73a17\wwanapi.dll", hr=0x0

2025-11-27T01:40:29.819 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ne-np_591939d32e7d4223_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:29.892 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.xboxidentityprovider_12.130.16001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-27T01:40:30.251 Engine:Setting original file name "Operativsystemet Microsoft� Windows�" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e2a170892be5347a116ae0806fb5309d\pcalua.exe.mui", hr=0x0

2025-11-27T01:40:30.342 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x0

2025-11-27T01:40:30.357 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x0

2025-11-27T01:40:30.639 Engine:Setting original file name "imageres.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-imageres_31bf3856ad364e35_10.0.26100.1_none_d9b14b936072a0bc\imageres.dll.mun", hr=0x0

2025-11-27T01:40:30.853 Engine:Setting original file name "vcruntime140.dll" for "c:\config.msi\1c742.rbf", hr=0x0

2025-11-27T01:40:30.892 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-27T01:40:30.934 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_kk-kz_71b9c9e0d19e9ee0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:31.120 Engine:Setting original file name "Apps_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\apps\nb-no\d2a92c7cfed83dc547a21508b5b0ea0f\diagpackage.dll.mui", hr=0x0

2025-11-27T01:40:31.137 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32.dll", hr=0x0

2025-11-27T01:40:31.192 Engine:Setting original file name "CertPKICmdlet" for "c:\windows\system32\en-us\certpkicmdlet.dll.mui", hr=0x0

2025-11-27T01:40:31.243 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ed4232cecc06e9efb72d2a7c142b63b4\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x0

2025-11-27T01:40:31.253 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.424.1611.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-27T01:40:31.314 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_0cb2119581e88ce0\diagpackage.dll.mui", hr=0x0

2025-11-27T01:40:31.473 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\system32\bcp47langs.dll", hr=0x0

2025-11-27T01:40:31.548 Engine:Setting original file name "gpapi.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-g..licy-base.resources_31bf3856ad364e35_10.0.26100.1_en-us_be2843fbd972ca37_gpapi.dll.mui_ef0a9748", hr=0x0

2025-11-27T01:40:31.602 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x0

2025-11-27T01:40:31.611 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\winsxs\amd64_microsoft-windows-aerolite.resources_31bf3856ad364e35_10.0.26100.1_en-us_bc993ceae8fc48bf\aerolite.msstyles.mui", hr=0x0

2025-11-27T01:40:31.887 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\en-us\utilman.exe.mui", hr=0x0

2025-11-27T01:40:31.925 Engine:Setting original file name "clrgc.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25102.64.0_x64__8wekyb3d8bbwe\clrgcexp.dll", hr=0x0

2025-11-27T01:40:32.028 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x0

2025-11-27T01:40:32.137 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-27T01:40:32.145 Engine:Setting original file name "sqlite3" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\sqlite3.dll", hr=0x0

2025-11-27T01:40:32.206 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x0

2025-11-27T01:40:32.253 Engine:Setting original file name "w32time.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-time-tool.resources_31bf3856ad364e35_10.0.26100.1_en-us_7b897a2738f484fc\w32tm.exe.mui", hr=0x0

2025-11-27T01:40:32.257 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd473133072db5bb\diagpackage.dll.mui", hr=0x0

2025-11-27T01:40:32.282 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_80a1d04cb31f8eca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:32.287 Engine:Setting original file name "ERC" for "c:\windows\system32\nb-no\wercplsupport.dll.mui", hr=0x0

2025-11-27T01:40:32.317 Engine:Setting original file name "vdsutil.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-v..skservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_59d12af3dce743c1_vdsutil.dll.mui_0caf9b0e", hr=0x0

2025-11-27T01:40:32.405 Engine:Setting original file name "AppLockerCSP.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appidcore.resources_31bf3856ad364e35_10.0.26100.1_en-us_564c6ad9b132641f_applockercsp.dll.mui_d2a0df70", hr=0x0

2025-11-27T01:40:32.460 Engine:Setting original file name "dnsrslvr.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570_dnsrslvr.dll.mui_1e1a1ed1", hr=0x0

2025-11-27T01:40:32.527 Engine:Setting original file name "PSAPI" for "c:\windows\winsxs\backup\wow64_microsoft-windows-basedependencies_31bf3856ad364e35_10.0.26100.1_none_09ea4476c5bcc4c0_psapi.dll_e8b5b4d1", hr=0x0

2025-11-27T01:40:32.553 Engine:Setting original file name "AcPlugin.dll" for "c:\program files\windowsapps\microsoft.applicationcompatibilityenhancements_1.2511.9.0_x64__8wekyb3d8bbwe\amd64\acplugin_test.dll", hr=0x0

2025-11-27T01:40:32.564 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\426c2b1101abec586136a4bbd67a716e\narrator.exe.mui", hr=0x0

2025-11-27T01:40:32.582 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..tiator_ui.resources_31bf3856ad364e35_10.0.26100.1_en-us_7967a83a130d426e\iscsicpl.dll.mui", hr=0x0

2025-11-27T01:40:32.670 Engine:Setting original file name "WindowsMediaPlayerPlayDVD_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_587c1f8aa98a4a71\diagpackage.dll.mui", hr=0x0

2025-11-27T01:40:32.858 Engine:Setting original file name "scecli" for "c:\windows\system32\nb-no\scecli.dll.mui", hr=0x0

2025-11-27T01:40:32.875 Engine:Setting original file name "scesrv" for "c:\windows\winsxs\amd64_microsoft-windows-s..ionengine.resources_31bf3856ad364e35_10.0.26100.1_en-us_e63bd45b831a32e3\scesrv.dll.mui", hr=0x0

2025-11-27T01:40:32.906 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_bg-bg_af9bba51d24fbf0e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:32.966 Engine:Setting original file name "nvhda.sys" for "c:\windows\system32\driverstore\filerepository\nvhda.inf_amd64_c32d8360d192a82e\nvhda64v.sys", hr=0x0

2025-11-27T01:40:32.975 Engine:Setting original file name "wmiutils.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiutils.dll.mui_42583eaf", hr=0x0

2025-11-27T01:40:32.990 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_te-in_e10bae4a47776b9f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:33.020 Engine:Setting original file name "BdncProxy.dll" for "c:\program files\bitdefender agent\27.1.1.23\crash_handler\bdnc.dll", hr=0x0

2025-11-27T01:40:33.092 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.26100.1_nb-no_e175a2f7bf27ee8d_ws2ifsl.sys.mui_b672c7b4", hr=0x0

2025-11-27T01:40:33.155 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_eu-es_e55e702bbb854a24_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:33.190 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-msinfo32-exe.resources_31bf3856ad364e35_10.0.26100.1_en-us_53ae64398a08feba\msinfo32.exe.mui", hr=0x0

2025-11-27T01:40:33.235 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-27T01:40:33.332 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x86__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-27T01:40:33.351 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x0

2025-11-27T01:40:33.450 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x0

2025-11-27T01:40:33.457 Engine:Setting original file name "NxCooking.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\v2.7.6\physxcooking.dll", hr=0x0

2025-11-27T01:40:33.485 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-27T01:40:33.623 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x0

2025-11-27T01:40:33.697 Engine:Setting original file name "filterLib.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\4fffc8576907b0b5da815790887fb244\fltlib.dll.mui", hr=0x0

2025-11-27T01:40:33.726 Engine:Setting original file name "srpuxgp.dll" for "c:\windows\systemresources\srpuxnativesnapin.dll.mun", hr=0x0

2025-11-27T01:40:33.728 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-27T01:40:33.916 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_nl-nl_0d26e65c98dbf6f7_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:33.926 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sl-si_8549ba61ed8af84b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:33.930 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x0

2025-11-27T01:40:34.097 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_pl-pl_9d43c82914fc6152_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:34.118 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.web.winmd", hr=0x0

2025-11-27T01:40:34.179 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-27T01:40:34.296 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ca-es_584cefb2c144b7d8_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:34.305 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\winsxs\amd64_microsoft-windows-qedwipes_31bf3856ad364e35_10.0.26100.1_none_5473011012d79dc1\qedwipes.dll.mun", hr=0x0

2025-11-27T01:40:34.469 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_et-ee_4da61d721400c924_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:34.507 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_fb2fbffb5205c552_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:34.724 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..xe-common.resources_31bf3856ad364e35_10.0.26100.1_en-us_58b62bf54b9ae38a\msinfo32.exe.mui", hr=0x0

2025-11-27T01:40:34.844 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.70.1338.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-27T01:40:34.849 Engine:Setting original file name "netcfgx.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-tcpip.resources_31bf3856ad364e35_10.0.26100.1_en-us_c93621b935b09922_tcpipcfg.dll.mui_a5479fc1", hr=0x0

2025-11-27T01:40:34.899 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_f4c1513bcd79893e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:34.946 Engine:Setting original file name "nvxdsync.exe" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\session\nvxdsyncplugin.dll", hr=0x0

2025-11-27T01:40:35.071 Engine:Setting original file name "ReShade" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\reshadefxc64.exe", hr=0x0

2025-11-27T01:40:35.114 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-27T01:40:35.157 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_0fbfb1c9f2926e3e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:35.188 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\power\nb-no\2803551e72f3605cc0b181750700647e\diagpackage.dll.mui", hr=0x0

2025-11-27T01:40:35.248 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_th-th_25ee4fb15dc2e739_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:35.253 Engine:Setting original file name "Umpo.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-u..erservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_a887c532823d0a08_umpo.dll.mui_cac12e54", hr=0x0

2025-11-27T01:40:35.256 Engine:Setting original file name "bootres" for "c:\windows\boot\resources\nb-no\bootres.dll.mui", hr=0x0

2025-11-27T01:40:35.280 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\b74f41bc269d13282681d018820fb031\ddores.dll.mui", hr=0x0

2025-11-27T01:40:35.305 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x0

2025-11-27T01:40:35.313 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\mscordaccore_amd64_amd64_8.0.2125.47513.dll", hr=0x0

2025-11-27T01:40:35.339 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-namedpipe-l1-1-0.dll", hr=0x0

2025-11-27T01:40:35.438 Engine:Setting original file name "dxmasf.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_10.0.26100.7019_none_b1abcb083360b859\msdxm.ocx", hr=0x0

2025-11-27T01:40:35.571 Engine:Setting original file name "Bubbles" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ee15dd2b573766654f76694ac2f468d4\bubbles.scr.mui", hr=0x0

2025-11-27T01:40:35.607 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_tr-tr_2c24c8b8ddbbff8a_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:35.630 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_es-mx_9dca765f230af946_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-27T01:40:35.653 Engine:Setting original file name "CUDART64_65_19.DLL" for "c:\program files (x86)\nvidia corporation\physx\common\cudart64_65.dll", hr=0x0

2025-11-27T01:40:35.671 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-errorhandling-l1-1-0.dll", hr=0x0

2025-11-27T01:40:35.798 Engine:Setting original file name "wcp.dll" for "c:\windows\system32\ssshim.dll", hr=0x0

2025-11-27T01:40:35.901 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.exe", hr=0x0

2025-11-27T01:40:35.948 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-time-l1-1-0.dll", hr=0x0

2025-11-27T01:40:35.953 Engine:Setting original file name "SCardDlg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.26100.3323_en-us_fe960d41ea77a2e8_scarddlg.dll.mui_300ae9df", hr=0x0

2025-11-27T01:40:35.985 Engine:Setting original file name "reg.exe" for "c:\windows\winsxs\wow64_microsoft-windows-r..-commandline-editor_31bf3856ad364e35_10.0.26100.5074_none_d7dcabbe0ef09540\reg.exe", hr=0x0

2025-11-27T01:40:35.997 Engine:Setting original file name "TrustedSignalCredProv.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..-credprov.resources_31bf3856ad364e35_10.0.26100.1_en-us_080e5e17ad23b7b4_trustedsignalcredprov.dll.mui_5edc427b", hr=0x0

2025-11-27T01:40:36.033 Engine:Setting original file name "fpb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\fpb.rs.mui", hr=0x0

2025-11-27T01:40:36.075 OriginalFileName Maintenance::11515 files in Moac, 0 skipped (cached), 434 filename set

2025-11-27T01:40:36.075 [AutoPurge] Routine task for Cache Maintenance has ended.

2025-11-27T01:43:25.536 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T01:52:05.891 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #341776, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T01:52:05.894 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #341777, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T01:52:08.665 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #341780, FileId: 0x1f000000077e48, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T01:52:15.904 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #341788, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T01:52:15.908 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #341789, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T01:54:17.267 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T02:05:55.534 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #342071, FileId: 0xff000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T02:07:09.152 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #342085, FileId: 0x1e000000077eba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T02:09:22.259 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T02:17:30.364 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 4996, Count: 680, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1752, Count: 35, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\FileZilla_Server_1.12.0_win64-setup.exe, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 781, Count: 86, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\fc84b46d-1e09-42a7-a94b-7b13704475a5.tmp, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 675, Count: 97, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.3_2.32002.13001.0_x86__8wekyb3d8bbwe\AppxManifest.xml->(UTF-8), EstimatedImpact: 7%

2025-11-27T02:17:30.364 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 662, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\949ecc13-aac6-4843-8775-8eb32ab4d636.tmp, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: , Pid: 4, TotalTime: 645, Count: 96, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy17\System Volume Information\{35f377ec-bd30-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 2%

2025-11-27T02:17:30.364 ProcessImageName: RuntimeBroker.exe, Pid: 7356, TotalTime: 512, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 34%

2025-11-27T02:17:30.364 ProcessImageName: taskhostw.exe, Pid: 5268, TotalTime: 405, Count: 86, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 19%

2025-11-27T02:17:30.364 ProcessImageName: RuntimeBroker.exe, Pid: 13548, TotalTime: 356, Count: 20, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 25%

2025-11-27T02:17:30.364 ProcessImageName: VSSVC.exe, Pid: 14984, TotalTime: 328, Count: 2, MaxTime: 328, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100%

2025-11-27T02:17:30.364 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 150, Count: 50, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 139, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: svchost.exe, Pid: 9356, TotalTime: 136, Count: 22, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 105, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: taskhostw.exe, Pid: 21992, TotalTime: 75, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-27T02:17:30.364 ProcessImageName: GameBar.exe, Pid: 21620, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.8_8.2501.31001.0_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 9%

2025-11-27T02:17:30.364 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\1278339d-b788-4b83-8ca7-be39cd73c5c2\content.phf, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: StoreDesktopExtension.exe, Pid: 27220, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: SrTasks.exe, Pid: 8372, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolumeShadowCopy17\System Volume Information\SPP\metadata-2, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: taskhostw.exe, Pid: 7616, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-27T02:17:30.364 ProcessImageName: updater.exe, Pid: 22656, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\8a4580d4-78cc-4c32-89e7-5291eb57833e.tmp, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Local Storage\leveldb\006455.ldb, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: updater.exe, Pid: 12144, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-27T02:17:30.364 ProcessImageName: RuntimeBroker.exe, Pid: 28076, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\BackgroundTransferApi\8e9989ed-045a-4106-aed9-b48d61c2d814.down_data, EstimatedImpact: 0%

2025-11-27T02:22:09.624 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #342865, FileId: 0x1200000007871c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T02:24:27.254 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T02:37:10.054 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #343103, FileId: 0x2a000000075c25, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T02:39:32.249 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)



BEGIN BM telemetry

GUID:{3D56D243-4B42-A5ED-DE61-A043DCF6027B}

SignatureID:340520518878414

SigSha:e1735ced290d41223a12e50689d7c8ade6f705e0

ThreatLevel:0

ProcessID:26680

ProcessCreationTime:134082425297793485

SessionID:1

CreationTime:11-27-2025 02:41:40

ImagePath:C:\xampp\apache\bin\httpd.exe

Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: 

Operations:None

END BM telemetry



2025-11-27T02:41:40.896 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-27T02:41:40.896 [Cloud] Start of cloud request. Passive mode: 0

2025-11-27T02:41:40.896 [Cloud] Queued cloud request.

2025-11-27T02:41:40.896 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-27T02:41:40.896 [Cloud] Dequeued cloud request.

2025-11-27T02:41:40.896 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-27T02:41:41.051 [Cloud] End of cloud request.

2025-11-27T02:41:41.058 [Cloud] SubmitReport(CMpBmSpyNetReportContext)

2025-11-27T02:41:41.058 [Cloud] Start of cloud request. Passive mode: 0

2025-11-27T02:41:41.058 [Cloud] Queued cloud request.

2025-11-27T02:41:41.058 [Cloud] Dequeued cloud request.

2025-11-27T02:41:41.059 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-27T02:41:41.116 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-27T02:41:41.116 [Cloud] End of cloud request.

2025-11-27T02:41:41.565 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T02:52:06.749 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #343484, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T02:52:06.752 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #343485, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T02:52:10.498 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #343487, FileId: 0x9b00000002736a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T02:52:16.758 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #343493, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T02:52:16.762 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #343494, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T02:54:37.240 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T03:07:10.881 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #344063, FileId: 0x10000000077835, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T03:09:42.244 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T03:22:11.164 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #344374, FileId: 0x4e000000077639, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T03:24:47.231 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T03:37:12.513 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #344552, FileId: 0xab000000037c6f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T03:39:52.222 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T03:43:27.450 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T03:52:06.122 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #345313, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T03:52:06.125 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #345314, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T03:52:13.936 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #345322, FileId: 0x9d00000002736a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T03:52:16.123 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #345326, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T03:52:16.126 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #345328, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T03:54:57.219 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T04:07:14.033 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #345533, FileId: 0x270000000769d2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T04:10:02.209 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T04:17:30.324 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 10321, Count: 1404, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 2931, Count: 535, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 1%

2025-11-27T04:17:30.324 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1752, Count: 35, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\FileZilla_Server_1.12.0_win64-setup.exe, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1503, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 79%

2025-11-27T04:17:30.324 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1456, Count: 170, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\fc84b46d-1e09-42a7-a94b-7b13704475a5.tmp, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1202, Count: 104, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\949ecc13-aac6-4843-8775-8eb32ab4d636.tmp, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 675, Count: 97, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.3_2.32002.13001.0_x86__8wekyb3d8bbwe\AppxManifest.xml->(UTF-8), EstimatedImpact: 7%

2025-11-27T04:17:30.324 ProcessImageName: , Pid: 4, TotalTime: 645, Count: 96, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy17\System Volume Information\{35f377ec-bd30-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 2%

2025-11-27T04:17:30.324 ProcessImageName: RuntimeBroker.exe, Pid: 7356, TotalTime: 512, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 34%

2025-11-27T04:17:30.324 ProcessImageName: taskhostw.exe, Pid: 5268, TotalTime: 405, Count: 86, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 19%

2025-11-27T04:17:30.324 ProcessImageName: RuntimeBroker.exe, Pid: 13548, TotalTime: 356, Count: 20, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 25%

2025-11-27T04:17:30.324 ProcessImageName: VSSVC.exe, Pid: 14984, TotalTime: 328, Count: 2, MaxTime: 328, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100%

2025-11-27T04:17:30.324 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 185, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\http.sys, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 180, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 150, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: svchost.exe, Pid: 9356, TotalTime: 136, Count: 22, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 106, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: taskhostw.exe, Pid: 21992, TotalTime: 75, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-27T04:17:30.324 ProcessImageName: GameBar.exe, Pid: 21620, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.8_8.2501.31001.0_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 9%

2025-11-27T04:17:30.324 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 60, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\0c34b69c4345a5f428467074b1bcda7b4d2f6a0f08112bbab8598a6f1948e625, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\1278339d-b788-4b83-8ca7-be39cd73c5c2\content.phf, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: StoreDesktopExtension.exe, Pid: 27220, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: DeviceCensus.exe, Pid: 27948, TotalTime: 45, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Recovery\ReAgent.xml->(UTF-8), EstimatedImpact: 1%

2025-11-27T04:17:30.324 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\1f780ea1-f0ec-47bf-957d-07f9d2f2f597.tmp, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: SrTasks.exe, Pid: 8372, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolumeShadowCopy17\System Volume Information\SPP\metadata-2, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: svchost.exe, Pid: 8748, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_1446006514\BIT59B4.tmp, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: taskhostw.exe, Pid: 15128, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 8%

2025-11-27T04:17:30.324 ProcessImageName: taskhostw.exe, Pid: 7856, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 13%

2025-11-27T04:17:30.324 ProcessImageName: taskhostw.exe, Pid: 7616, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-27T04:17:30.324 ProcessImageName: updater.exe, Pid: 22656, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\8a4580d4-78cc-4c32-89e7-5291eb57833e.tmp, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: RuntimeBroker.exe, Pid: 28076, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\BackgroundTransferApi\8e9989ed-045a-4106-aed9-b48d61c2d814.down_data, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-27T04:17:30.324 ProcessImageName: updater.exe, Pid: 12144, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-27T04:22:14.470 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #345882, FileId: 0x56000000077f08, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T04:25:07.205 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T04:37:15.705 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #346067, FileId: 0x220000000788f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T04:40:12.197 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T04:52:07.125 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #346253, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T04:52:07.129 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #346254, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T04:52:16.238 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #346261, FileId: 0x17000000072a2a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T04:52:17.130 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #346262, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T04:52:17.133 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #346263, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T04:55:17.195 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T05:07:16.659 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #346494, FileId: 0x34000000077288, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T05:10:22.193 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T05:22:17.309 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #346766, FileId: 0x1b0000000787a3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T05:25:27.188 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T05:37:18.737 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #348832, FileId: 0x11d000000008fdd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T05:40:32.185 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T05:43:29.590 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T05:52:05.481 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #349235, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T05:52:05.483 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #349236, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T05:52:15.493 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #349244, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T05:52:15.498 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #349246, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T05:52:18.741 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #349249, FileId: 0x13700000000a609, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T05:55:37.176 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T06:07:18.875 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #349450, FileId: 0x7700000000b7d9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T06:10:42.180 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T06:17:30.296 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 15871, Count: 2127, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 2931, Count: 537, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2161, Count: 253, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\fc84b46d-1e09-42a7-a94b-7b13704475a5.tmp, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1892, Count: 157, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\949ecc13-aac6-4843-8775-8eb32ab4d636.tmp, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1752, Count: 35, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\FileZilla_Server_1.12.0_win64-setup.exe, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1503, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 79%

2025-11-27T06:17:30.296 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 705, Count: 101, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.3_2.32002.13001.0_x86__8wekyb3d8bbwe\AppxManifest.xml->(UTF-8), EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: , Pid: 4, TotalTime: 645, Count: 96, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy17\System Volume Information\{35f377ec-bd30-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 2%

2025-11-27T06:17:30.296 ProcessImageName: RuntimeBroker.exe, Pid: 7356, TotalTime: 512, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 34%

2025-11-27T06:17:30.296 ProcessImageName: taskhostw.exe, Pid: 5268, TotalTime: 405, Count: 86, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 19%

2025-11-27T06:17:30.296 ProcessImageName: RuntimeBroker.exe, Pid: 13548, TotalTime: 356, Count: 20, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 25%

2025-11-27T06:17:30.296 ProcessImageName: VSSVC.exe, Pid: 14984, TotalTime: 328, Count: 2, MaxTime: 328, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100%

2025-11-27T06:17:30.296 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 255, Count: 64, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 210, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 200, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\http.sys, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 195, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 151, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: svchost.exe, Pid: 9356, TotalTime: 136, Count: 22, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 90, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\0c34b69c4345a5f428467074b1bcda7b4d2f6a0f08112bbab8598a6f1948e625, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: taskhostw.exe, Pid: 21992, TotalTime: 75, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-27T06:17:30.296 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 75, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\1278339d-b788-4b83-8ca7-be39cd73c5c2\content.phf, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: GameBar.exe, Pid: 21620, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.8_8.2501.31001.0_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 9%

2025-11-27T06:17:30.296 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: StoreDesktopExtension.exe, Pid: 27220, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: DeviceCensus.exe, Pid: 27948, TotalTime: 45, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Recovery\ReAgent.xml->(UTF-8), EstimatedImpact: 1%

2025-11-27T06:17:30.296 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: taskhostw.exe, Pid: 24032, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 4%

2025-11-27T06:17:30.296 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\1f780ea1-f0ec-47bf-957d-07f9d2f2f597.tmp, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: SrTasks.exe, Pid: 8372, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolumeShadowCopy17\System Volume Information\SPP\metadata-2, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: svchost.exe, Pid: 8748, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_1446006514\BIT59B4.tmp, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: taskhostw.exe, Pid: 7856, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 13%

2025-11-27T06:17:30.296 ProcessImageName: taskhostw.exe, Pid: 15128, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 8%

2025-11-27T06:17:30.296 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: taskhostw.exe, Pid: 7616, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-27T06:17:30.296 ProcessImageName: updater.exe, Pid: 22656, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\8a4580d4-78cc-4c32-89e7-5291eb57833e.tmp, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: updater.exe, Pid: 25252, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\43bb2ab9-56a8-4964-a01c-c2baa4b6b4a5.tmp, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: updater.exe, Pid: 12144, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-27T06:17:30.296 ProcessImageName: RuntimeBroker.exe, Pid: 28076, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\BackgroundTransferApi\8e9989ed-045a-4106-aed9-b48d61c2d814.down_data, EstimatedImpact: 0%

2025-11-27T06:22:18.997 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #349760, FileId: 0x2900000000e65d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T06:23:33.505 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\182D681C-E9FA-40F9-9CB6-A62D6A1C40E960bc.1dc5f665a365719

2025-11-27T06:23:33.535 Verifying engine and signature files (source: 0) ...

2025-11-27T06:23:33.535 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CD9A66C-9563-4EC1-8B47-26FBD62355A2}\mpengine.dll] due to PPL.

2025-11-27T06:23:33.535 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CD9A66C-9563-4EC1-8B47-26FBD62355A2}\mpasbase.vdm] (file in cache)

2025-11-27T06:23:33.535 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CD9A66C-9563-4EC1-8B47-26FBD62355A2}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-27T06:23:33.546 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CD9A66C-9563-4EC1-8B47-26FBD62355A2}\mpasdlta.vdm]

2025-11-27T06:23:33.546 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CD9A66C-9563-4EC1-8B47-26FBD62355A2}\mpavbase.vdm] (file in cache)

2025-11-27T06:23:33.546 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CD9A66C-9563-4EC1-8B47-26FBD62355A2}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-27T06:23:33.556 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CD9A66C-9563-4EC1-8B47-26FBD62355A2}\mpavdlta.vdm]

2025-11-27T06:23:33.628 [Engine] IsHybridMode: 0

2025-11-27T06:23:33.628 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-27T06:23:33.637 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-C2ACE3C3F22E620D04345E714B3BF08B9C030524.bin): 0x00000002

2025-11-27T06:23:33.639 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-C2ACE3C3F22E620D04345E714B3BF08B9C030524.bin)

2025-11-27T06:23:33.639 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-27T06:23:33.639 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-27T06:23:33.639 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-27T06:23:33.639 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-27T06:23:39.046 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-27T06:23:39.046 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-27T06:23:39.055 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE6F7CA660, lRefCount: 5, hr=0

2025-11-27T06:23:39.055 [Engine] New active engine 00007FFE6E3FA660 replacing engine 00007FFE6F7CA660. Number of active engines: 2

2025-11-27T06:23:39.062 EngineInit:Global ASOC is enabled

2025-11-27T06:23:39.062 EngineInit:ASOO is enabled for developer volumes

2025-11-27T06:23:39.095 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-27T06:23:39.096 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.096 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-27T06:23:39.096 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-27T06:23:39.097 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-27T06:23:39.097 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.097 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.098 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.098 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-27T06:23:39.098 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.098 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.099 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-27T06:23:39.099 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.099 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.100 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.100 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.100 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.100 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.101 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T06:23:39.101 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\87e6adb3b89588e7b13ca6278a0f3add58d819a4

Dynamic Signature Compilation Timestamp:11-26-2025 06:00:23

Persistence Type:Duration

Time remaining:864000000

2025-11-27T06:23:39.102 Dynamic signature dropped

2025-11-27T06:23:39.103 MpWriteUupSignatureVersion 1.441.521.0, hr = 0

2025-11-27T06:23:39.105 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-27T06:23:39.117 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-27T06:23:39.118 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-27T06:23:39.118 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-27T06:23:39.118 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-27T06:23:39.119 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-27T06:23:39.133 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-27T06:23:39.133 [Plugin] Initializing RTP plugin state...

2025-11-27T06:23:39.133 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-27T06:23:39.133 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 27 - 2025 01:17:30

Last Perf: 11 - 27 - 2025 01:17:30

First RTP Scan: 11 - 27 - 2025 01:17:31

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1976

  Misses:10086

BM Queue:0,107,0

  Proc:0,43,0

  File:0,101,0

Plugin Queue:0,1,0

  Threat:0,0,0

  Susp:0,1,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,2,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:349900

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:1980378800

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:21

  TotalStreamCon:10161

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:1743442

   TotalHits:2520408

   InstanceCacheInserts:115824

   InstanceCacheUpdates:0

   InstanceCacheDeletes:91479

   InstanceCacheHits:5033

   InstanceCacheMisses:440124

   InstanceCacheOverflows:8634

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (774/893)

   Success: 893, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-27T06:23:39.134 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CD9A66C-9563-4EC1-8B47-26FBD62355A2}

2025-11-27T06:23:39.134 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{272CE70C-4C85-47DE-9CF6-C66154ECAF9B}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{272CE70C-4C85-47DE-9CF6-C66154ECAF9B}\mpasbase.vdm in use, hr=0x80070020

2025-11-27T06:23:39.134 [SCC][CID=909849187_27892] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-27T06:23:39.135 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-27T06:23:39.135 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-27T06:23:39.135 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-27T06:23:39.135 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-27T06:23:39.135 MdCoreSvc is supported in this platform and OS

2025-11-27T06:23:39.136 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-27-2025 06:23:39

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-27-2025 06:23:39

2025-11-27T06:23:39.138 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-27T06:23:39.138 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-27T06:23:39.139 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-27T06:23:39.139 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-27-2025 06:23:39

END TDT(U) telemetry



2025-11-27T06:23:39.142 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T06:23:39.142 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-27T06:23:39.142 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-27T06:23:39.142 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-27T06:23:39.142 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-27T06:23:39.142 MdCoreSvc is supported in this platform and OS

Signature updated on 11-27-2025 06:23:39

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.521.0

AV Signature Version: 1.441.521.0

************************************************************

2025-11-27T06:23:39.144 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-27T06:23:39.144 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\182D681C-E9FA-40F9-9CB6-A62D6A1C40E960bc.1dc5f665a365719

2025-11-27T06:23:39.152 Process scan (postsignatureupdatescan) started.

2025-11-27T06:23:39.184 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-27T06:23:39.185 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-27T06:23:39.317 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-27T06:23:39.317 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-27T06:23:39.317 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-27T06:23:39.317 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-27T06:23:39.317 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-27T06:23:39.319 [Engine] Engine 00007FFE6F7CA660 no longer in use. Number of active engines: 1

2025-11-27T06:23:39.319 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-27T06:23:39.319 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-27T06:23:39.476 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 16201, Count: 2164, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T06:23:39.476 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 2931, Count: 537, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-27T06:23:39.476 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2206, Count: 257, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\fc84b46d-1e09-42a7-a94b-7b13704475a5.tmp, EstimatedImpact: 0%

2025-11-27T06:23:39.476 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1937, Count: 160, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\949ecc13-aac6-4843-8775-8eb32ab4d636.tmp, EstimatedImpact: 0%

2025-11-27T06:23:39.476 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 1752, Count: 35, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Downloads\FileZilla_Server_1.12.0_win64-setup.exe, EstimatedImpact: 0%

2025-11-27T06:23:39.476 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1503, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 79%

2025-11-27T06:23:39.476 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 705, Count: 101, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.3_2.32002.13001.0_x86__8wekyb3d8bbwe\AppxManifest.xml->(UTF-8), EstimatedImpact: 0%

2025-11-27T06:23:39.476 ProcessImageName: , Pid: 4, TotalTime: 645, Count: 96, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy17\System Volume Information\{35f377ec-bd30-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 2%

2025-11-27T06:23:39.476 ProcessImageName: RuntimeBroker.exe, Pid: 7356, TotalTime: 512, Count: 21, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 34%

2025-11-27T06:23:39.476 ProcessImageName: taskhostw.exe, Pid: 5268, TotalTime: 405, Count: 86, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 19%

2025-11-27T06:23:39.476 ProcessImageName: RuntimeBroker.exe, Pid: 13548, TotalTime: 356, Count: 20, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 25%

2025-11-27T06:23:39.476 ProcessImageName: VSSVC.exe, Pid: 14984, TotalTime: 328, Count: 2, MaxTime: 328, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100%

2025-11-27T06:23:39.476 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 255, Count: 64, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-27T06:23:39.476 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 225, Count: 44, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T06:23:39.476 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 200, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\http.sys, EstimatedImpact: 0%

2025-11-27T06:23:39.476 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 195, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T06:23:39.491 [Engine] RSIG_UNLOADENGINE, 00007FFE6F7CA660, err=0x0

2025-11-27T06:23:39.509 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{272CE70C-4C85-47DE-9CF6-C66154ECAF9B} removed

2025-11-27T06:23:39.628 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-27T06:23:39.634 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-27T06:23:39.634 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-27T06:23:39.634 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-27T06:23:39.634 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-27T06:23:39.634 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-27T06:23:39.634 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-27T06:23:39.637 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-27T06:23:39.637 [RTP] Duplicating the current plugin configuration object...

2025-11-27T06:23:39.637 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-27T06:23:39.637 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-27T06:23:39.637 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-27T06:23:39.637 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-27T06:23:39.637 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-27T06:23:39.637 [RTP] No config change detected. Not updating plugin configuration.

2025-11-27T06:23:39.637 [RTP] No config changes found. No configuration switch.

2025-11-27T06:23:39.637 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-27T06:23:39.637 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-27T06:23:39.637 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-27T06:23:39.637 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-27T06:23:39.637 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-27T06:23:39.637 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-27T06:23:39.637 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-27T06:23:39.638 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-27T06:23:39.638 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-27T06:23:39.638 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-27T06:23:39.638 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-27T06:23:39.638 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-27T06:23:39.638 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-27T06:23:39.638 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-27T06:23:39.638 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-27T06:23:39.638 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-27T06:23:39.638 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T06:23:39.640 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T06:23:39.642 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T06:23:39.644 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T06:23:39.646 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T06:23:39.646 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 81377620(ms) from now at 05:59 (04:59 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-27T06:23:41.163 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-27T06:23:41.166 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-27T06:23:41.167 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-27T06:23:42.186 [RTP] Duplicating the current plugin configuration object...

2025-11-27T06:23:42.186 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-27T06:23:42.186 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-27T06:23:42.186 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-27T06:23:42.186 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157ED7C270CE, sigsha=5eded354160aa060b3f2a16db0725661264de9cd, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF9518016, sigsha=8fa60ffaf004b3696b5767c35f78f1425d04eb09, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0xa85b3f00

2025-11-27T06:23:44.413 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-27T06:23:44.413 [Cloud] Start of cloud request. Passive mode: 0

2025-11-27T06:23:44.413 [Cloud] Queued cloud request.

2025-11-27T06:23:44.413 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-27T06:23:44.413 [Cloud] Dequeued cloud request.

2025-11-27T06:23:44.413 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\98402758d214e1f1828abd31bb5858b7eda24e44

Dynamic Signature Compilation Timestamp:11-27-2025 06:23:44

Persistence Type:Duration

Time remaining:864000000

2025-11-27T06:23:44.613 Dynamic signature received

2025-11-27T06:23:44.614 [Cloud] End of cloud request.

2025-11-27T06:23:44.614 RTSD:RTSD recieved, rescanning impacted resources

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-27T06:23:45.126 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T06:23:45.944 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-27T06:23:45.944 [Cloud] Start of cloud request. Passive mode: 0

2025-11-27T06:23:45.944 [Cloud] Queued cloud request.

2025-11-27T06:23:45.944 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-27T06:23:45.944 [Cloud] Dequeued cloud request.

2025-11-27T06:23:45.944 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-27T06:23:46.307 [Cloud] End of cloud request.

2025-11-27T06:23:46.826 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T06:23:55.014 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-27T06:23:55.014 Process scan (postsignatureupdatescan) completed.

2025-11-27T06:25:47.167 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T06:28:39.078 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-27T06:37:19.101 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #350086, FileId: 0x6200000000a2cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T06:40:52.158 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T06:52:06.684 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #350547, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T06:52:06.688 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #350548, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T06:52:16.685 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #350555, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T06:52:16.685 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #350554, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T06:52:16.688 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #350557, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T06:52:19.418 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #350559, FileId: 0x13e00000000bfaa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T06:55:57.163 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T07:07:19.784 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #351069, FileId: 0x7f00000000e13b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T07:11:02.150 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T07:22:20.363 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #351469, FileId: 0x4500000000f5f3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T07:26:07.145 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T07:37:20.568 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #351642, FileId: 0x25500000000a310, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T07:40:12.048 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #351903, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T07:41:12.148 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T07:43:31.582 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T07:46:05.978 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #352049, FileId: 0x100000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T07:52:05.979 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #352136, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T07:52:05.981 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #352137, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T07:52:15.979 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #352145, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T07:52:15.983 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #352146, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T07:52:20.802 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #352149, FileId: 0x4300000000b893, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T07:56:17.140 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T08:01:52.395 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #352386, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T08:07:21.025 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #352444, FileId: 0x21200000000a38b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T08:11:22.138 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T08:22:21.400 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #352825, FileId: 0xf900000000fbee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T08:23:39.032 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 5460, Count: 724, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T08:23:39.032 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 826, Count: 87, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\e703c3d2-e698-40a5-847a-297372f45982.tmp, EstimatedImpact: 0%

2025-11-27T08:23:39.032 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 570, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\2cf60cd7-fa47-4026-b4a5-027f6886e3b4.tmp, EstimatedImpact: 0%

2025-11-27T08:23:39.032 ProcessImageName: RuntimeBroker.exe, Pid: 8428, TotalTime: 497, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 33%

2025-11-27T08:23:39.032 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 195, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-27T08:23:39.032 ProcessImageName: taskhostw.exe, Pid: 21148, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-27T08:23:39.032 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-27T08:23:39.032 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T08:23:39.032 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T08:23:39.032 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-27T08:23:39.032 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\3451eded-3e94-4b45-a638-bea709dddc76.tmp, EstimatedImpact: 0%

2025-11-27T08:23:39.032 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-27T08:23:39.032 ProcessImageName: HxTsr.exe, Pid: 8072, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 12%

2025-11-27T08:23:39.032 ProcessImageName: StoreDesktopExtension.exe, Pid: 24816, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-27T08:23:39.032 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-27T08:23:39.032 ProcessImageName: updater.exe, Pid: 10208, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-27T08:26:27.123 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T08:37:21.392 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #353001, FileId: 0x9600000000a74a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T08:41:32.132 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T08:52:05.734 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #353701, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T08:52:05.737 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #353702, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T08:52:15.748 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #353708, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T08:52:15.752 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #353709, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T08:52:21.551 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #353712, FileId: 0x26400000000cf61, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T08:56:37.114 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T09:07:22.168 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #353918, FileId: 0x12500000000bd7c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T09:11:42.124 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T09:22:23.560 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #354174, FileId: 0x16600000000a820, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T09:26:47.111 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T09:37:24.192 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #354356, FileId: 0xa200000000e172, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T09:41:52.103 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T09:43:33.543 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T09:45:41.013 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #354550, FileId: 0x101000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0



BEGIN BM telemetry

GUID:{F6704E86-D06E-FD3A-746B-99AA193E540C}

SignatureID:340520518878414

SigSha:e1735ced290d41223a12e50689d7c8ade6f705e0

ThreatLevel:0

ProcessID:26680

ProcessCreationTime:134082425297793485

SessionID:1

CreationTime:11-27-2025 09:50:41

ImagePath:C:\xampp\apache\bin\httpd.exe

Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: 

Operations:None

END BM telemetry



2025-11-27T09:50:42.422 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-27T09:50:42.422 [Cloud] Start of cloud request. Passive mode: 0

2025-11-27T09:50:42.422 [Cloud] Queued cloud request.

2025-11-27T09:50:42.422 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-27T09:50:42.422 [Cloud] Dequeued cloud request.

2025-11-27T09:50:42.422 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-27T09:50:42.566 [Cloud] End of cloud request.

2025-11-27T09:50:43.081 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T09:52:07.065 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #354641, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T09:52:07.069 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #354642, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T09:52:17.072 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #354650, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T09:52:17.076 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #354651, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T09:52:24.436 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #354656, FileId: 0xa100000000a74a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T09:56:57.096 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T10:07:25.044 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #354856, FileId: 0xcf00000000cf81, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T10:12:02.101 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T10:22:25.218 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #355181, FileId: 0x6d0000000095dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T10:23:38.997 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 10905, Count: 1448, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1486, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-27T10:23:38.997 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1381, Count: 170, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\e703c3d2-e698-40a5-847a-297372f45982.tmp, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1170, Count: 105, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\2cf60cd7-fa47-4026-b4a5-027f6886e3b4.tmp, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 616, Count: 126, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: RuntimeBroker.exe, Pid: 8428, TotalTime: 497, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 33%

2025-11-27T10:23:38.997 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 255, Count: 57, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: taskhostw.exe, Pid: 21148, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-27T10:23:38.997 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 150, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 135, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 120, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 60, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\3451eded-3e94-4b45-a638-bea709dddc76.tmp, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: HxTsr.exe, Pid: 8072, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 12%

2025-11-27T10:23:38.997 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: StoreDesktopExtension.exe, Pid: 24816, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-27T10:23:38.997 ProcessImageName: updater.exe, Pid: 10208, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-27T10:27:07.095 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T10:37:25.405 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #355370, FileId: 0x96000000010602, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T10:42:12.081 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T10:52:06.174 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #355582, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T10:52:06.178 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #355583, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T10:52:16.178 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #355589, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T10:52:16.182 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #355590, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T10:52:26.035 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #355593, FileId: 0xfa00000000a295, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T10:57:17.073 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T11:07:26.200 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #355963, FileId: 0x1dd00000000f4bc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T11:12:22.075 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T11:22:26.886 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #356209, FileId: 0x51000000011438, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T11:27:27.066 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T11:37:27.197 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #356395, FileId: 0x1e500000000fa85, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T11:42:32.058 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T11:43:35.533 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T11:52:06.059 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #356650, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T11:52:06.063 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #356651, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T11:52:16.066 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #356658, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T11:52:16.066 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #356659, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T11:52:16.069 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #356660, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T11:52:16.070 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #356661, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T11:52:27.866 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #356664, FileId: 0xe2000000011413, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T11:57:37.051 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T12:04:46.685 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #356957, FileId: 0xc600000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T12:07:29.363 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #356998, FileId: 0x9800000000a669, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T12:12:42.042 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T12:22:30.705 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #357446, FileId: 0x4800000000e66c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T12:23:38.948 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 16695, Count: 2224, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2191, Count: 257, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\e703c3d2-e698-40a5-847a-297372f45982.tmp, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1831, Count: 162, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\c394c762-1142-48db-bda8-eb034f5cb19b.tmp, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1486, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-27T12:23:38.948 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 616, Count: 126, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: RuntimeBroker.exe, Pid: 8428, TotalTime: 497, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 33%

2025-11-27T12:23:38.948 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 300, Count: 63, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 210, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: taskhostw.exe, Pid: 21148, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-27T12:23:38.948 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 195, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 180, Count: 36, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 105, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 105, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\3451eded-3e94-4b45-a638-bea709dddc76.tmp, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: HxTsr.exe, Pid: 8072, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 12%

2025-11-27T12:23:38.948 ProcessImageName: StoreDesktopExtension.exe, Pid: 24816, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: taskhostw.exe, Pid: 9380, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: updater.exe, Pid: 1820, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\8720eed8-a5a2-4d0d-9285-9a5930ddd68b.tmp, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 0%

2025-11-27T12:23:38.948 ProcessImageName: updater.exe, Pid: 10208, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-27T12:27:47.048 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T12:37:31.327 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #357681, FileId: 0x1d2000000009d5b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T12:42:52.038 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T12:52:06.344 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #357948, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T12:52:06.347 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #357949, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T12:52:16.356 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #357956, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T12:52:16.361 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #357957, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T12:52:32.296 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #357961, FileId: 0x6b00000000b078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T12:57:57.027 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T13:07:33.253 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #358229, FileId: 0xf7000000009452, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T13:13:02.020 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T13:22:33.881 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #358565, FileId: 0x8d0000000183f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T13:28:07.018 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T13:37:34.853 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #358779, FileId: 0x11f00000000eda8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T13:43:12.018 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T13:43:37.282 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T13:52:06.526 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #359077, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T13:52:06.529 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #359078, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T13:52:16.539 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #359086, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T13:52:16.543 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #359087, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T13:52:35.762 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #359092, FileId: 0xbb0000000183f8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T13:54:27.990 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #359194, FileId: 0x102000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T13:58:17.001 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T14:07:37.008 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #359845, FileId: 0x41100000000d3ed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T14:10:20.174 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #360112, FileId: 0xc700000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T14:13:21.998 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T14:22:37.958 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #360280, FileId: 0x128000000018344, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T14:23:38.911 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 25335, Count: 3302, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3107, Count: 342, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\e703c3d2-e698-40a5-847a-297372f45982.tmp, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2417, Count: 214, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\c394c762-1142-48db-bda8-eb034f5cb19b.tmp, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1486, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-27T14:23:38.911 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 616, Count: 126, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: RuntimeBroker.exe, Pid: 8428, TotalTime: 497, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 33%

2025-11-27T14:23:38.911 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 345, Count: 69, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 300, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 285, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: taskhostw.exe, Pid: 21148, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-27T14:23:38.911 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 180, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 150, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 105, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\3451eded-3e94-4b45-a638-bea709dddc76.tmp, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: HxTsr.exe, Pid: 8072, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 12%

2025-11-27T14:23:38.911 ProcessImageName: StoreDesktopExtension.exe, Pid: 24816, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: taskhostw.exe, Pid: 9380, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: updater.exe, Pid: 1820, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\8720eed8-a5a2-4d0d-9285-9a5930ddd68b.tmp, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 0%

2025-11-27T14:23:38.911 ProcessImageName: updater.exe, Pid: 10208, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-27T14:28:26.998 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T14:37:39.004 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #361750, FileId: 0x6000000000148c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T14:40:40.477 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume4\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #363554, FileId: 0xac000000009558, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T14:43:31.996 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T14:52:06.245 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #363727, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T14:52:06.249 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #363728, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T14:52:16.249 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #363735, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T14:52:16.255 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #363736, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T14:52:39.998 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #363741, FileId: 0xd000000000a180, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T14:58:36.987 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T15:07:40.490 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #364112, FileId: 0x16600000000deb1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T15:13:41.987 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T15:22:41.534 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #364425, FileId: 0x263000000002119, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T15:28:46.978 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T15:37:42.155 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #364636, FileId: 0x16400000000bc30, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T15:43:39.504 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T15:43:51.976 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T15:52:05.982 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #364937, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T15:52:05.984 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #364938, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T15:52:15.997 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #364947, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T15:52:16.001 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #364948, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T15:52:43.297 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #364955, FileId: 0xa900000000a186, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T15:58:56.963 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T16:07:44.166 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #365263, FileId: 0x3f200000000fb0b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T16:14:01.960 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T16:22:45.285 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #365611, FileId: 0xbe000000009558, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T16:23:38.877 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 33960, Count: 4380, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3918, Count: 425, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\e703c3d2-e698-40a5-847a-297372f45982.tmp, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3139, Count: 269, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\c394c762-1142-48db-bda8-eb034f5cb19b.tmp, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1486, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-27T16:23:38.877 ProcessImageName: SrTasks.exe, Pid: 24208, TotalTime: 1426, Count: 356, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 17%

2025-11-27T16:23:38.877 ProcessImageName: SrTasks.exe, Pid: 23404, TotalTime: 1275, Count: 524, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{8D6E0C76-A03A-4349-8274-C6EED98CFB81}{e905aad7-cb66-11f0-b6df-000acd3b8d8d}.TMContainer00000000000000000002.regtrans-ms, EstimatedImpact: 5%

2025-11-27T16:23:38.877 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 631, Count: 127, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: RuntimeBroker.exe, Pid: 8428, TotalTime: 497, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 33%

2025-11-27T16:23:38.877 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 405, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 390, Count: 77, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 390, Count: 62, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: WinSAT.exe, Pid: 17592, TotalTime: 281, Count: 2, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 3%

2025-11-27T16:23:38.877 ProcessImageName: taskhostw.exe, Pid: 21148, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-27T16:23:38.877 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 180, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 180, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: WmiPrvSE.exe, Pid: 14616, TotalTime: 137, Count: 6, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 100%

2025-11-27T16:23:38.877 ProcessImageName: ngentask.exe, Pid: 17228, TotalTime: 120, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 12%

2025-11-27T16:23:38.877 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 105, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: taskhostw.exe, Pid: 19656, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 3%

2025-11-27T16:23:38.877 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: ngentask.exe, Pid: 23392, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 8%

2025-11-27T16:23:38.877 ProcessImageName: ngentask.exe, Pid: 24736, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 17%

2025-11-27T16:23:38.877 ProcessImageName: ngentask.exe, Pid: 24408, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-27T16:23:38.877 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\3451eded-3e94-4b45-a638-bea709dddc76.tmp, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: ngentask.exe, Pid: 9532, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 31%

2025-11-27T16:23:38.877 ProcessImageName: ngentask.exe, Pid: 18684, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 32%

2025-11-27T16:23:38.877 ProcessImageName: HxTsr.exe, Pid: 8072, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 12%

2025-11-27T16:23:38.877 ProcessImageName: PhoneExperienceHost.exe, Pid: 1316, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\Public\Desktop\desktop.ini, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: StoreDesktopExtension.exe, Pid: 24816, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: taskhostw.exe, Pid: 9380, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: updater.exe, Pid: 1820, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\8720eed8-a5a2-4d0d-9285-9a5930ddd68b.tmp, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 0%

2025-11-27T16:23:38.877 ProcessImageName: updater.exe, Pid: 10208, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-27T16:29:06.953 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T16:37:45.997 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #365828, FileId: 0xb800000000e0a8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T16:44:11.960 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T16:52:06.300 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #366093, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T16:52:06.303 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #366094, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T16:52:16.317 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #366100, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T16:52:16.319 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #366101, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T16:52:16.323 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #366102, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T16:52:16.327 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #366103, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T16:52:46.917 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #366110, FileId: 0x1d000000000f8b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T16:59:16.950 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T17:07:47.566 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #366358, FileId: 0x2e0000000105f7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T17:14:21.940 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T17:25:48.733 Bm signature throttled:0x00002db31bed458f

2025-11-27T17:29:26.944 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T17:43:41.515 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T17:44:31.943 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T17:59:36.938 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T18:01:37.444 Bm signature throttled:0x00002db31bed458f

2025-11-27T18:14:41.930 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T18:23:38.847 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 42601, Count: 5465, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 4822, Count: 510, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\e703c3d2-e698-40a5-847a-297372f45982.tmp, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3926, Count: 322, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\c394c762-1142-48db-bda8-eb034f5cb19b.tmp, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1486, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-27T18:23:38.847 ProcessImageName: SrTasks.exe, Pid: 24208, TotalTime: 1426, Count: 356, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 17%

2025-11-27T18:23:38.847 ProcessImageName: SrTasks.exe, Pid: 23404, TotalTime: 1275, Count: 524, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{8D6E0C76-A03A-4349-8274-C6EED98CFB81}{e905aad7-cb66-11f0-b6df-000acd3b8d8d}.TMContainer00000000000000000002.regtrans-ms, EstimatedImpact: 5%

2025-11-27T18:23:38.847 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1125, Count: 176, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\oem20.PNF, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 631, Count: 127, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: RuntimeBroker.exe, Pid: 8428, TotalTime: 497, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 33%

2025-11-27T18:23:38.847 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 465, Count: 80, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 465, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 435, Count: 83, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: WinSAT.exe, Pid: 17592, TotalTime: 281, Count: 2, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 3%

2025-11-27T18:23:38.847 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 270, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 240, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: taskhostw.exe, Pid: 21148, TotalTime: 195, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-27T18:23:38.847 ProcessImageName: WmiPrvSE.exe, Pid: 14616, TotalTime: 137, Count: 6, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 100%

2025-11-27T18:23:38.847 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\3451eded-3e94-4b45-a638-bea709dddc76.tmp, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: ngentask.exe, Pid: 17228, TotalTime: 120, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 12%

2025-11-27T18:23:38.847 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 105, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: taskhostw.exe, Pid: 19656, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 3%

2025-11-27T18:23:38.847 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: ngentask.exe, Pid: 23392, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 8%

2025-11-27T18:23:38.847 ProcessImageName: ngentask.exe, Pid: 24736, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 17%

2025-11-27T18:23:38.847 ProcessImageName: ngentask.exe, Pid: 24408, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-27T18:23:38.847 ProcessImageName: ngentask.exe, Pid: 9532, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 31%

2025-11-27T18:23:38.847 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 25%

2025-11-27T18:23:38.847 ProcessImageName: ngentask.exe, Pid: 18684, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 32%

2025-11-27T18:23:38.847 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 30, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\59D76868C250B3240414CE3EFBB12518_3F5491CA446915306213EF514DD481E0, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: HxTsr.exe, Pid: 8072, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 12%

2025-11-27T18:23:38.847 ProcessImageName: svchost.exe, Pid: 25712, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_1081590103\BIT58B2.tmp, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: PhoneExperienceHost.exe, Pid: 1316, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\Public\Desktop\desktop.ini, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: taskhostw.exe, Pid: 9380, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: StoreDesktopExtension.exe, Pid: 24816, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: updater.exe, Pid: 1820, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\8720eed8-a5a2-4d0d-9285-9a5930ddd68b.tmp, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: svchost.exe, Pid: 26992, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_20108_1910601967\BIT50B4.tmp, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: updater.exe, Pid: 16340, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\d05ec53f-2643-4c0c-b22d-19b998dc1606.tmp, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: nvngx_update.exe, Pid: 24560, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: updater.exe, Pid: 10208, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NvProfileUpdaterPlugin\optimus\metadata.json, EstimatedImpact: 0%

2025-11-27T18:23:38.847 ProcessImageName: nvngx_update.exe, Pid: 6284, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-27T18:29:46.923 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T18:37:53.013 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #369653, FileId: 0x2c8000000007a15, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T18:38:26.752 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\51CEB5C5-A601-4180-9750-CCEE53D9515164ec.1dc5fcd03d974c8

2025-11-27T18:38:26.785 Verifying engine and signature files (source: 0) ...

2025-11-27T18:38:26.785 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F2EA411A-C9CF-44D3-A413-3E87B2588F94}\mpengine.dll] due to PPL.

2025-11-27T18:38:26.785 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F2EA411A-C9CF-44D3-A413-3E87B2588F94}\mpasbase.vdm] (file in cache)

2025-11-27T18:38:26.785 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F2EA411A-C9CF-44D3-A413-3E87B2588F94}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-27T18:38:26.795 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F2EA411A-C9CF-44D3-A413-3E87B2588F94}\mpasdlta.vdm]

2025-11-27T18:38:26.795 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F2EA411A-C9CF-44D3-A413-3E87B2588F94}\mpavbase.vdm] (file in cache)

2025-11-27T18:38:26.795 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F2EA411A-C9CF-44D3-A413-3E87B2588F94}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-27T18:38:26.806 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F2EA411A-C9CF-44D3-A413-3E87B2588F94}\mpavdlta.vdm]

2025-11-27T18:38:26.877 [Engine] IsHybridMode: 0

2025-11-27T18:38:26.878 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-27T18:38:26.888 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-8947952E7892CA73A1A8FBAD00161B9823D17FD9.bin): 0x00000002

2025-11-27T18:38:26.890 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-8947952E7892CA73A1A8FBAD00161B9823D17FD9.bin)

2025-11-27T18:38:26.890 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-27T18:38:26.890 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-27T18:38:26.890 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-27T18:38:26.890 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-27T18:38:32.328 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-27T18:38:32.329 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-27T18:38:32.336 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE6E3FA660, lRefCount: 5, hr=0

2025-11-27T18:38:32.336 [Engine] New active engine 00007FFE6F7CA660 replacing engine 00007FFE6E3FA660. Number of active engines: 2

2025-11-27T18:38:32.343 EngineInit:Global ASOC is enabled

2025-11-27T18:38:32.343 EngineInit:ASOO is enabled for developer volumes

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.389 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-27T18:38:32.391 MpWriteUupSignatureVersion 1.441.535.0, hr = 0

2025-11-27T18:38:32.392 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-27T18:38:32.405 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-27T18:38:32.406 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-27T18:38:32.406 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-27T18:38:32.406 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-27T18:38:32.406 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-27T18:38:32.421 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-27T18:38:32.421 [Plugin] Initializing RTP plugin state...

2025-11-27T18:38:32.421 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 27 - 2025 07:23:39

Last Perf: 11 - 27 - 2025 07:23:39

First RTP Scan: 11 - 27 - 2025 07:23:40

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:2739

  Misses:8311

BM Queue:0,25,0

  Proc:0,25,0

  File:0,13,0

Plugin Queue:0,1,0

  Threat:0,0,0

  Susp:0,1,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:369812

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:-2102931082

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:21

  TotalStreamCon:35476

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:2026097

   TotalHits:2712772

   InstanceCacheInserts:128139

   InstanceCacheUpdates:0

   InstanceCacheDeletes:95286

   InstanceCacheHits:5054

   InstanceCacheMisses:483036

   InstanceCacheOverflows:10503

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (1461/1715)

   Success: 1715, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-27T18:38:32.421 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-27T18:38:32.421 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F2EA411A-C9CF-44D3-A413-3E87B2588F94}

2025-11-27T18:38:32.421 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CD9A66C-9563-4EC1-8B47-26FBD62355A2}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CD9A66C-9563-4EC1-8B47-26FBD62355A2}\mpasbase.vdm in use, hr=0x80070020

2025-11-27T18:38:32.421 [SCC][CID=953942734_19872] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-27T18:38:32.423 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-27T18:38:32.423 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-27T18:38:32.423 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-27T18:38:32.423 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-27T18:38:32.423 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-27T18:38:32.424 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-27-2025 18:38:32

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-27-2025 18:38:32

2025-11-27T18:38:32.426 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-27T18:38:32.426 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-27T18:38:32.427 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-27T18:38:32.427 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-27-2025 18:38:32

END TDT(U) telemetry



2025-11-27T18:38:32.429 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T18:38:32.429 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-27T18:38:32.429 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-27T18:38:32.430 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-27T18:38:32.430 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-27T18:38:32.430 MdCoreSvc is supported in this platform and OS

Signature updated on 11-27-2025 18:38:32

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.535.0

AV Signature Version: 1.441.535.0

************************************************************

2025-11-27T18:38:32.431 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-27T18:38:32.431 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\51CEB5C5-A601-4180-9750-CCEE53D9515164ec.1dc5fcd03d974c8

2025-11-27T18:38:32.447 Process scan (postsignatureupdatescan) started.

2025-11-27T18:38:32.469 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-27T18:38:32.470 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-27T18:38:32.607 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-27T18:38:32.607 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-27T18:38:32.607 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-27T18:38:32.607 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-27T18:38:32.607 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-27T18:38:32.609 [Engine] Engine 00007FFE6E3FA660 no longer in use. Number of active engines: 1

2025-11-27T18:38:32.609 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-27T18:38:32.609 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-27T18:38:32.769 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 43562, Count: 5599, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T18:38:32.770 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 4972, Count: 521, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\e703c3d2-e698-40a5-847a-297372f45982.tmp, EstimatedImpact: 0%

2025-11-27T18:38:32.770 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4032, Count: 328, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\c394c762-1142-48db-bda8-eb034f5cb19b.tmp, EstimatedImpact: 0%

2025-11-27T18:38:32.770 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1486, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 83%

2025-11-27T18:38:32.770 ProcessImageName: SrTasks.exe, Pid: 24208, TotalTime: 1426, Count: 356, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 17%

2025-11-27T18:38:32.770 ProcessImageName: SrTasks.exe, Pid: 23404, TotalTime: 1275, Count: 524, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{8D6E0C76-A03A-4349-8274-C6EED98CFB81}{e905aad7-cb66-11f0-b6df-000acd3b8d8d}.TMContainer00000000000000000002.regtrans-ms, EstimatedImpact: 5%

2025-11-27T18:38:32.770 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1260, Count: 194, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\oem20.PNF, EstimatedImpact: 0%

2025-11-27T18:38:32.770 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 903, Count: 149, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 0%

2025-11-27T18:38:32.770 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 631, Count: 127, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-27T18:38:32.770 ProcessImageName: RuntimeBroker.exe, Pid: 8428, TotalTime: 497, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 33%

2025-11-27T18:38:32.770 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 495, Count: 86, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T18:38:32.770 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 480, Count: 50, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T18:38:32.770 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 435, Count: 83, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-27T18:38:32.770 ProcessImageName: WmiPrvSE.exe, Pid: 17520, TotalTime: 339, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 86%

2025-11-27T18:38:32.770 ProcessImageName: WinSAT.exe, Pid: 17592, TotalTime: 281, Count: 2, MaxTime: 281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 3%

2025-11-27T18:38:32.770 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 270, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-27T18:38:32.787 [Engine] RSIG_UNLOADENGINE, 00007FFE6E3FA660, err=0x0

2025-11-27T18:38:32.803 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CD9A66C-9563-4EC1-8B47-26FBD62355A2} removed

2025-11-27T18:38:32.911 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue

IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4

IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b

IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4

IDynamicConfig::ReportError ECS value=MpDisableAsrHealthMonitoring hr=0x800700d4

IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4

IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b

IDynamicConfig::ReportError ECS value=MpDisableBmRescan hr=0x8007007b

IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse

2025-11-27T18:38:32.917 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-27T18:38:32.917 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-27T18:38:32.917 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-27T18:38:32.918 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-27T18:38:32.918 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-27T18:38:32.918 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-27T18:38:32.921 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-27T18:38:32.921 [RTP] Duplicating the current plugin configuration object...

2025-11-27T18:38:32.921 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-27T18:38:32.921 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-27T18:38:32.921 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-27T18:38:32.922 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-27T18:38:32.922 [RTP] No config change detected. Not updating plugin configuration.

2025-11-27T18:38:32.922 [RTP] No config changes found. No configuration switch.

2025-11-27T18:38:32.922 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-27T18:38:32.922 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-27T18:38:32.922 [RTP] Duplicating the current plugin configuration object...

2025-11-27T18:38:32.922 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-27T18:38:32.922 [RTP] Updating plugin configuration due to recent config changes (0x2) ...

2025-11-27T18:38:32.922 [RTP] No config change detected. Not updating plugin configuration.

2025-11-27T18:38:32.922 [RTP] No config changes found. No configuration switch.

2025-11-27T18:38:32.922 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0

2025-11-27T18:38:32.922 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-27T18:38:32.922 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-27T18:38:32.922 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-27T18:38:32.922 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-27T18:38:32.922 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-27T18:38:32.922 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-27T18:38:32.922 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-27T18:38:32.922 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-27T18:38:32.922 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-27T18:38:32.922 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-27T18:38:32.922 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-27T18:38:32.922 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-27T18:38:32.922 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-27T18:38:32.922 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-27T18:38:32.922 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-27T18:38:32.922 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T18:38:32.924 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T18:38:32.926 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T18:38:32.928 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T18:38:32.929 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T18:38:32.931 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 26586262(ms) from now at 03:01 (02:01 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-27T18:38:34.447 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-27T18:38:34.451 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-27T18:38:34.451 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-27T18:38:35.460 [RTP] Duplicating the current plugin configuration object...

2025-11-27T18:38:35.460 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-27T18:38:35.460 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-27T18:38:35.460 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-27T18:38:35.460 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-27T18:38:37.817 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-27T18:38:37.817 [Cloud] Start of cloud request. Passive mode: 0

2025-11-27T18:38:37.817 [Cloud] Queued cloud request.

2025-11-27T18:38:37.817 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-27T18:38:37.817 [Cloud] Dequeued cloud request.

2025-11-27T18:38:37.818 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-27T18:38:38.221 [Cloud] End of cloud request.

2025-11-27T18:38:38.730 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-27T18:38:46.863 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-27T18:38:46.864 Process scan (postsignatureupdatescan) completed.

2025-11-27T18:43:32.356 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-27T18:44:51.918 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T18:52:05.867 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #370437, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T18:52:05.870 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #370438, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T18:52:15.869 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #370444, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T18:52:15.873 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #370445, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T18:52:54.162 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #370455, FileId: 0x1e0000000010fde, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T18:59:56.910 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T19:07:54.786 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #370980, FileId: 0x1de00000001848f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T19:15:01.912 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T19:22:55.722 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #371479, FileId: 0x2b800000000f772, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T19:30:06.905 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T19:37:56.905 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #371828, FileId: 0x9d00000000a377, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T19:43:43.500 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T19:45:11.904 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T19:52:06.398 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #372161, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T19:52:06.403 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #372162, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T19:52:16.407 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #372171, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T19:52:16.408 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #372172, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T19:52:16.413 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #372173, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T19:52:57.705 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #372182, FileId: 0x17f00000001849c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T20:00:16.891 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T20:01:55.816 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #372423, FileId: 0x103000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T20:07:58.727 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #372504, FileId: 0xd500000000a180, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T20:15:21.876 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T20:22:58.764 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #372900, FileId: 0xde00000000120d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T20:30:26.878 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T20:37:59.992 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #373129, FileId: 0xbb00000000a377, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T20:38:32.300 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 8640, Count: 1082, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T20:38:32.300 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 812, Count: 86, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\b9011350-9aec-4950-bfb0-be1f4a48ea12.tmp, EstimatedImpact: 0%

2025-11-27T20:38:32.300 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 737, Count: 54, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\9fd99fea-a988-4329-9f32-b223f1bc155a.tmp, EstimatedImpact: 0%

2025-11-27T20:38:32.300 ProcessImageName: RuntimeBroker.exe, Pid: 21540, TotalTime: 434, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-27T20:38:32.300 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 210, Count: 56, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-27T20:38:32.300 ProcessImageName: taskhostw.exe, Pid: 26724, TotalTime: 180, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-27T20:38:32.300 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T20:38:32.300 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-27T20:38:32.300 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 77, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-27T20:38:32.300 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-27T20:38:32.300 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T20:38:32.300 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\reported_apps_state.json, EstimatedImpact: 0%

2025-11-27T20:38:32.300 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 30, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.277.358.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-27T20:38:32.300 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 30, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 2%

2025-11-27T20:38:32.300 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 11%

2025-11-27T20:38:32.300 ProcessImageName: StoreDesktopExtension.exe, Pid: 20844, TotalTime: 0, Count: 9, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-27T20:38:32.300 ProcessImageName: updater.exe, Pid: 22340, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-27T20:45:31.863 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T20:52:06.236 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #373389, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T20:52:06.239 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #373390, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T20:52:16.245 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #373397, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T20:52:16.248 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #373398, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T20:53:01.367 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #373427, FileId: 0x2290000000189b8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T20:54:37.498 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T21:00:36.867 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T21:06:28.150 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #374008, FileId: 0xc800000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T21:08:01.497 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #374117, FileId: 0x10b00000001580b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T21:15:41.859 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T21:15:42.417 Bm signature throttled:0x00002db31bed458f

2025-11-27T21:16:25.550 Bm signature throttled:0x00002db31bed458f

2025-11-27T21:21:58.847 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\setup\logs\Install_2025-11-26_224310_28028-12372.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #374730, FileId: 0x5e000000014099, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T21:21:58.929 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T21:23:02.878 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #374823, FileId: 0x9000000031696, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T21:30:46.851 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T21:38:03.340 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #374984, FileId: 0x37000000018c6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T21:45:51.847 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T21:52:06.252 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #375113, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T21:52:06.256 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #375114, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T21:52:16.252 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #375121, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T21:52:16.253 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #375122, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T21:52:16.256 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #375123, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T21:52:16.258 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #375124, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T21:53:03.596 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #375132, FileId: 0x8000000032128, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T22:00:56.839 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T22:08:04.415 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #375278, FileId: 0x27000000004a91, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T22:16:01.836 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T22:22:12.633 Bm signature throttled:0x0000fab3228bcd4d

2025-11-27T22:23:04.838 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #375472, FileId: 0x7000000032ef8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T22:31:06.823 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T22:38:05.404 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #375749, FileId: 0x800000003277b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T22:38:32.268 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 11610, Count: 1449, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1622, Count: 173, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\b9011350-9aec-4950-bfb0-be1f4a48ea12.tmp, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1503, Count: 108, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\9fd99fea-a988-4329-9f32-b223f1bc155a.tmp, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: RuntimeBroker.exe, Pid: 21540, TotalTime: 434, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-27T22:38:32.268 ProcessImageName: powershell.exe, Pid: 19268, TotalTime: 336, Count: 45, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\4acfdbda9fe7d2c227cd2d57ea292ba9\System.Management.Automation.ni.dll, EstimatedImpact: 30%

2025-11-27T22:38:32.268 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 240, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Network Shortcuts\SSL\target.lnk, EstimatedImpact: 9%

2025-11-27T22:38:32.268 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 225, Count: 58, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 195, Count: 37, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\telemetry-dll-ramp-value.txt, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 5848, TotalTime: 195, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 3%

2025-11-27T22:38:32.268 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 181, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: taskhostw.exe, Pid: 26724, TotalTime: 180, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-27T22:38:32.268 ProcessImageName: backgroundTaskHost.exe, Pid: 12144, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446->(UTF-16LE), EstimatedImpact: 26%

2025-11-27T22:38:32.268 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 90, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 77, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 76, Count: 16, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 60, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 1%

2025-11-27T22:38:32.268 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\reported_apps_state.json, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 30, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.277.358.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: taskhostw.exe, Pid: 21288, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 14%

2025-11-27T22:38:32.268 ProcessImageName: ffdetect.exe, Pid: 15672, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 6%

2025-11-27T22:38:32.268 ProcessImageName: taskhostw.exe, Pid: 21148, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 14%

2025-11-27T22:38:32.268 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: updater.exe, Pid: 26412, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\6f56148f-a503-4c50-899c-6238f1f33041.tmp, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\507a366f-4a19-499e-87d3-239447acf8f9.tmp, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\chunk~2dcc5aaf7.css, EstimatedImpact: 11%

2025-11-27T22:38:32.268 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 3%

2025-11-27T22:38:32.268 ProcessImageName: svchost.exe, Pid: 23284, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BITA1E8.tmp, EstimatedImpact: 6%

2025-11-27T22:38:32.268 ProcessImageName: StoreDesktopExtension.exe, Pid: 20844, TotalTime: 0, Count: 9, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: powershell.exe, Pid: 6868, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\__PSScriptPolicyTest_jcpdzgjd.nz1.psm1, EstimatedImpact: 0%

2025-11-27T22:38:32.268 ProcessImageName: updater.exe, Pid: 22340, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-27T22:46:11.818 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T22:52:06.062 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #375847, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T22:52:06.067 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #375848, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T22:52:16.077 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #375855, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T22:52:16.080 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #375856, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T22:52:16.080 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #375857, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T22:53:06.127 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #375872, FileId: 0x70000000337b4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T23:01:16.817 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T23:08:06.909 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #376113, FileId: 0xb0000000332c4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T23:16:21.811 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T23:23:07.456 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #376417, FileId: 0x6000000034158, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T23:24:29.548 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #376516, FileId: 0x104000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T23:31:26.810 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T23:38:08.099 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #377166, FileId: 0x170000000088e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T23:46:31.810 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-27T23:52:06.006 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #377496, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T23:52:06.009 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #377497, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T23:52:16.009 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #377505, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T23:52:16.013 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #377506, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-27T23:53:08.839 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #377517, FileId: 0x80000000344ad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T00:01:36.798 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T00:08:09.265 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #377746, FileId: 0x137000000013d97, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T00:16:41.787 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T00:17:06.787 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3

2025-11-28T00:17:06.788 Job Notification: New process added to job (18376)

2025-11-28T00:17:06.791 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched

2025-11-28T00:17:06.792 Aggressive catchup quick scan threshold: 2542415285419 / 25920000000000

2025-11-28T00:17:06.795 Job Notification: New process added to job (23136)

2025-11-28T00:17:06.803 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:18376] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:23136]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-28T00:17:06.850 Job Notification: New process added to job (14004)

2025-11-28T00:17:06.853 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched

2025-11-28T00:17:06.854 Job Notification: New process added to job (516)

2025-11-28T00:17:06.860 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:14004] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:516]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-28T00:17:06.884 Job Notification: New process added to job (10496)

2025-11-28T00:17:06.887 Task(GetDeviceTicket -AccessKey 67D03F57-6A27-80F8-69B4-CE5D50AA1BAB ) launched as network service

2025-11-28T00:17:07.308 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-28T00:17:07.308 [RTP] Duplicating the current plugin configuration object...

2025-11-28T00:17:07.308 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-28T00:17:07.308 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-28T00:17:07.309 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-28T00:17:07.309 [RTP] No config change detected. Not updating plugin configuration.

2025-11-28T00:17:07.309 [RTP] No config changes found. No configuration switch.

2025-11-28T00:17:07.309 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-28T00:17:07.350 Job Notification: Process exited from job (10496)

2025-11-28T00:17:07.594 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-28T00:17:07.594 [Cloud] Start of cloud request. Passive mode: 0

2025-11-28T00:17:07.594 [Cloud] Queued cloud request.

2025-11-28T00:17:07.594 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-28T00:17:07.594 [Cloud] Dequeued cloud request.

2025-11-28T00:17:07.595 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-28T00:17:07.595 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0

2025-11-28T00:17:07.595 [Cloud] Start of cloud request. Passive mode: 0

2025-11-28T00:17:07.595 [Cloud] Queued cloud request.

2025-11-28T00:17:07.595 [Cloud] Dequeued cloud request.

2025-11-28T00:17:07.597 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-28T00:17:07.700 [Cloud] End of cloud request.

2025-11-28T00:17:07.746 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-28T00:17:07.746 [Cloud] End of cloud request.

2025-11-28T00:17:08.104 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T00:17:13.026 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\9B9DAD3A-E625-4840-8A98-21CAEABEEC7367ac.1dc5ffc5740ac81

2025-11-28T00:17:13.082 Verifying engine and signature files (source: 0) ...

2025-11-28T00:17:13.082 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1C90460-CF39-4216-8AF1-6640B5F8E34B}\mpengine.dll] due to PPL.

2025-11-28T00:17:13.082 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1C90460-CF39-4216-8AF1-6640B5F8E34B}\mpasbase.vdm] (file in cache)

2025-11-28T00:17:13.082 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1C90460-CF39-4216-8AF1-6640B5F8E34B}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-28T00:17:13.093 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1C90460-CF39-4216-8AF1-6640B5F8E34B}\mpasdlta.vdm]

2025-11-28T00:17:13.093 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1C90460-CF39-4216-8AF1-6640B5F8E34B}\mpavbase.vdm] (file in cache)

2025-11-28T00:17:13.093 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1C90460-CF39-4216-8AF1-6640B5F8E34B}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-28T00:17:13.105 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1C90460-CF39-4216-8AF1-6640B5F8E34B}\mpavdlta.vdm]

2025-11-28T00:17:13.177 [Engine] IsHybridMode: 0

2025-11-28T00:17:13.177 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-28T00:17:13.187 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-98990AE1C2D2B98DFB5441ED73BC3C5CDF152437.bin): 0x00000002

2025-11-28T00:17:13.189 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-98990AE1C2D2B98DFB5441ED73BC3C5CDF152437.bin)

2025-11-28T00:17:13.189 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-28T00:17:13.189 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-28T00:17:13.189 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-28T00:17:13.189 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-28T00:17:18.443 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-28T00:17:18.444 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-28T00:17:18.448 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE6F7CA660, lRefCount: 5, hr=0

2025-11-28T00:17:18.448 [Engine] New active engine 00007FFE7225A660 replacing engine 00007FFE6F7CA660. Number of active engines: 2

2025-11-28T00:17:18.450 EngineInit:Global ASOC is enabled

2025-11-28T00:17:18.450 EngineInit:ASOO is enabled for developer volumes

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.483 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T00:17:18.484 MpWriteUupSignatureVersion 1.441.541.0, hr = 0

2025-11-28T00:17:18.486 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-28T00:17:18.499 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-28T00:17:18.500 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-28T00:17:18.500 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-28T00:17:18.500 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-28T00:17:18.500 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-28T00:17:18.514 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-28T00:17:18.514 [Plugin] Initializing RTP plugin state...

2025-11-28T00:17:18.514 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-28T00:17:18.514 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 27 - 2025 19:38:32

Last Perf: 11 - 27 - 2025 19:38:32

First RTP Scan: 11 - 27 - 2025 19:38:33

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:810

  Misses:4068

BM Queue:0,38,0

  Proc:0,37,0

  File:0,15,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:378030

  Pending:0

  RegSize:306846

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:-2026381244

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:21

  TotalStreamCon:34750

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:2086674

   TotalHits:2803049

   InstanceCacheInserts:132347

   InstanceCacheUpdates:0

   InstanceCacheDeletes:103478

   InstanceCacheHits:5057

   InstanceCacheMisses:496470

   InstanceCacheOverflows:10504

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (697/797)

   Success: 797, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-28T00:17:18.514 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1C90460-CF39-4216-8AF1-6640B5F8E34B}

2025-11-28T00:17:18.514 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F2EA411A-C9CF-44D3-A413-3E87B2588F94}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F2EA411A-C9CF-44D3-A413-3E87B2588F94}\mpasbase.vdm in use, hr=0x80070020

2025-11-28T00:17:18.515 [SCC][CID=974268953_27980] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-28T00:17:18.515 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-28T00:17:18.515 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-28T00:17:18.515 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-28T00:17:18.516 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-28T00:17:18.516 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-28T00:17:18.516 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-28-2025 00:17:18

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-28-2025 00:17:18

2025-11-28T00:17:18.519 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-28T00:17:18.519 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-28T00:17:18.520 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-28T00:17:18.520 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-28-2025 00:17:18

END TDT(U) telemetry



2025-11-28T00:17:18.522 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T00:17:18.522 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-28T00:17:18.522 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-28T00:17:18.522 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-28T00:17:18.522 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-28T00:17:18.522 MdCoreSvc is supported in this platform and OS

Signature updated on 11-28-2025 00:17:18

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.541.0

AV Signature Version: 1.441.541.0

************************************************************

2025-11-28T00:17:18.524 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-28T00:17:18.524 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\9B9DAD3A-E625-4840-8A98-21CAEABEEC7367ac.1dc5ffc5740ac81

2025-11-28T00:17:18.545 Process scan (postsignatureupdatescan) started.

2025-11-28T00:17:18.565 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-28T00:17:18.566 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

Signature updated via MicrosoftUpdateServer on 11-28-2025 00:17:18

************************************************************

2025-11-28T00:17:18.619 Job Notification: Process exited from job (14004)

2025-11-28T00:17:18.620 Job Notification: Process exited from job (516)

2025-11-28T00:17:18.655 Job Notification: Process exited from job (18376)

2025-11-28T00:17:18.656 Job Notification: Process exited from job (23136)

2025-11-28T00:17:18.705 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-28T00:17:18.705 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-28T00:17:18.705 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-28T00:17:18.705 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-28T00:17:18.705 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-28T00:17:18.707 [Engine] Engine 00007FFE6F7CA660 no longer in use. Number of active engines: 1

2025-11-28T00:17:18.707 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-28T00:17:18.707 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-28T00:17:18.838 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 13966, Count: 1771, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-28T00:17:18.838 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2312, Count: 244, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\b9011350-9aec-4950-bfb0-be1f4a48ea12.tmp, EstimatedImpact: 0%

2025-11-28T00:17:18.838 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2044, Count: 152, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\9fd99fea-a988-4329-9f32-b223f1bc155a.tmp, EstimatedImpact: 0%

2025-11-28T00:17:18.838 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1646, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 85%

2025-11-28T00:17:18.838 ProcessImageName: RuntimeBroker.exe, Pid: 21540, TotalTime: 434, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-28T00:17:18.838 ProcessImageName: powershell.exe, Pid: 19268, TotalTime: 336, Count: 45, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\4acfdbda9fe7d2c227cd2d57ea292ba9\System.Management.Automation.ni.dll, EstimatedImpact: 30%

2025-11-28T00:17:18.838 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 241, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T00:17:18.838 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 240, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Network Shortcuts\SSL\target.lnk, EstimatedImpact: 9%

2025-11-28T00:17:18.838 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28028, TotalTime: 225, Count: 58, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-28T00:17:18.838 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 210, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\telemetry-dll-ramp-value.txt, EstimatedImpact: 0%

2025-11-28T00:17:18.838 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 5848, TotalTime: 195, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 3%

2025-11-28T00:17:18.838 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 195, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-28T00:17:18.838 ProcessImageName: taskhostw.exe, Pid: 26724, TotalTime: 180, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 9%

2025-11-28T00:17:18.838 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 135, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T00:17:18.838 ProcessImageName: backgroundTaskHost.exe, Pid: 12144, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446->(UTF-16LE), EstimatedImpact: 26%

2025-11-28T00:17:18.838 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 106, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-28T00:17:18.853 [Engine] RSIG_UNLOADENGINE, 00007FFE6F7CA660, err=0x0

2025-11-28T00:17:18.868 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F2EA411A-C9CF-44D3-A413-3E87B2588F94} removed

2025-11-28T00:17:18.999 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-28T00:17:19.006 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-28T00:17:19.006 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-28T00:17:19.006 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-28T00:17:19.007 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-28T00:17:19.007 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-28T00:17:19.007 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-28T00:17:19.010 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-28T00:17:19.010 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-28T00:17:19.010 [RTP] Duplicating the current plugin configuration object...

2025-11-28T00:17:19.010 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-28T00:17:19.010 [RTP] Updating plugin configuration due to recent config changes (0x22) ...

2025-11-28T00:17:19.010 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-28T00:17:19.010 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-28T00:17:19.010 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-28T00:17:19.010 [RTP] No config change detected. Not updating plugin configuration.

2025-11-28T00:17:19.010 [RTP] No config changes found. No configuration switch.

2025-11-28T00:17:19.010 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x22, Changed: 0

2025-11-28T00:17:19.010 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-28T00:17:19.010 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-28T00:17:19.010 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-28T00:17:19.010 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-28T00:17:19.010 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-28T00:17:19.010 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-28T00:17:19.010 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-28T00:17:19.010 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-28T00:17:19.010 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-28T00:17:19.010 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-28T00:17:19.010 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-28T00:17:19.010 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-28T00:17:19.010 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-28T00:17:19.011 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-28T00:17:19.011 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T00:17:19.012 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T00:17:19.014 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T00:17:19.015 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T00:17:19.017 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T00:17:19.019 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 16165214(ms) from now at 05:46 (04:46 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-28T00:17:20.547 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-28T00:17:20.550 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-28T00:17:20.551 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-28T00:17:21.557 [RTP] Duplicating the current plugin configuration object...

2025-11-28T00:17:21.557 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-28T00:17:21.557 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-28T00:17:21.557 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-28T00:17:21.557 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-28T00:17:23.854 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-28T00:17:23.854 [Cloud] Start of cloud request. Passive mode: 0

2025-11-28T00:17:23.854 [Cloud] Queued cloud request.

2025-11-28T00:17:23.854 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-28T00:17:23.855 [Cloud] Dequeued cloud request.

2025-11-28T00:17:23.855 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-28T00:17:24.210 [Cloud] End of cloud request.

2025-11-28T00:17:24.726 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T00:17:32.658 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-28T00:17:32.659 Process scan (postsignatureupdatescan) completed.

2025-11-28T00:22:18.466 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-28T00:23:09.771 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #378298, FileId: 0x6300000003b5ad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T00:31:46.793 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T00:38:10.391 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #378708, FileId: 0x4a00000003a0bf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T00:46:51.785 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T00:52:07.663 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #378993, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T00:52:07.666 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #378994, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T00:52:17.670 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #379001, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T00:52:17.674 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #379002, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T00:53:11.797 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #379011, FileId: 0xf000000078b0e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T01:01:56.783 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T01:08:12.107 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #379218, FileId: 0x170000000788cb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T01:17:01.767 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T01:22:15.464 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T01:23:12.437 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #379710, FileId: 0x20000000078c95, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T01:32:06.762 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T01:38:13.201 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #379892, FileId: 0x1c000000078c44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T01:39:46.116 [AutoPurge] Verification Routine tasks have started.

2025-11-28T01:39:46.116 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-28T01:39:46.119 [AutoPurge] Routine task for Cache Maintenance has started.

2025-11-28T01:39:46.120 [AutoPurge] Routine task for Cache Maintenance ...

2025-11-28T01:39:46.120 [AutoPurge] Routine task for MpSFCBuild ...

2025-11-28T01:39:46.120 [AutoPurge] MpCmIsBuildCompleted() - S_OK

2025-11-28T01:39:46.120 [AutoPurge] MpSignalMaintenanceMode ...

2025-11-28T01:39:46.120 [AutoPurge] Routine task for Cache Maintenance has ended.

2025-11-28T01:39:46.125 [AutoPurge] Cleanup Routine tasks have started.

2025-11-28T01:39:46.130 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:48657335-446A-4EBC-95D3-AE38081C382F, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1)

2025-11-28T01:39:46.130 Scheduled scan with Id 48657335-446A-4EBC-95D3-AE38081C382F configured CPU priority: normal (LowCpuPriority: 0)

2025-11-28T01:39:46.131 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0)

2025-11-28T01:39:46.131 [AutoPurge] Purged 0 expired detection item(s) from a total of 0.

2025-11-28T01:39:46.131 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build.

2025-11-28T01:39:46.131 [SFC] System file cache build is not needed (already completed)

2025-11-28T01:39:46.131 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds)

2025-11-28T01:39:46.131 QuickScan:ScanID:48657335-446A-4EBC-95D3-AE38081C382F: Quick Scan skipped since it already ran during the past 7 days

2025-11-28T01:39:46.131 QuickScan:ScanID:48657335-446A-4EBC-95D3-AE38081C382F: Quick scan finished with error 1223

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:65538

Start time:11-28-2025 01:39:46

2025-11-28T01:39:46.131 OnDemandScanWorker: Scan Cancelled! scanId:48657335-446A-4EBC-95D3-AE38081C382F, hr = 0x80508018

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-28-2025 01:39:46

!ERROR

Begin Quick Scan

Scan ID:{48657335-446A-4EBC-95D3-AE38081C382F}

Scan Source:1

Start Time:11-28-2025 01:39:46

Unsuccessful Scan

Return Code:1223

************************************************************



2025-11-28T01:39:46.134 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ...

2025-11-28T01:39:46.134 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0 ...

2025-11-28T01:39:46.134 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0 ...

2025-11-28T01:39:46.134 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ...

2025-11-28T01:39:46.135 [AutoPurge] Cleanup Routine tasks have ended.

2025-11-28T01:39:46.185 EnsureProtectedFolderAcls(), hr = 0x0

2025-11-28T01:39:46.187 [AutoPurge] MpReinforceServiceAcls: 0

2025-11-28T01:39:46.198 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0

2025-11-28T01:39:46.200 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed.

2025-11-28T01:39:46.201 [AutoPurge] Verification Routine tasks have ended.

2025-11-28T01:39:48.148 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-28T01:39:48.152 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-28T01:39:48.152 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-28T01:39:50.162 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-28T01:39:50.164 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-28T01:39:50.165 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-28T01:47:11.767 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T01:52:06.193 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #380152, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T01:52:06.197 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #380153, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T01:52:16.197 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #380161, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T01:52:16.201 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #380162, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T01:53:13.220 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #380175, FileId: 0x450000000290d6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T02:02:16.752 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T02:07:07.293 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

2025-11-28T02:07:07.302 [DLP] DlpEngineConfigStorage::OnConfigChange DlpDwordSettingsMap:

2025-11-28T02:07:07.303 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-28T02:07:07.303 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-28T02:07:07.303 [RTP] Duplicating the current plugin configuration object...

2025-11-28T02:07:07.303 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-28T02:07:07.303 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-28T02:07:07.303 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-28T02:07:07.303 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-28T02:07:07.303 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-28T02:07:07.303 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-28T02:07:07.303 [RTP] No config change detected. Not updating plugin configuration.

2025-11-28T02:07:07.303 [RTP] No config changes found. No configuration switch.

2025-11-28T02:07:07.303 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-28T02:07:07.303 [RTP] [RtpConfig] Config change detected, type: 16

2025-11-28T02:07:07.303 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-28T02:07:07.303 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-28T02:07:07.303 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-28T02:07:07.303 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-28T02:07:07.303 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-28T02:07:07.303 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-28T02:07:07.303 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-28T02:07:07.303 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-28T02:07:07.303 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-28T02:07:07.303 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-28T02:07:07.303 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-28T02:07:07.303 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-28T02:07:07.303 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-28T02:07:07.303 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-28T02:07:07.304 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T02:07:07.305 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T02:07:07.307 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T02:07:07.309 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T02:07:07.310 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T02:07:07.311 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 9637056(ms) from now at 05:47 (04:47 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-28T02:07:09.849 [RTP] Duplicating the current plugin configuration object...

2025-11-28T02:07:09.849 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-28T02:07:09.849 [RTP] Updating plugin configuration due to recent config changes (0x41e) ...

2025-11-28T02:07:09.849 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-28T02:07:09.849 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x218

2025-11-28T02:08:14.104 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #380421, FileId: 0x9c00000002b60e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T02:09:55.529 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #380811, FileId: 0xc900000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T02:17:18.413 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 5250, Count: 724, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: RuntimeBroker.exe, Pid: 17652, TotalTime: 1083, Count: 42, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 900, Count: 85, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d7376d2a-e36d-491d-9870-909a86ff535c.tmp, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 600, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\742bec2e-4c2c-4e9d-9825-220301b49dbb.tmp, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: taskhostw.exe, Pid: 23940, TotalTime: 240, Count: 44, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 7%

2025-11-28T02:17:18.413 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 210, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: taskhostw.exe, Pid: 24492, TotalTime: 165, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 7%

2025-11-28T02:17:18.413 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 22%

2025-11-28T02:17:18.413 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: HxTsr.exe, Pid: 17084, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1822317515-1041744019-1682422708-1001-MergedResources-81.pri, EstimatedImpact: 17%

2025-11-28T02:17:18.413 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\f73ac36d-8b4d-4931-afee-f99ae0f9cdea.tmp, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: updater.exe, Pid: 21296, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-28T02:17:18.413 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-28T02:17:21.748 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T02:23:14.312 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #381221, FileId: 0x6900000002d3df, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T02:32:26.750 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T02:38:15.477 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #381469, FileId: 0x600000003168a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T02:47:31.749 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T02:52:06.288 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #381676, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T02:52:06.291 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #381677, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T02:52:16.299 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #381683, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T02:52:16.303 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #381684, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T02:53:16.898 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #381695, FileId: 0x70000000321b2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T03:02:36.735 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T03:08:17.043 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #382072, FileId: 0x80000000314a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T03:17:41.740 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T03:22:17.614 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T03:23:17.470 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #383047, FileId: 0x6000000032edf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T03:32:46.726 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T03:38:17.901 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #383256, FileId: 0x7000000033e4d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T03:47:51.724 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T03:52:06.400 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #383562, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T03:52:06.404 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #383563, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T03:52:16.414 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #383571, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T03:52:16.415 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #383572, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T03:52:16.417 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #383573, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T03:52:16.418 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #383574, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T03:53:18.384 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #383589, FileId: 0x7000000033cec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T04:02:56.725 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T04:08:19.846 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #383944, FileId: 0x6000000033b2f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T04:17:18.386 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 10995, Count: 1446, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1635, Count: 170, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d7376d2a-e36d-491d-9870-909a86ff535c.tmp, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1520, Count: 81, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 88%

2025-11-28T04:17:18.386 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1155, Count: 104, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\742bec2e-4c2c-4e9d-9825-220301b49dbb.tmp, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: RuntimeBroker.exe, Pid: 17652, TotalTime: 1083, Count: 42, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: DeviceCensus.exe, Pid: 14616, TotalTime: 342, Count: 11, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-28T04:17:18.386 ProcessImageName: taskhostw.exe, Pid: 23940, TotalTime: 240, Count: 44, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 7%

2025-11-28T04:17:18.386 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 225, Count: 57, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: taskhostw.exe, Pid: 24492, TotalTime: 165, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 7%

2025-11-28T04:17:18.386 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 154, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 120, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\f73ac36d-8b4d-4931-afee-f99ae0f9cdea.tmp, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 120, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 105, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 90, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 22%

2025-11-28T04:17:18.386 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\5f44eeec-7711-4490-a8d0-5ec1a4420a86.tmp, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\OneDrive\Bilder\Camera Roll\20251127_194117.jpg, EstimatedImpact: 1%

2025-11-28T04:17:18.386 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: taskhostw.exe, Pid: 27960, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 24%

2025-11-28T04:17:18.386 ProcessImageName: HxTsr.exe, Pid: 17084, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1822317515-1041744019-1682422708-1001-MergedResources-81.pri, EstimatedImpact: 17%

2025-11-28T04:17:18.386 ProcessImageName: StoreDesktopExtension.exe, Pid: 28020, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: updater.exe, Pid: 19280, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\6e64070c-1282-4547-bdd5-1584dd1b0292.tmp, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: svchost.exe, Pid: 13160, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_1142475879\BITA453.tmp, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: updater.exe, Pid: 27060, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\c522cbba-3ca5-432c-ace8-928d59c12286.tmp, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-28T04:17:18.386 ProcessImageName: updater.exe, Pid: 21296, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-28T04:18:01.716 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T04:23:20.194 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #384282, FileId: 0x5d00000003af7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T04:33:06.713 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T04:38:21.601 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #384496, FileId: 0x19000000078df3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T04:48:11.703 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T04:52:06.858 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #384672, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T04:52:06.861 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #384673, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T04:52:16.865 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #384679, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T04:52:16.869 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #384680, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T04:53:21.804 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #384695, FileId: 0x5b00000002b3d4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T05:03:16.703 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T05:08:23.232 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #384914, FileId: 0x5300000002838a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T05:18:21.696 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T05:22:19.632 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T05:23:23.449 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #385202, FileId: 0x6000000032370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T05:33:26.701 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T05:38:23.646 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #386710, FileId: 0xa000000078ec8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T05:48:31.694 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T05:52:05.311 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #386964, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T05:52:05.315 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #386965, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T05:52:15.311 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #386975, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T05:52:15.314 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #386976, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T05:52:15.326 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #386977, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T05:52:15.330 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #386978, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T05:53:23.706 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #386990, FileId: 0x6000000033c9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T06:03:36.690 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T06:08:23.900 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #387193, FileId: 0xc30000000282a8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T06:17:18.360 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 16831, Count: 2168, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2265, Count: 255, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d7376d2a-e36d-491d-9870-909a86ff535c.tmp, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1725, Count: 156, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\742bec2e-4c2c-4e9d-9825-220301b49dbb.tmp, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1520, Count: 81, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 88%

2025-11-28T06:17:18.360 ProcessImageName: RuntimeBroker.exe, Pid: 17652, TotalTime: 1083, Count: 42, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: DeviceCensus.exe, Pid: 14616, TotalTime: 342, Count: 11, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-28T06:17:18.360 ProcessImageName: WmiPrvSE.exe, Pid: 6164, TotalTime: 255, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf, EstimatedImpact: 22%

2025-11-28T06:17:18.360 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 255, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: taskhostw.exe, Pid: 23940, TotalTime: 240, Count: 44, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 7%

2025-11-28T06:17:18.360 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 180, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 169, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: taskhostw.exe, Pid: 24492, TotalTime: 165, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 7%

2025-11-28T06:17:18.360 ProcessImageName: svchost.exe, Pid: 28048, TotalTime: 151, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 100%

2025-11-28T06:17:18.360 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 150, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 135, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 120, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\f73ac36d-8b4d-4931-afee-f99ae0f9cdea.tmp, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 105, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\da6ee8bf-055b-4d50-9f1f-1b4f3ffcc006\content.phf, EstimatedImpact: 1%

2025-11-28T06:17:18.360 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 60, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 22%

2025-11-28T06:17:18.360 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\5f44eeec-7711-4490-a8d0-5ec1a4420a86.tmp, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\OneDrive\Bilder\Camera Roll\20251127_194117.jpg, EstimatedImpact: 1%

2025-11-28T06:17:18.360 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: taskhostw.exe, Pid: 27960, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 24%

2025-11-28T06:17:18.360 ProcessImageName: HxTsr.exe, Pid: 17084, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1822317515-1041744019-1682422708-1001-MergedResources-81.pri, EstimatedImpact: 17%

2025-11-28T06:17:18.360 ProcessImageName: StoreDesktopExtension.exe, Pid: 28020, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: updater.exe, Pid: 19280, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\6e64070c-1282-4547-bdd5-1584dd1b0292.tmp, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: taskhostw.exe, Pid: 17360, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 2%

2025-11-28T06:17:18.360 ProcessImageName: svchost.exe, Pid: 13160, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_1142475879\BITA453.tmp, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: updater.exe, Pid: 27060, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\c522cbba-3ca5-432c-ace8-928d59c12286.tmp, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-28T06:17:18.360 ProcessImageName: updater.exe, Pid: 21296, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-28T06:18:41.683 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T06:23:25.335 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #387524, FileId: 0x970000000131a5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T06:33:46.683 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T06:38:25.674 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #387757, FileId: 0x4b000000023966, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T06:48:51.681 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T06:52:07.949 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #387954, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T06:52:07.953 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #387955, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T06:52:17.963 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #387961, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T06:52:17.966 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #387962, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T06:53:26.868 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #387971, FileId: 0x1800000007a669, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T07:00:53.020 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\A49D7793-5ED6-4244-9FC9-3AA79ECABB225be0.1dc6034bb7b84b5

2025-11-28T07:00:53.053 Verifying engine and signature files (source: 0) ...

2025-11-28T07:00:53.053 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD3AA790-D2DA-4A68-A34D-62641E0468B1}\mpengine.dll] due to PPL.

2025-11-28T07:00:53.053 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD3AA790-D2DA-4A68-A34D-62641E0468B1}\mpasbase.vdm] (file in cache)

2025-11-28T07:00:53.053 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD3AA790-D2DA-4A68-A34D-62641E0468B1}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-28T07:00:53.063 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD3AA790-D2DA-4A68-A34D-62641E0468B1}\mpasdlta.vdm]

2025-11-28T07:00:53.063 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD3AA790-D2DA-4A68-A34D-62641E0468B1}\mpavbase.vdm] (file in cache)

2025-11-28T07:00:53.063 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD3AA790-D2DA-4A68-A34D-62641E0468B1}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-28T07:00:53.074 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD3AA790-D2DA-4A68-A34D-62641E0468B1}\mpavdlta.vdm]

2025-11-28T07:00:53.145 [Engine] IsHybridMode: 0

2025-11-28T07:00:53.145 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-28T07:00:53.151 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-4392BA84C5E7921446CFAC83B19460BF60735649.bin): 0x00000002

2025-11-28T07:00:53.155 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-4392BA84C5E7921446CFAC83B19460BF60735649.bin)

2025-11-28T07:00:53.155 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-28T07:00:53.155 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-28T07:00:53.155 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-28T07:00:53.155 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-28T07:00:58.621 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-28T07:00:58.621 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-28T07:00:58.629 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7225A660, lRefCount: 5, hr=0

2025-11-28T07:00:58.629 [Engine] New active engine 00007FFE4C3EA660 replacing engine 00007FFE7225A660. Number of active engines: 2

2025-11-28T07:00:58.631 EngineInit:Global ASOC is enabled

2025-11-28T07:00:58.631 EngineInit:ASOO is enabled for developer volumes

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-28T07:00:58.661 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.662 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.662 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.662 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.662 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.662 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.662 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T07:00:58.662 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\98402758d214e1f1828abd31bb5858b7eda24e44

Dynamic Signature Compilation Timestamp:11-27-2025 06:23:44

Persistence Type:Duration

Time remaining:864000000

2025-11-28T07:00:58.662 Dynamic signature dropped

2025-11-28T07:00:58.662 MpWriteUupSignatureVersion 1.441.550.0, hr = 0

2025-11-28T07:00:58.665 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-28T07:00:58.678 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-28T07:00:58.679 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-28T07:00:58.679 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-28T07:00:58.679 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-28T07:00:58.679 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-28T07:00:58.693 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-28T07:00:58.693 [Plugin] Initializing RTP plugin state...

2025-11-28T07:00:58.693 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-28T07:00:58.693 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 28 - 2025 01:17:18

Last Perf: 11 - 28 - 2025 01:17:18

First RTP Scan: 11 - 28 - 2025 01:17:18

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1231

  Misses:4911

BM Queue:0,36,0

  Proc:0,35,0

  File:0,9,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:388281

  Pending:0

  RegSize:306586

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:-1823243784

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:21

  TotalStreamCon:39947

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:2341273

   TotalHits:2904694

   InstanceCacheInserts:137281

   InstanceCacheUpdates:0

   InstanceCacheDeletes:109026

   InstanceCacheHits:5059

   InstanceCacheMisses:513815

   InstanceCacheOverflows:10504

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (587/803)

   Success: 803, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-28T07:00:58.693 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD3AA790-D2DA-4A68-A34D-62641E0468B1}

2025-11-28T07:00:58.693 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1C90460-CF39-4216-8AF1-6640B5F8E34B}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1C90460-CF39-4216-8AF1-6640B5F8E34B}\mpasbase.vdm in use, hr=0x80070020

2025-11-28T07:00:58.694 [SCC][CID=998489250_15412] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-28T07:00:58.694 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-28T07:00:58.694 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-28T07:00:58.694 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-28T07:00:58.695 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-28T07:00:58.695 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-28T07:00:58.695 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-28-2025 07:00:58

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-28-2025 07:00:58

2025-11-28T07:00:58.697 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-28T07:00:58.697 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-28T07:00:58.698 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-28T07:00:58.698 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-28-2025 07:00:58

END TDT(U) telemetry



2025-11-28T07:00:58.700 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T07:00:58.700 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-28T07:00:58.700 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-28T07:00:58.700 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-28T07:00:58.700 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-28T07:00:58.701 MdCoreSvc is supported in this platform and OS

Signature updated on 11-28-2025 07:00:58

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.550.0

AV Signature Version: 1.441.550.0

************************************************************

2025-11-28T07:00:58.702 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-28T07:00:58.702 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\A49D7793-5ED6-4244-9FC9-3AA79ECABB225be0.1dc6034bb7b84b5

2025-11-28T07:00:58.722 Process scan (postsignatureupdatescan) started.

2025-11-28T07:00:58.742 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-28T07:00:58.743 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-28T07:00:58.873 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-28T07:00:58.873 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-28T07:00:58.873 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-28T07:00:58.873 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-28T07:00:58.873 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-28T07:00:58.874 [Engine] Engine 00007FFE7225A660 no longer in use. Number of active engines: 1

2025-11-28T07:00:58.874 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-28T07:00:58.874 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-28T07:00:58.950 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 18751, Count: 2430, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-28T07:00:58.950 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2535, Count: 283, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\d7376d2a-e36d-491d-9870-909a86ff535c.tmp, EstimatedImpact: 0%

2025-11-28T07:00:58.950 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1920, Count: 176, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\742bec2e-4c2c-4e9d-9825-220301b49dbb.tmp, EstimatedImpact: 0%

2025-11-28T07:00:58.950 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1520, Count: 81, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 88%

2025-11-28T07:00:58.950 ProcessImageName: RuntimeBroker.exe, Pid: 17652, TotalTime: 1083, Count: 42, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-28T07:00:58.950 ProcessImageName: DeviceCensus.exe, Pid: 14616, TotalTime: 342, Count: 11, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-28T07:00:58.950 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 270, Count: 63, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\AT\r_PHM3PP4J9R6J6TVI\c_0H864NG6CFB59HVP\rc_B9NVNQPISMFG2QJD.bin, EstimatedImpact: 0%

2025-11-28T07:00:58.950 ProcessImageName: WmiPrvSE.exe, Pid: 6164, TotalTime: 255, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\swenum.inf, EstimatedImpact: 22%

2025-11-28T07:00:58.950 ProcessImageName: taskhostw.exe, Pid: 23940, TotalTime: 240, Count: 44, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 7%

2025-11-28T07:00:58.950 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 210, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T07:00:58.950 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 180, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T07:00:58.950 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 169, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-28T07:00:58.950 ProcessImageName: taskhostw.exe, Pid: 24492, TotalTime: 165, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 7%

2025-11-28T07:00:58.950 ProcessImageName: svchost.exe, Pid: 28048, TotalTime: 151, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 100%

2025-11-28T07:00:58.950 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 150, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-28T07:00:58.950 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 120, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\f73ac36d-8b4d-4931-afee-f99ae0f9cdea.tmp, EstimatedImpact: 0%

2025-11-28T07:00:58.973 [Engine] RSIG_UNLOADENGINE, 00007FFE7225A660, err=0x0

2025-11-28T07:00:58.992 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1C90460-CF39-4216-8AF1-6640B5F8E34B} removed

2025-11-28T07:00:59.190 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-28T07:00:59.197 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-28T07:00:59.197 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-28T07:00:59.197 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-28T07:00:59.198 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-28T07:00:59.198 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-28T07:00:59.198 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-28T07:00:59.201 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-28T07:00:59.201 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-28T07:00:59.201 [RTP] Duplicating the current plugin configuration object...

2025-11-28T07:00:59.201 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-28T07:00:59.201 [RTP] Updating plugin configuration due to recent config changes (0x22) ...

2025-11-28T07:00:59.201 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-28T07:00:59.201 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-28T07:00:59.201 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-28T07:00:59.201 [RTP] No config change detected. Not updating plugin configuration.

2025-11-28T07:00:59.201 [RTP] No config changes found. No configuration switch.

2025-11-28T07:00:59.201 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x22, Changed: 0

2025-11-28T07:00:59.201 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-28T07:00:59.201 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-28T07:00:59.201 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-28T07:00:59.201 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-28T07:00:59.201 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-28T07:00:59.201 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-28T07:00:59.201 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-28T07:00:59.202 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-28T07:00:59.202 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-28T07:00:59.202 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-28T07:00:59.202 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-28T07:00:59.202 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-28T07:00:59.202 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-28T07:00:59.202 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-28T07:00:59.202 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T07:00:59.203 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T07:00:59.205 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T07:00:59.206 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T07:00:59.209 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T07:00:59.210 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 75315085(ms) from now at 04:56 (03:56 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-28T07:01:00.708 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-28T07:01:00.711 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-28T07:01:00.712 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-28T07:01:01.722 [RTP] Duplicating the current plugin configuration object...

2025-11-28T07:01:01.722 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-28T07:01:01.722 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-28T07:01:01.722 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-28T07:01:01.722 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157ED7C270CE, sigsha=5eded354160aa060b3f2a16db0725661264de9cd, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF9518016, sigsha=8fa60ffaf004b3696b5767c35f78f1425d04eb09, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0xa85b3f00

2025-11-28T07:01:03.930 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-28T07:01:03.930 [Cloud] Start of cloud request. Passive mode: 0

2025-11-28T07:01:03.930 [Cloud] Queued cloud request.

2025-11-28T07:01:03.930 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-28T07:01:03.930 [Cloud] Dequeued cloud request.

2025-11-28T07:01:03.930 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\600323d6a0b82a027026391ac362e3a2f8b56c6a

Dynamic Signature Compilation Timestamp:11-28-2025 07:01:04

Persistence Type:Duration

Time remaining:864000000

2025-11-28T07:01:04.197 Dynamic signature received

2025-11-28T07:01:04.197 [Cloud] End of cloud request.

2025-11-28T07:01:04.198 RTSD:RTSD recieved, rescanning impacted resources

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-28T07:01:04.708 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T07:01:05.614 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-28T07:01:05.614 [Cloud] Start of cloud request. Passive mode: 0

2025-11-28T07:01:05.614 [Cloud] Queued cloud request.

2025-11-28T07:01:05.614 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-28T07:01:05.614 [Cloud] Dequeued cloud request.

2025-11-28T07:01:05.614 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-28T07:01:05.945 [Cloud] End of cloud request.

2025-11-28T07:01:06.462 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T07:01:14.057 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-28T07:01:14.058 Process scan (postsignatureupdatescan) completed.

2025-11-28T07:03:56.671 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T07:05:58.644 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-28T07:08:28.001 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #388591, FileId: 0x1e00000007a6fc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T07:19:01.675 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T07:23:29.372 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #389161, FileId: 0x1d00000007a795, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T07:34:06.675 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T07:38:29.816 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #389378, FileId: 0x1230000000088a1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T07:49:11.669 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T07:52:06.185 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #389623, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T07:52:06.189 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #389624, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T07:52:16.190 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #389632, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T07:52:16.194 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #389633, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T07:53:30.163 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #389651, FileId: 0x3b00000007a882, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T08:01:57.390 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #389893, FileId: 0x105000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T08:04:16.663 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T08:08:30.501 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #389993, FileId: 0x3870000000212cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T08:19:21.657 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T08:22:22.565 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T08:23:31.911 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #390792, FileId: 0x9200000002aa54, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T08:34:26.653 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T08:38:31.955 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #391020, FileId: 0x250000000548dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T08:49:31.648 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T08:52:06.117 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #391208, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T08:52:06.120 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #391209, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T08:52:16.117 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #391216, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T08:52:16.118 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #391217, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T08:52:16.120 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #391218, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T08:52:16.121 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #391219, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T08:53:32.164 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #391228, FileId: 0x83000000028469, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T09:00:58.605 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 5160, Count: 722, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-28T09:00:58.605 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1518, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 87%

2025-11-28T09:00:58.605 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 915, Count: 85, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\56da8cbe-0745-490f-8014-d5f5f495750f.tmp, EstimatedImpact: 0%

2025-11-28T09:00:58.605 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 630, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\00f92601-5384-4e70-a1a0-01e73636251b.tmp, EstimatedImpact: 0%

2025-11-28T09:00:58.605 ProcessImageName: RuntimeBroker.exe, Pid: 27576, TotalTime: 586, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-28T09:00:58.605 ProcessImageName: taskhostw.exe, Pid: 27716, TotalTime: 195, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 10%

2025-11-28T09:00:58.605 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 180, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-28T09:00:58.605 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 61, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-28T09:00:58.605 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T09:00:58.605 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T09:00:58.605 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-28T09:00:58.605 ProcessImageName: StoreDesktopExtension.exe, Pid: 17784, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-28T09:00:58.605 ProcessImageName: taskhostw.exe, Pid: 6720, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-28T09:00:58.605 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.277.358.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-28T09:00:58.605 ProcessImageName: updater.exe, Pid: 10156, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-28T09:00:58.605 ProcessImageName: updater.exe, Pid: 19504, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\d5937876-f58e-404d-94e9-aebfa5f553bd.tmp, EstimatedImpact: 0%

2025-11-28T09:04:36.645 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T09:08:32.339 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #391527, FileId: 0x6000000031080, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T09:09:55.442 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #391676, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T09:19:41.637 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T09:23:33.566 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #391964, FileId: 0x1900000007a8d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T09:34:46.636 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T09:38:33.997 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #392136, FileId: 0x1860000000040c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T09:45:41.003 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #392297, FileId: 0x106000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T09:49:51.627 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T09:52:04.752 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #392380, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T09:52:04.756 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #392381, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T09:52:14.756 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #392389, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T09:52:14.760 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #392390, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T09:53:35.377 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #392403, FileId: 0x7a00000003ed2a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T10:04:56.628 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T10:08:35.684 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #392792, FileId: 0x7000000030f58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T10:20:01.617 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T10:22:24.583 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T10:23:36.532 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #392997, FileId: 0x5c00000007a9ad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T10:35:06.616 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T10:38:37.238 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #393223, FileId: 0xd7000000019fa3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T10:50:11.601 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T10:52:08.056 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #393459, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T10:52:08.060 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #393460, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T10:52:18.064 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #393466, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T10:52:18.068 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #393467, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T10:53:37.808 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #393482, FileId: 0x3600000007aa63, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T11:00:58.576 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 12076, Count: 1583, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1711, Count: 171, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\082a61b9-d5bb-438a-b32a-55967834b273.tmp, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1518, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 87%

2025-11-28T11:00:58.576 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1322, Count: 109, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ed16c363-4920-44fe-9329-e214403d37e0.tmp, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: RuntimeBroker.exe, Pid: 27576, TotalTime: 586, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-28T11:00:58.576 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 195, Count: 55, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: taskhostw.exe, Pid: 27716, TotalTime: 195, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 10%

2025-11-28T11:00:58.576 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 135, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 105, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 92, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 90, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.277.358.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: taskhostw.exe, Pid: 21452, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 5%

2025-11-28T11:00:58.576 ProcessImageName: StoreDesktopExtension.exe, Pid: 17784, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: taskhostw.exe, Pid: 6720, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-28T11:00:58.576 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\5378b854-33b1-4210-ba89-3d2710c57bb3.tmp, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: updater.exe, Pid: 10156, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-28T11:00:58.576 ProcessImageName: updater.exe, Pid: 19504, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\d5937876-f58e-404d-94e9-aebfa5f553bd.tmp, EstimatedImpact: 0%

2025-11-28T11:05:16.599 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T11:08:38.926 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #393886, FileId: 0x7d0000000279a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T11:20:21.597 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T11:23:39.868 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #394249, FileId: 0x1900000007aadd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T11:35:26.596 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T11:38:40.323 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #394467, FileId: 0x5f00000007ab40, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T11:50:31.588 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T11:52:07.868 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #394738, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T11:52:07.872 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #394739, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T11:52:17.882 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #394747, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T11:52:17.887 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #394748, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T11:53:41.382 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #394764, FileId: 0x1b00000007ab69, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T12:05:36.583 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T12:08:42.087 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #395054, FileId: 0x1a00000007abb1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T12:20:41.578 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T12:22:26.534 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T12:23:42.972 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #395438, FileId: 0x7000000003bf29, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T12:35:46.580 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T12:38:43.726 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #395657, FileId: 0x3d0000000551a0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T12:50:51.572 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T12:52:08.057 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #395882, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T12:52:08.060 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #395883, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T12:52:18.068 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #395889, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T12:52:18.071 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #395890, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T12:53:44.604 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #395941, FileId: 0x1000000007ac49, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T13:00:58.544 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 20522, Count: 2659, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2553, Count: 257, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\082a61b9-d5bb-438a-b32a-55967834b273.tmp, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2014, Count: 162, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ed16c363-4920-44fe-9329-e214403d37e0.tmp, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1518, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 87%

2025-11-28T13:00:58.544 ProcessImageName: RuntimeBroker.exe, Pid: 27576, TotalTime: 586, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-28T13:00:58.544 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 225, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 210, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: taskhostw.exe, Pid: 27716, TotalTime: 195, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 10%

2025-11-28T13:00:58.544 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 165, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 150, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 92, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: taskhostw.exe, Pid: 27952, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-28T13:00:58.544 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 30, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.277.358.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: StoreDesktopExtension.exe, Pid: 17784, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: taskhostw.exe, Pid: 21452, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 5%

2025-11-28T13:00:58.544 ProcessImageName: taskhostw.exe, Pid: 17228, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 19%

2025-11-28T13:00:58.544 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\5378b854-33b1-4210-ba89-3d2710c57bb3.tmp, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: taskhostw.exe, Pid: 19136, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 20%

2025-11-28T13:00:58.544 ProcessImageName: taskhostw.exe, Pid: 6720, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-28T13:00:58.544 ProcessImageName: updater.exe, Pid: 10156, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: taskhostw.exe, Pid: 13348, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-28T13:00:58.544 ProcessImageName: updater.exe, Pid: 19504, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\d5937876-f58e-404d-94e9-aebfa5f553bd.tmp, EstimatedImpact: 0%

2025-11-28T13:05:56.571 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T13:08:45.525 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #396199, FileId: 0x1900000007ac92, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T13:21:01.556 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T13:23:46.347 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #396893, FileId: 0x1600000007ad2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T13:36:06.559 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T13:38:47.173 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #397122, FileId: 0x1800000007ad71, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T13:51:11.558 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T13:52:06.132 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #397410, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T13:52:06.136 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #397411, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T13:52:16.137 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #397418, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T13:52:16.139 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #397419, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T13:52:16.142 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #397420, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T13:52:16.146 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #397421, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T13:53:48.006 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #397438, FileId: 0x3b000000055654, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T14:06:16.559 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T14:08:48.920 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #397695, FileId: 0x13000000055824, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T14:09:55.650 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #397834, FileId: 0xcb00000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T14:21:21.548 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T14:22:28.565 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T14:23:49.881 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #398062, FileId: 0x27000000055c00, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T14:36:26.545 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T14:38:50.581 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #398340, FileId: 0x19000000055cfc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T14:51:31.540 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T14:52:05.866 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #398575, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T14:52:05.870 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #398576, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T14:52:15.872 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #398582, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T14:52:15.879 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #398584, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T14:53:51.372 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #398604, FileId: 0x8000000033a48, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T15:00:58.519 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 29434, Count: 3737, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3378, Count: 341, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\082a61b9-d5bb-438a-b32a-55967834b273.tmp, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2689, Count: 214, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ed16c363-4920-44fe-9329-e214403d37e0.tmp, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1518, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 87%

2025-11-28T15:00:58.519 ProcessImageName: RuntimeBroker.exe, Pid: 27576, TotalTime: 586, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-28T15:00:58.519 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 270, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 270, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 240, Count: 65, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: taskhostw.exe, Pid: 27716, TotalTime: 195, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 10%

2025-11-28T15:00:58.519 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 165, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 92, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: taskhostw.exe, Pid: 27952, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-28T15:00:58.519 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\5378b854-33b1-4210-ba89-3d2710c57bb3.tmp, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 45, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.277.358.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: taskhostw.exe, Pid: 21452, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 5%

2025-11-28T15:00:58.519 ProcessImageName: StoreDesktopExtension.exe, Pid: 17784, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: taskhostw.exe, Pid: 17228, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 19%

2025-11-28T15:00:58.519 ProcessImageName: taskhostw.exe, Pid: 9592, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-28T15:00:58.519 ProcessImageName: taskhostw.exe, Pid: 19136, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 20%

2025-11-28T15:00:58.519 ProcessImageName: taskhostw.exe, Pid: 6720, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-28T15:00:58.519 ProcessImageName: backgroundTaskHost.exe, Pid: 8844, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1764341984, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: updater.exe, Pid: 10156, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: updater.exe, Pid: 18700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\6fcf6079-266d-4df2-b324-c201ea70e237.tmp, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: taskhostw.exe, Pid: 13348, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-28T15:00:58.519 ProcessImageName: updater.exe, Pid: 19504, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\d5937876-f58e-404d-94e9-aebfa5f553bd.tmp, EstimatedImpact: 0%

2025-11-28T15:06:36.536 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T15:08:52.313 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #398944, FileId: 0x14000000055f30, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T15:21:41.542 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T15:23:52.871 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #399221, FileId: 0x2400000007af03, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T15:36:46.532 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T15:38:53.620 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #399326, FileId: 0x2b000000055dd8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T15:41:10.224 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume4\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #399806, FileId: 0x233000000028273, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T15:51:51.529 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T15:52:05.306 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #399947, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T15:52:05.309 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #399948, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T15:52:15.306 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #399955, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T15:52:15.310 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #399956, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T15:52:15.321 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #399957, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T15:52:15.324 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #399958, FileId: 0xe7000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T15:53:54.656 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #399961, FileId: 0x1800000007afcf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T16:06:56.523 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T16:08:55.460 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #400082, FileId: 0x1600000007b038, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T16:22:01.522 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T16:22:30.550 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T16:23:56.348 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #400337, FileId: 0x1700000007b0bf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T16:37:06.509 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T16:38:57.115 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #400491, FileId: 0xf00000007b164, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T16:52:06.621 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #400594, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000001, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T16:52:06.624 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #400595, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T16:52:11.514 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T16:52:16.622 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #400600, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T16:52:16.622 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #400601, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T16:52:16.626 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #400602, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T16:53:57.700 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #400605, FileId: 0xd00000007b1f8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T17:00:58.503 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 30424, Count: 3865, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 4325, Count: 427, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\082a61b9-d5bb-438a-b32a-55967834b273.tmp, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3394, Count: 267, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ed16c363-4920-44fe-9329-e214403d37e0.tmp, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1518, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 87%

2025-11-28T17:00:58.503 ProcessImageName: RuntimeBroker.exe, Pid: 27576, TotalTime: 586, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-28T17:00:58.503 ProcessImageName: taskhostw.exe, Pid: 27808, TotalTime: 372, Count: 6, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 3%

2025-11-28T17:00:58.503 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 345, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 315, Count: 57, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 285, Count: 73, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 195, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: taskhostw.exe, Pid: 27716, TotalTime: 195, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 10%

2025-11-28T17:00:58.503 ProcessImageName: ngentask.exe, Pid: 26188, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 18%

2025-11-28T17:00:58.503 ProcessImageName: ngentask.exe, Pid: 29316, TotalTime: 135, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 14%

2025-11-28T17:00:58.503 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 92, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: taskhostw.exe, Pid: 27952, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-28T17:00:58.503 ProcessImageName: ngentask.exe, Pid: 28952, TotalTime: 60, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 14%

2025-11-28T17:00:58.503 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\5378b854-33b1-4210-ba89-3d2710c57bb3.tmp, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: ngentask.exe, Pid: 9424, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-28T17:00:58.503 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: ngentask.exe, Pid: 12468, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 39%

2025-11-28T17:00:58.503 ProcessImageName: ngentask.exe, Pid: 26344, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 52%

2025-11-28T17:00:58.503 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 45, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 45, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.277.358.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: taskhostw.exe, Pid: 27852, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 3%

2025-11-28T17:00:58.503 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: StoreDesktopExtension.exe, Pid: 17784, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: taskhostw.exe, Pid: 21452, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 5%

2025-11-28T17:00:58.503 ProcessImageName: taskhostw.exe, Pid: 17228, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 19%

2025-11-28T17:00:58.503 ProcessImageName: taskhostw.exe, Pid: 9592, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-28T17:00:58.503 ProcessImageName: taskhostw.exe, Pid: 6720, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-28T17:00:58.503 ProcessImageName: taskhostw.exe, Pid: 19136, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 20%

2025-11-28T17:00:58.503 ProcessImageName: backgroundTaskHost.exe, Pid: 8844, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1764341984, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: taskhostw.exe, Pid: 23536, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\8e2e8f09d1dfc4870ecd0b12c00c0c26ec5ce220.tbres, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: updater.exe, Pid: 10156, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: updater.exe, Pid: 18700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\6fcf6079-266d-4df2-b324-c201ea70e237.tmp, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: taskhostw.exe, Pid: 13348, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-28T17:00:58.503 ProcessImageName: updater.exe, Pid: 19504, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\d5937876-f58e-404d-94e9-aebfa5f553bd.tmp, EstimatedImpact: 0%

2025-11-28T17:07:16.511 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T17:08:58.568 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #400770, FileId: 0x1500000007b24e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T17:22:19.793 Bm signature throttled:0x00002db31bed458f

2025-11-28T17:22:21.505 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T17:23:59.207 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #400986, FileId: 0x1300000007b2be, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T17:37:26.501 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T17:38:59.953 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #401092, FileId: 0x1600000007b335, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T17:39:46.195 Bm signature throttled:0x00002db31bed458f

2025-11-28T17:52:04.887 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #401951, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T17:52:04.890 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #401952, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T17:52:14.901 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #401963, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T17:52:31.494 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T17:54:00.769 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #402349, FileId: 0x1500000007b3c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T18:01:37.326 Bm signature throttled:0x00002db31bed458f

2025-11-28T18:07:36.494 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T18:09:01.479 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #402517, FileId: 0x2700000007b477, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T18:21:46.271 Bm signature throttled:0x00002db31bed458f

2025-11-28T18:22:32.582 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T18:22:41.488 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T18:37:46.489 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T18:45:47.766 ReportLowfi(c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe, 0x83161cd9) from 0x0002c9bd4055ee43

2025-11-28T18:45:47.766 ReportLowfi(c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe , 0x83161cd9) from 0x0002c9bd4055ee43

2025-11-28T18:52:51.484 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T19:00:58.481 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 30439, Count: 3867, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 5165, Count: 514, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\082a61b9-d5bb-438a-b32a-55967834b273.tmp, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4101, Count: 319, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ed16c363-4920-44fe-9329-e214403d37e0.tmp, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1518, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 87%

2025-11-28T19:00:58.481 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1245, Count: 197, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 961, Count: 160, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\1080p\The Ring (2002) Multi 1080p BluRay AV1 [AV1D].mkv, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: RuntimeBroker.exe, Pid: 27576, TotalTime: 586, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-28T19:00:58.481 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 420, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 390, Count: 79, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: taskhostw.exe, Pid: 27808, TotalTime: 372, Count: 6, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 3%

2025-11-28T19:00:58.481 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 345, Count: 80, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: WmiPrvSE.exe, Pid: 9988, TotalTime: 275, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 86%

2025-11-28T19:00:58.481 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 255, Count: 50, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: taskhostw.exe, Pid: 27716, TotalTime: 195, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 10%

2025-11-28T19:00:58.481 ProcessImageName: ngentask.exe, Pid: 26188, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 18%

2025-11-28T19:00:58.481 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 135, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.277.358.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: ngentask.exe, Pid: 29316, TotalTime: 135, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 14%

2025-11-28T19:00:58.481 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 107, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\storport.sys, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\5378b854-33b1-4210-ba89-3d2710c57bb3.tmp, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: taskhostw.exe, Pid: 27952, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 4%

2025-11-28T19:00:58.481 ProcessImageName: ngentask.exe, Pid: 28952, TotalTime: 60, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 14%

2025-11-28T19:00:58.481 ProcessImageName: ngentask.exe, Pid: 9424, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-28T19:00:58.481 ProcessImageName: ngentask.exe, Pid: 26344, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 52%

2025-11-28T19:00:58.481 ProcessImageName: ngentask.exe, Pid: 12468, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 39%

2025-11-28T19:00:58.481 ProcessImageName: taskhostw.exe, Pid: 27852, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 3%

2025-11-28T19:00:58.481 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\59D76868C250B3240414CE3EFBB12518_3F5491CA446915306213EF514DD481E0, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 30, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 17%

2025-11-28T19:00:58.481 ProcessImageName: StoreDesktopExtension.exe, Pid: 17784, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: taskhostw.exe, Pid: 21452, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 5%

2025-11-28T19:00:58.481 ProcessImageName: taskhostw.exe, Pid: 19136, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 20%

2025-11-28T19:00:58.481 ProcessImageName: taskhostw.exe, Pid: 17228, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 19%

2025-11-28T19:00:58.481 ProcessImageName: taskhostw.exe, Pid: 9592, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-28T19:00:58.481 ProcessImageName: taskhostw.exe, Pid: 6720, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-28T19:00:58.481 ProcessImageName: backgroundTaskHost.exe, Pid: 23788, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\310091\1763750868, EstimatedImpact: 2%

2025-11-28T19:00:58.481 ProcessImageName: nvngx_update.exe, Pid: 29160, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\1\files\nvngx_mapping.json, EstimatedImpact: 5%

2025-11-28T19:00:58.481 ProcessImageName: backgroundTaskHost.exe, Pid: 8844, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1764341984, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: taskhostw.exe, Pid: 23536, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\8e2e8f09d1dfc4870ecd0b12c00c0c26ec5ce220.tbres, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: updater.exe, Pid: 18700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\6fcf6079-266d-4df2-b324-c201ea70e237.tmp, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: updater.exe, Pid: 10156, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: updater.exe, Pid: 10076, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\b066307d-8dd0-45a6-94a8-9745922cf018.tmp, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: taskhostw.exe, Pid: 13348, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: updater.exe, Pid: 19504, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\d5937876-f58e-404d-94e9-aebfa5f553bd.tmp, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NvProfileUpdaterPlugin\optimus\metadata.json, EstimatedImpact: 0%

2025-11-28T19:00:58.481 ProcessImageName: nvngx_update.exe, Pid: 5252, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-28T19:07:56.480 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T19:23:01.470 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T19:24:04.723 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #404100, FileId: 0x1300000007b6aa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T19:28:17.244 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\B3E8268B-1971-42ED-8300-587CDFFC9EAB1dc4.1dc609d24ba2131

2025-11-28T19:28:17.276 Verifying engine and signature files (source: 0) ...

2025-11-28T19:28:17.276 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D1DC849E-4D5A-47D1-B6B1-80F52BFF982C}\mpengine.dll] due to PPL.

2025-11-28T19:28:17.276 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D1DC849E-4D5A-47D1-B6B1-80F52BFF982C}\mpasbase.vdm] (file in cache)

2025-11-28T19:28:17.276 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D1DC849E-4D5A-47D1-B6B1-80F52BFF982C}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-28T19:28:17.286 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D1DC849E-4D5A-47D1-B6B1-80F52BFF982C}\mpasdlta.vdm]

2025-11-28T19:28:17.286 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D1DC849E-4D5A-47D1-B6B1-80F52BFF982C}\mpavbase.vdm] (file in cache)

2025-11-28T19:28:17.286 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D1DC849E-4D5A-47D1-B6B1-80F52BFF982C}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-28T19:28:17.296 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D1DC849E-4D5A-47D1-B6B1-80F52BFF982C}\mpavdlta.vdm]

2025-11-28T19:28:17.367 [Engine] IsHybridMode: 0

2025-11-28T19:28:17.367 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-28T19:28:17.372 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-7495E37D34F54C754078C0D5889090F41BA9F738.bin): 0x00000002

2025-11-28T19:28:17.377 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-7495E37D34F54C754078C0D5889090F41BA9F738.bin)

2025-11-28T19:28:17.377 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-28T19:28:17.377 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-28T19:28:17.377 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-28T19:28:17.377 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-28T19:28:22.736 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-28T19:28:22.737 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-28T19:28:22.744 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE4C3EA660, lRefCount: 5, hr=0

2025-11-28T19:28:22.744 [Engine] New active engine 00007FFE7225A660 replacing engine 00007FFE4C3EA660. Number of active engines: 2

2025-11-28T19:28:22.746 EngineInit:Global ASOC is enabled

2025-11-28T19:28:22.746 EngineInit:ASOO is enabled for developer volumes

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.776 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.777 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.777 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.777 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.777 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-28T19:28:22.778 MpWriteUupSignatureVersion 1.441.561.0, hr = 0

2025-11-28T19:28:22.779 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-28T19:28:22.792 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-28T19:28:22.793 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-28T19:28:22.793 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-28T19:28:22.793 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-28T19:28:22.793 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-28T19:28:22.807 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-28T19:28:22.807 [Plugin] Initializing RTP plugin state...

2025-11-28T19:28:22.808 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-28T19:28:22.808 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 28 - 2025 08:00:58

Last Perf: 11 - 28 - 2025 08:00:58

First RTP Scan: 11 - 28 - 2025 08:00:59

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:984

  Misses:7994

BM Queue:0,85,0

  Proc:0,75,0

  File:0,13,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:404272

  Pending:0

  RegSize:306586

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:-1644495248

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:21

  TotalStreamCon:49027

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:2502180

   TotalHits:3091918

   InstanceCacheInserts:145197

   InstanceCacheUpdates:0

   InstanceCacheDeletes:112615

   InstanceCacheHits:5061

   InstanceCacheMisses:539768

   InstanceCacheOverflows:10504

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (1171/1491)

   Success: 1491, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-28T19:28:22.808 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D1DC849E-4D5A-47D1-B6B1-80F52BFF982C}

2025-11-28T19:28:22.808 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD3AA790-D2DA-4A68-A34D-62641E0468B1}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD3AA790-D2DA-4A68-A34D-62641E0468B1}\mpasbase.vdm in use, hr=0x80070020

2025-11-28T19:28:22.808 [SCC][CID=1043333562_26932] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-28T19:28:22.809 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-28T19:28:22.809 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-28T19:28:22.809 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-28T19:28:22.809 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-28T19:28:22.809 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-28T19:28:22.809 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-28-2025 19:28:22

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-28-2025 19:28:22

2025-11-28T19:28:22.812 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-28T19:28:22.812 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-28T19:28:22.812 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-28T19:28:22.812 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-28-2025 19:28:22

END TDT(U) telemetry



2025-11-28T19:28:22.814 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T19:28:22.815 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-28T19:28:22.815 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-28T19:28:22.815 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-28T19:28:22.815 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-28T19:28:22.815 MdCoreSvc is supported in this platform and OS

Signature updated on 11-28-2025 19:28:22

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.561.0

AV Signature Version: 1.441.561.0

************************************************************

2025-11-28T19:28:22.816 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-28T19:28:22.816 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\B3E8268B-1971-42ED-8300-587CDFFC9EAB1dc4.1dc609d24ba2131

2025-11-28T19:28:22.831 Process scan (postsignatureupdatescan) started.

2025-11-28T19:28:22.856 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-28T19:28:22.857 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-28T19:28:22.990 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-28T19:28:22.990 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-28T19:28:22.990 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-28T19:28:22.990 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-28T19:28:22.990 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-28T19:28:22.991 [Engine] Engine 00007FFE4C3EA660 no longer in use. Number of active engines: 1

2025-11-28T19:28:22.991 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-28T19:28:22.991 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-28T19:28:23.078 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 30439, Count: 3867, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-28T19:28:23.078 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 5300, Count: 534, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\082a61b9-d5bb-438a-b32a-55967834b273.tmp, EstimatedImpact: 0%

2025-11-28T19:28:23.078 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4266, Count: 332, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\ed16c363-4920-44fe-9329-e214403d37e0.tmp, EstimatedImpact: 0%

2025-11-28T19:28:23.078 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1518, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 87%

2025-11-28T19:28:23.078 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1245, Count: 197, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-28T19:28:23.078 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 961, Count: 160, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume1\Filmer\1080p\The Ring (2002) Multi 1080p BluRay AV1 [AV1D].mkv, EstimatedImpact: 0%

2025-11-28T19:28:23.078 ProcessImageName: RuntimeBroker.exe, Pid: 27576, TotalTime: 586, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-28T19:28:23.078 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 450, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T19:28:23.078 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 420, Count: 85, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T19:28:23.078 ProcessImageName: taskhostw.exe, Pid: 27808, TotalTime: 372, Count: 6, MaxTime: 312, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 3%

2025-11-28T19:28:23.078 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 360, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-28T19:28:23.078 ProcessImageName: WmiPrvSE.exe, Pid: 9988, TotalTime: 275, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 86%

2025-11-28T19:28:23.078 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 255, Count: 52, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-28T19:28:23.078 ProcessImageName: taskhostw.exe, Pid: 27716, TotalTime: 195, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 10%

2025-11-28T19:28:23.078 ProcessImageName: ngentask.exe, Pid: 26188, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 18%

2025-11-28T19:28:23.078 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 135, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\AppRepository\Packages\SpotifyAB.SpotifyMusic_1.277.358.0_x64__zpdnekdrzrea0\S-1-5-21-1822317515-1041744019-1682422708-1001.pckgdep, EstimatedImpact: 0%

2025-11-28T19:28:23.097 [Engine] RSIG_UNLOADENGINE, 00007FFE4C3EA660, err=0x0

2025-11-28T19:28:23.116 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD3AA790-D2DA-4A68-A34D-62641E0468B1} removed

2025-11-28T19:28:23.308 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-28T19:28:23.314 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-28T19:28:23.314 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-28T19:28:23.314 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-28T19:28:23.315 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-28T19:28:23.315 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-28T19:28:23.315 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-28T19:28:23.318 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-28T19:28:23.318 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-28T19:28:23.318 [RTP] Duplicating the current plugin configuration object...

2025-11-28T19:28:23.318 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-28T19:28:23.318 [RTP] Updating plugin configuration due to recent config changes (0x22) ...

2025-11-28T19:28:23.318 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-28T19:28:23.318 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-28T19:28:23.318 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-28T19:28:23.318 [RTP] No config change detected. Not updating plugin configuration.

2025-11-28T19:28:23.318 [RTP] No config changes found. No configuration switch.

2025-11-28T19:28:23.318 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x22, Changed: 0

2025-11-28T19:28:23.318 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-28T19:28:23.318 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-28T19:28:23.318 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-28T19:28:23.318 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-28T19:28:23.318 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-28T19:28:23.318 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-28T19:28:23.318 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-28T19:28:23.318 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-28T19:28:23.318 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-28T19:28:23.318 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-28T19:28:23.318 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-28T19:28:23.318 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-28T19:28:23.318 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-28T19:28:23.318 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-28T19:28:23.319 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T19:28:23.320 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T19:28:23.322 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T19:28:23.324 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T19:28:23.325 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T19:28:23.327 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 28944281(ms) from now at 04:30 (03:30 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-28T19:28:24.832 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-28T19:28:24.836 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-28T19:28:24.836 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-28T19:28:25.844 [RTP] Duplicating the current plugin configuration object...

2025-11-28T19:28:25.844 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-28T19:28:25.844 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-28T19:28:25.844 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-28T19:28:25.844 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-28T19:28:28.027 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-28T19:28:28.027 [Cloud] Start of cloud request. Passive mode: 0

2025-11-28T19:28:28.027 [Cloud] Queued cloud request.

2025-11-28T19:28:28.027 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-28T19:28:28.028 [Cloud] Dequeued cloud request.

2025-11-28T19:28:28.028 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-28T19:28:28.432 [Cloud] End of cloud request.

2025-11-28T19:28:28.944 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-28T19:28:36.408 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-28T19:28:36.408 Process scan (postsignatureupdatescan) completed.

2025-11-28T19:33:22.764 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-28T19:38:06.460 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T19:39:05.048 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #404522, FileId: 0x16500000000e052, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T19:52:06.031 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #404916, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T19:52:06.035 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #404917, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T19:52:16.030 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #404925, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T19:52:16.034 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #404926, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T19:52:16.045 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #404927, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T19:52:16.049 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #404928, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T19:53:11.466 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T19:54:05.291 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #404940, FileId: 0x12500000000eb3f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T20:02:00.605 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #405140, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T20:08:16.460 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T20:09:06.189 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #405208, FileId: 0xd00000007b847, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T20:23:13.472 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\setup\logs\Install_2025-11-27_212158_21140-23644.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #405821, FileId: 0x6000000031686, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T20:23:13.532 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T20:23:21.450 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T20:24:06.764 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #405885, FileId: 0xb00000007b96d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T20:38:26.450 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T20:39:07.443 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #406066, FileId: 0x1200000007ba2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T20:52:07.652 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #406226, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T20:52:07.655 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #406227, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T20:52:17.662 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #406233, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T20:52:17.666 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #406234, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T20:53:31.439 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T20:54:07.880 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #406253, FileId: 0x1900000007b94a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T20:54:37.648 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T21:08:36.434 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T21:09:09.353 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #406755, FileId: 0x1600000007b299, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T21:23:26.505 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T21:23:41.425 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T21:24:09.505 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #406940, FileId: 0x1200000007bacb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T21:28:22.720 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 948, Count: 81, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\93d466bc-47fc-466d-9517-0610cc340ce2.tmp, EstimatedImpact: 0%

2025-11-28T21:28:22.720 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 870, Count: 85, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\a4d0344c-ed1a-4f39-9008-41fc9cfacd38.tmp, EstimatedImpact: 0%

2025-11-28T21:28:22.720 ProcessImageName: RuntimeBroker.exe, Pid: 12368, TotalTime: 527, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 29%

2025-11-28T21:28:22.720 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 285, Count: 56, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-28T21:28:22.720 ProcessImageName: taskhostw.exe, Pid: 3952, TotalTime: 225, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-28T21:28:22.720 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 28512, TotalTime: 135, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 2%

2025-11-28T21:28:22.720 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 120, Count: 56, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\532001fc78e4e796.customDestinations-ms, EstimatedImpact: 0%

2025-11-28T21:28:22.720 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 105, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-11-28T21:28:22.720 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 77, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-28T21:28:22.720 ProcessImageName: GameBar.exe, Pid: 19136, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_7.325.11061.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1822317515-1041744019-1682422708-1001-MergedResources-34.pri, EstimatedImpact: 9%

2025-11-28T21:28:22.720 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T21:28:22.720 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T21:28:22.720 ProcessImageName: svchost.exe, Pid: 8188, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT31EF.tmp, EstimatedImpact: 0%

2025-11-28T21:28:22.720 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-28T21:28:22.720 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-28T21:28:22.720 ProcessImageName: RuntimeBroker.exe, Pid: 29092, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\BackgroundTransferApi\2ce82ac5-238e-4e56-b2d7-5aa5d8938522.down_data, EstimatedImpact: 3%

2025-11-28T21:28:22.720 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\401d44483c00cbf832531ee06b1ff1d7f8a5c686.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-28T21:28:22.720 ProcessImageName: StoreDesktopExtension.exe, Pid: 15208, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-28T21:28:22.720 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--kglcheck-.lnk, EstimatedImpact: 12%

2025-11-28T21:28:22.720 ProcessImageName: updater.exe, Pid: 4012, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-28T21:38:46.429 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T21:39:10.339 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #407103, FileId: 0x1800000007bcde, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T21:52:06.113 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #407287, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T21:52:06.117 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #407288, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T21:52:16.115 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #407297, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T21:52:16.118 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #407298, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T21:53:51.418 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T21:54:11.103 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #407304, FileId: 0x14000000009ecb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T22:08:56.419 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T22:09:11.647 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #407447, FileId: 0xd00000007bd9b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T22:24:01.406 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T22:24:12.228 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #407718, FileId: 0xe00000007be04, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T22:39:06.403 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T22:39:12.718 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #408419, FileId: 0x1000000007be8e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T22:52:06.572 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #408535, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T22:52:06.576 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #408536, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T22:52:16.585 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #408542, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T22:52:16.589 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #408543, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T22:54:11.409 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T22:54:13.363 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #408548, FileId: 0x154000000003645, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T23:09:14.034 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #408735, FileId: 0x1af000000003f89, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T23:09:16.409 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T23:23:28.551 Bm signature throttled:0x0000fab3228bcd4d

2025-11-28T23:24:14.250 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #409011, FileId: 0x1f7000000006231, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T23:24:21.402 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T23:28:22.698 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1725, Count: 172, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\a4d0344c-ed1a-4f39-9008-41fc9cfacd38.tmp, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1623, Count: 133, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\93d466bc-47fc-466d-9517-0610cc340ce2.tmp, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1519, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 88%

2025-11-28T23:28:22.698 ProcessImageName: RuntimeBroker.exe, Pid: 12368, TotalTime: 527, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 29%

2025-11-28T23:28:22.698 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 300, Count: 58, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: taskhostw.exe, Pid: 3952, TotalTime: 225, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-28T23:28:22.698 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 135, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 28512, TotalTime: 135, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 2%

2025-11-28T23:28:22.698 ProcessImageName: backgroundTaskHost.exe, Pid: 14024, TotalTime: 135, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446, EstimatedImpact: 39%

2025-11-28T23:28:22.698 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 120, Count: 57, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\532001fc78e4e796.customDestinations-ms, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 120, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 77, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: GameBar.exe, Pid: 19136, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_7.325.11061.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1822317515-1041744019-1682422708-1001-MergedResources-34.pri, EstimatedImpact: 9%

2025-11-28T23:28:22.698 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: svchost.exe, Pid: 8188, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT31EF.tmp, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: RuntimeBroker.exe, Pid: 29092, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\BackgroundTransferApi\2ce82ac5-238e-4e56-b2d7-5aa5d8938522.down_data, EstimatedImpact: 3%

2025-11-28T23:28:22.698 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\401d44483c00cbf832531ee06b1ff1d7f8a5c686.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-28T23:28:22.698 ProcessImageName: StoreDesktopExtension.exe, Pid: 15208, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-28T23:28:22.698 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--kglcheck-.lnk, EstimatedImpact: 12%

2025-11-28T23:28:22.698 ProcessImageName: updater.exe, Pid: 4012, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-28T23:39:14.520 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #409098, FileId: 0x17100000000865d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T23:39:26.400 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-28T23:52:05.550 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #409253, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T23:52:05.554 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #409254, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T23:52:15.563 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #409261, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T23:52:15.566 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #409262, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T23:52:15.567 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #409263, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T23:54:15.169 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #409268, FileId: 0xa6000000008bcf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-28T23:54:31.389 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T00:09:15.777 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #409513, FileId: 0x7f000000008eb2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T00:09:36.384 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T00:17:06.380 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3

2025-11-29T00:17:06.380 Job Notification: New process added to job (29380)

2025-11-29T00:17:06.383 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched

2025-11-29T00:17:06.384 Aggressive catchup quick scan threshold: 3406411200643 / 25920000000000

2025-11-29T00:17:06.386 Job Notification: New process added to job (28952)

2025-11-29T00:17:06.393 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:29380] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:28952]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-29T00:17:06.436 Job Notification: New process added to job (18868)

2025-11-29T00:17:06.438 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched

2025-11-29T00:17:06.440 Job Notification: New process added to job (26000)

2025-11-29T00:17:06.447 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:18868] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:26000]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-29T00:17:06.467 Job Notification: New process added to job (27864)

2025-11-29T00:17:06.469 Task(GetDeviceTicket -AccessKey A67599E9-F844-0AA0-AA8E-966E4FA62CF3 ) launched as network service

2025-11-29T00:17:06.898 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-29T00:17:06.898 [RTP] Duplicating the current plugin configuration object...

2025-11-29T00:17:06.898 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-29T00:17:06.898 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-29T00:17:06.898 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-29T00:17:06.898 [RTP] No config change detected. Not updating plugin configuration.

2025-11-29T00:17:06.898 [RTP] No config changes found. No configuration switch.

2025-11-29T00:17:06.898 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-29T00:17:06.920 Job Notification: Process exited from job (27864)

2025-11-29T00:17:07.118 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-29T00:17:07.118 [Cloud] Start of cloud request. Passive mode: 0

2025-11-29T00:17:07.118 [Cloud] Queued cloud request.

2025-11-29T00:17:07.118 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-29T00:17:07.118 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0

2025-11-29T00:17:07.118 [Cloud] Start of cloud request. Passive mode: 0

2025-11-29T00:17:07.118 [Cloud] Queued cloud request.

2025-11-29T00:17:07.118 [Cloud] Dequeued cloud request.

2025-11-29T00:17:07.118 [Cloud] Dequeued cloud request.

2025-11-29T00:17:07.118 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-29T00:17:07.119 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-29T00:17:07.198 [Cloud] End of cloud request.

2025-11-29T00:17:07.246 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-29T00:17:07.247 [Cloud] End of cloud request.

2025-11-29T00:17:07.625 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T00:17:16.753 Job Notification: Process exited from job (18868)

2025-11-29T00:17:16.754 Job Notification: Process exited from job (26000)

2025-11-29T00:17:16.787 Job Notification: Process exited from job (29380)

2025-11-29T00:17:16.788 Job Notification: Process exited from job (28952)

2025-11-29T00:24:16.389 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #409853, FileId: 0x2a00000000a091, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T00:24:41.383 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T00:39:16.855 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #410025, FileId: 0x1000000007c04b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T00:39:46.384 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T00:52:06.706 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #410132, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T00:52:06.708 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #410133, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T00:52:16.706 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #410138, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T00:52:16.709 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #410139, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T00:52:16.721 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #410140, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T00:52:16.725 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #410141, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T00:54:17.134 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #410147, FileId: 0x1b600000000a9a5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T00:54:51.371 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)



BEGIN BM telemetry

GUID:{C5B8A789-94C4-0D2C-78BA-73D8098B6826}

SignatureID:340520518878414

SigSha:e1735ced290d41223a12e50689d7c8ade6f705e0

ThreatLevel:0

ProcessID:26680

ProcessCreationTime:134082425297793485

SessionID:1

CreationTime:11-29-2025 01:05:35

ImagePath:C:\xampp\apache\bin\httpd.exe

Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: 

Operations:None

END BM telemetry



2025-11-29T01:05:36.197 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-29T01:05:36.197 [Cloud] Start of cloud request. Passive mode: 0

2025-11-29T01:05:36.197 [Cloud] Queued cloud request.

2025-11-29T01:05:36.197 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-29T01:05:36.197 [Cloud] Dequeued cloud request.

2025-11-29T01:05:36.197 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-29T01:05:46.287 [Cloud] End of cloud request.

2025-11-29T01:05:46.807 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

Internal signature match:subtype=Lowfi, sigseq=0x00003DE76FD743A5, sigsha=a3f6370dcaa32529126db6cd838b3997e8094849, cached=false, source=5, resourceid=0xcd6d50fa

Internal signature match:subtype=Lowfi, sigseq=0x00004BE750F81766, sigsha=5655fecec92898faa1b7f001a9000f125061a5d7, cached=false, source=5, resourceid=0xcd6d50fa

Internal signature match:subtype=Lowfi, sigseq=0x000036E75B8ED7A4, sigsha=2016f0f8c3abcfaee96874d0863d38c2b8b3ab16, cached=false, source=5, resourceid=0xcd6d50fa

2025-11-29T01:06:13.884 FP supression checks:CheckTrusted=true (Sigseq=0x45e7d3838ef4), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0)

2025-11-29T01:06:13.888 SDN:Issuing SDN query for \Device\HarddiskVolume4\xampp\tmp\php4AEA.tmp (\Device\HarddiskVolume4\xampp\tmp\php4AEA.tmp) (sha1=c36c9b0e6c7e87ac6b45fdd4a5ddcf88643c62db, sha2=3221a142697e82b93ba0cfbff2e7bdb5f69fee7a24c4aff7eaf82b15123ce269)

2025-11-29T01:06:13.890 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-29T01:06:13.890 [Cloud] Start of cloud request. Passive mode: 0

2025-11-29T01:06:13.890 [Cloud] Queued cloud request.

2025-11-29T01:06:13.890 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-29T01:06:13.890 [Cloud] Dequeued cloud request.

2025-11-29T01:06:13.890 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-29T01:06:13.971 SDN:SDN query completed: 00000000

2025-11-29T01:06:13.971 [Cloud] End of cloud request.

2025-11-29T01:06:13.973 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume4\xampp\tmp\php4AEA.tmp. status=0x8070022, statusex=0x200002, threatid=0x80073b1d, sigseq=0x45e7d3838ef4

2025-11-29T01:06:13.975 [RTP] [Mini-filter] Blocked file(#54): \Device\HarddiskVolume4\xampp\tmp\php4AEA.tmp. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0x0, State: 16, ScanRequest #410280, FileId: 0x1a00000007c0ef, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0



BEGIN BM telemetry

GUID:{DC24C1F1-9E06-8EB2-66CC-893C17FDDB8E}

SignatureID:120615708262628

SigSha:e885968f9a24daa58050ac5509c0821faae78591

ThreatLevel:0

ProcessID:26680

ProcessCreationTime:134082425297793485

SessionID:1

CreationTime:11-29-2025 01:06:13

ImagePath:C:\xampp\apache\bin\httpd.exe

Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: 

Operations:None

END BM telemetry



Internal signature match:subtype=Lowfi, sigseq=0x00003DE76FD743A5, sigsha=a3f6370dcaa32529126db6cd838b3997e8094849, cached=false, source=0, resourceid=0x6ddc87be

Internal signature match:subtype=Lowfi, sigseq=0x00004BE750F81766, sigsha=5655fecec92898faa1b7f001a9000f125061a5d7, cached=false, source=0, resourceid=0x6ddc87be

Internal signature match:subtype=Lowfi, sigseq=0x000036E75B8ED7A4, sigsha=2016f0f8c3abcfaee96874d0863d38c2b8b3ab16, cached=false, source=0, resourceid=0x6ddc87be

2025-11-29T01:06:13.989 FP supression checks:CheckTrusted=true (Sigseq=0x45e7d3838ef4), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0)

Begin Resource Scan

Scan ID:{B4F37E30-C4E7-45C7-99D6-D5D617090909}

Scan Source:3

Start Time:11-29-2025 01:06:13

End Time:11-29-2025 01:06:13

Explicit resource to scan

Resource Schema:file

Resource Path:C:\xampp\tmp\php4AEA.tmp

Result Count:1

Threat Name:Backdoor:PHP/AlfaWebShell.GP!MSR

ID:2147957533

Severity:5

Number of Resources:1

Resource Schema:file

Resource Path:C:\xampp\tmp\php4AEA.tmp

Extended Info - SigSeq:000045e7d3838ef4

Extended Info - SigSha:78ebda22df5f8b865012355e278f82605a7c598d

End Scan

************************************************************



2025-11-29T01:06:13.995 Using action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action for threat (id - 0x80073b1d, sev - 5, category - 6). hr = 0x80070002

2025-11-29T01:06:13.996 Using action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action for threat (id - 0x80073b1d, sev - 5, category - 6). hr = 0x80070002

2025-11-29T01:06:13.999 DETECTIONEVENT MPSOURCE_REALTIME Backdoor:PHP/AlfaWebShell.GP!MSR file:C:\xampp\tmp\php4AEA.tmp;

2025-11-29T01:06:14.001 DETECTION_ADD#1 Backdoor:PHP/AlfaWebShell.GP!MSR file:C:\xampp\tmp\php4AEA.tmp PropBag [length: 0, data: (null)]

2025-11-29T01:06:14.001 [RoutineClean] New detection added. Routine cleaning timer scheduled to fire in 4971 milliseconds. 1 detections to be cleaned.

2025-11-29T01:06:14.481 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T01:06:14.495 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-29T01:06:14.495 [Cloud] Start of cloud request. Passive mode: 0

2025-11-29T01:06:14.495 [Cloud] Queued cloud request.

2025-11-29T01:06:14.495 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-29T01:06:14.495 [Cloud] Dequeued cloud request.

2025-11-29T01:06:14.495 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-29T01:06:14.738 [Cloud] End of cloud request.

2025-11-29T01:06:14.744 [Cloud] SubmitReport(CMpBmSpyNetReportContext)

2025-11-29T01:06:14.744 [Cloud] Start of cloud request. Passive mode: 0

2025-11-29T01:06:14.744 [Cloud] Queued cloud request.

2025-11-29T01:06:14.744 [Cloud] Dequeued cloud request.

2025-11-29T01:06:14.744 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-29T01:06:14.795 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-29T01:06:14.795 [Cloud] End of cloud request.

2025-11-29T01:06:15.252 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

Internal signature match:subtype=Lowfi, sigseq=0x00003DE76FD743A5, sigsha=a3f6370dcaa32529126db6cd838b3997e8094849, cached=false, source=5, resourceid=0x047e4f8d

Internal signature match:subtype=Lowfi, sigseq=0x00004BE750F81766, sigsha=5655fecec92898faa1b7f001a9000f125061a5d7, cached=false, source=5, resourceid=0x047e4f8d

Internal signature match:subtype=Lowfi, sigseq=0x000036E75B8ED7A4, sigsha=2016f0f8c3abcfaee96874d0863d38c2b8b3ab16, cached=false, source=5, resourceid=0x047e4f8d

2025-11-29T01:06:17.201 FP supression checks:CheckTrusted=true (Sigseq=0x45e7d3838ef4), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0)

2025-11-29T01:06:17.206 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume4\xampp\tmp\php56F2.tmp. status=0x8070022, statusex=0x200002, threatid=0x80073b1d, sigseq=0x45e7d3838ef4

2025-11-29T01:06:17.208 [RTP] [Mini-filter] Blocked file(#55): \Device\HarddiskVolume4\xampp\tmp\php56F2.tmp. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0x0, State: 16, ScanRequest #410293, FileId: 0x1900000007c0f5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

Internal signature match:subtype=Lowfi, sigseq=0x00003DE76FD743A5, sigsha=a3f6370dcaa32529126db6cd838b3997e8094849, cached=false, source=0, resourceid=0xa4cf98c9

Internal signature match:subtype=Lowfi, sigseq=0x00004BE750F81766, sigsha=5655fecec92898faa1b7f001a9000f125061a5d7, cached=false, source=0, resourceid=0xa4cf98c9

Internal signature match:subtype=Lowfi, sigseq=0x000036E75B8ED7A4, sigsha=2016f0f8c3abcfaee96874d0863d38c2b8b3ab16, cached=false, source=0, resourceid=0xa4cf98c9

2025-11-29T01:06:17.221 FP supression checks:CheckTrusted=true (Sigseq=0x45e7d3838ef4), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0)

Begin Resource Scan

Scan ID:{05EB5908-0948-4304-8BD3-FCC572A2CFD7}

Scan Source:3

Start Time:11-29-2025 01:06:17

End Time:11-29-2025 01:06:17

Explicit resource to scan

Resource Schema:file

Resource Path:C:\xampp\tmp\php56F2.tmp

Result Count:1

Threat Name:Backdoor:PHP/AlfaWebShell.GP!MSR

ID:2147957533

Severity:5

Number of Resources:1

Resource Schema:file

Resource Path:C:\xampp\tmp\php56F2.tmp

Extended Info - SigSeq:000045e7d3838ef4

Extended Info - SigSha:78ebda22df5f8b865012355e278f82605a7c598d

End Scan

************************************************************



2025-11-29T01:06:17.227 Using action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action for threat (id - 0x80073b1d, sev - 5, category - 6). hr = 0x80070002

2025-11-29T01:06:17.228 Using action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action for threat (id - 0x80073b1d, sev - 5, category - 6). hr = 0x80070002

2025-11-29T01:06:17.228 DETECTION_MERGE#2 Backdoor:PHP/AlfaWebShell.GP!MSR file:C:\xampp\tmp\php56F2.tmp PropBag [length: 0, data: (null)]

2025-11-29T01:06:17.229 DETECTIONEVENT MPSOURCE_REALTIME Backdoor:PHP/AlfaWebShell.GP!MSR file:C:\xampp\tmp\php4AEA.tmp;file:C:\xampp\tmp\php56F2.tmp;

Internal signature match:subtype=Lowfi, sigseq=0x00003DE76FD743A5, sigsha=a3f6370dcaa32529126db6cd838b3997e8094849, cached=false, source=5, resourceid=0x37a8abb0

Internal signature match:subtype=Lowfi, sigseq=0x00004BE750F81766, sigsha=5655fecec92898faa1b7f001a9000f125061a5d7, cached=false, source=5, resourceid=0x37a8abb0

Internal signature match:subtype=Lowfi, sigseq=0x000036E75B8ED7A4, sigsha=2016f0f8c3abcfaee96874d0863d38c2b8b3ab16, cached=false, source=5, resourceid=0x37a8abb0

2025-11-29T01:06:18.417 FP supression checks:CheckTrusted=true (Sigseq=0x45e7d3838ef4), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0)

2025-11-29T01:06:18.422 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume4\xampp\tmp\php60F5.tmp. status=0x8070022, statusex=0x200002, threatid=0x80073b1d, sigseq=0x45e7d3838ef4

2025-11-29T01:06:18.431 [RTP] [Mini-filter] Blocked file(#56): \Device\HarddiskVolume4\xampp\tmp\php60F5.tmp. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0x0, State: 16, ScanRequest #410297, FileId: 0x1a00000007c0f5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

Internal signature match:subtype=Lowfi, sigseq=0x00003DE76FD743A5, sigsha=a3f6370dcaa32529126db6cd838b3997e8094849, cached=false, source=0, resourceid=0x97197cf4

Internal signature match:subtype=Lowfi, sigseq=0x00004BE750F81766, sigsha=5655fecec92898faa1b7f001a9000f125061a5d7, cached=false, source=0, resourceid=0x97197cf4

Internal signature match:subtype=Lowfi, sigseq=0x000036E75B8ED7A4, sigsha=2016f0f8c3abcfaee96874d0863d38c2b8b3ab16, cached=false, source=0, resourceid=0x97197cf4

2025-11-29T01:06:18.443 FP supression checks:CheckTrusted=true (Sigseq=0x45e7d3838ef4), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0)

Begin Resource Scan

Scan ID:{C844DE36-9E75-48A5-A4FA-EC390A7629BA}

Scan Source:3

Start Time:11-29-2025 01:06:18

End Time:11-29-2025 01:06:18

Explicit resource to scan

Resource Schema:file

Resource Path:C:\xampp\tmp\php60F5.tmp

Result Count:1

Threat Name:Backdoor:PHP/AlfaWebShell.GP!MSR

ID:2147957533

Severity:5

Number of Resources:1

Resource Schema:file

Resource Path:C:\xampp\tmp\php60F5.tmp

Extended Info - SigSeq:000045e7d3838ef4

Extended Info - SigSha:78ebda22df5f8b865012355e278f82605a7c598d

End Scan

************************************************************



2025-11-29T01:06:18.449 Using action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action for threat (id - 0x80073b1d, sev - 5, category - 6). hr = 0x80070002

2025-11-29T01:06:18.450 Using action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action for threat (id - 0x80073b1d, sev - 5, category - 6). hr = 0x80070002

2025-11-29T01:06:18.450 DETECTION_MERGE#3 Backdoor:PHP/AlfaWebShell.GP!MSR file:C:\xampp\tmp\php60F5.tmp PropBag [length: 0, data: (null)]

2025-11-29T01:06:18.451 DETECTIONEVENT MPSOURCE_REALTIME Backdoor:PHP/AlfaWebShell.GP!MSR file:C:\xampp\tmp\php4AEA.tmp;file:C:\xampp\tmp\php56F2.tmp;file:C:\xampp\tmp\php60F5.tmp;

2025-11-29T01:06:18.976 [RoutineClean] Routine cleaning timer rescheduled to fire in 4474 milliseconds. 1 detections remaining to be cleaned.

Internal signature match:subtype=Lowfi, sigseq=0x00003DE76FD743A5, sigsha=a3f6370dcaa32529126db6cd838b3997e8094849, cached=false, source=5, resourceid=0x0a5469e0

Internal signature match:subtype=Lowfi, sigseq=0x00004BE750F81766, sigsha=5655fecec92898faa1b7f001a9000f125061a5d7, cached=false, source=5, resourceid=0x0a5469e0

Internal signature match:subtype=Lowfi, sigseq=0x000036E75B8ED7A4, sigsha=2016f0f8c3abcfaee96874d0863d38c2b8b3ab16, cached=false, source=5, resourceid=0x0a5469e0

2025-11-29T01:06:20.099 FP supression checks:CheckTrusted=true (Sigseq=0x45e7d3838ef4), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0)

2025-11-29T01:06:20.104 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume4\xampp\tmp\php67DC.tmp. status=0x8070022, statusex=0x200002, threatid=0x80073b1d, sigseq=0x45e7d3838ef4

2025-11-29T01:06:20.107 [RTP] [Mini-filter] Blocked file(#57): \Device\HarddiskVolume4\xampp\tmp\php67DC.tmp. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0x0, State: 16, ScanRequest #410304, FileId: 0x1b00000007c0f5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

Internal signature match:subtype=Lowfi, sigseq=0x00003DE76FD743A5, sigsha=a3f6370dcaa32529126db6cd838b3997e8094849, cached=false, source=0, resourceid=0xaae5bea4

Internal signature match:subtype=Lowfi, sigseq=0x00004BE750F81766, sigsha=5655fecec92898faa1b7f001a9000f125061a5d7, cached=false, source=0, resourceid=0xaae5bea4

Internal signature match:subtype=Lowfi, sigseq=0x000036E75B8ED7A4, sigsha=2016f0f8c3abcfaee96874d0863d38c2b8b3ab16, cached=false, source=0, resourceid=0xaae5bea4

2025-11-29T01:06:20.121 FP supression checks:CheckTrusted=true (Sigseq=0x45e7d3838ef4), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0)

Begin Resource Scan

Scan ID:{BBA5F58F-6989-47AB-8A53-D5EFBB407875}

Scan Source:3

Start Time:11-29-2025 01:06:20

End Time:11-29-2025 01:06:20

Explicit resource to scan

Resource Schema:file

Resource Path:C:\xampp\tmp\php67DC.tmp

Result Count:1

Threat Name:Backdoor:PHP/AlfaWebShell.GP!MSR

ID:2147957533

Severity:5

Number of Resources:1

Resource Schema:file

Resource Path:C:\xampp\tmp\php67DC.tmp

Extended Info - SigSeq:000045e7d3838ef4

Extended Info - SigSha:78ebda22df5f8b865012355e278f82605a7c598d

End Scan

************************************************************



2025-11-29T01:06:20.127 Using action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action for threat (id - 0x80073b1d, sev - 5, category - 6). hr = 0x80070002

2025-11-29T01:06:20.127 Using action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action for threat (id - 0x80073b1d, sev - 5, category - 6). hr = 0x80070002

2025-11-29T01:06:20.128 DETECTION_MERGE#4 Backdoor:PHP/AlfaWebShell.GP!MSR file:C:\xampp\tmp\php67DC.tmp PropBag [length: 0, data: (null)]

2025-11-29T01:06:20.128 DETECTIONEVENT MPSOURCE_REALTIME Backdoor:PHP/AlfaWebShell.GP!MSR file:C:\xampp\tmp\php4AEA.tmp;file:C:\xampp\tmp\php56F2.tmp;file:C:\xampp\tmp\php60F5.tmp;file:C:\xampp\tmp\php67DC.tmp;

2025-11-29T01:06:23.463 [RoutineClean] Routine cleaning timer rescheduled to fire in 1664 milliseconds. 1 detections remaining to be cleaned.

2025-11-29T01:06:25.138 [RoutineClean] Cleaning 1 detections

2025-11-29T01:06:25.143 Using action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action for threat (id - 0x80073b1d, sev - 5, category - 6). hr = 0x80070002

2025-11-29T01:06:25.143 Using action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action for threat (id - 0x80073b1d, sev - 5, category - 6). hr = 0x80070002

2025-11-29T01:06:25.156 [Cloud] SubmitReport(CMpSpyNetReportContext - clean error)

2025-11-29T01:06:25.156 [Cloud] Start of cloud request. Passive mode: 0

2025-11-29T01:06:25.156 [Cloud] Queued cloud request.

2025-11-29T01:06:25.156 [Cloud] Dequeued cloud request.

2025-11-29T01:06:25.156 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0x80508033 Backdoor:PHP/AlfaWebShell.GP!MSR file:C:\xampp\tmp\php4AEA.tmp;file:C:\xampp\tmp\php56F2.tmp;file:C:\xampp\tmp\php60F5.tmp;file:C:\xampp\tmp\php67DC.tmp;

2025-11-29T01:06:25.157 [Remediation] Threat file no longer exists. Marking remediation as success.

2025-11-29T01:06:25.157 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-29T01:06:25.158 [RoutineClean] Routine cleaning completed successfully on 1 detections.

2025-11-29T01:06:25.176 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-29T01:06:25.177 [Cloud] End of cloud request.

2025-11-29T01:06:25.698 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T01:06:27.160 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-29T01:06:27.163 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-29T01:06:27.164 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-29T01:06:29.179 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-29T01:06:29.182 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-29T01:06:29.182 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-29T01:09:17.476 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #410367, FileId: 0x66000000003f4c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T01:09:56.369 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T01:23:30.509 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T01:24:18.173 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #410597, FileId: 0xf00000007c182, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T01:25:01.373 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T01:28:22.667 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2550, Count: 258, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\a4d0344c-ed1a-4f39-9008-41fc9cfacd38.tmp, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2238, Count: 185, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\93d466bc-47fc-466d-9517-0610cc340ce2.tmp, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1519, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 88%

2025-11-29T01:28:22.667 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 739, Count: 139, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: RuntimeBroker.exe, Pid: 12368, TotalTime: 527, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 29%

2025-11-29T01:28:22.667 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 300, Count: 58, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 225, Count: 74, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\532001fc78e4e796.customDestinations-ms, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: taskhostw.exe, Pid: 3952, TotalTime: 225, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-29T01:28:22.667 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 210, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 195, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 165, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 28512, TotalTime: 135, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 2%

2025-11-29T01:28:22.667 ProcessImageName: backgroundTaskHost.exe, Pid: 14024, TotalTime: 135, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446, EstimatedImpact: 39%

2025-11-29T01:28:22.667 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 105, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: GameBar.exe, Pid: 19136, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_7.325.11061.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1822317515-1041744019-1682422708-1001-MergedResources-34.pri, EstimatedImpact: 9%

2025-11-29T01:28:22.667 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: svchost.exe, Pid: 8188, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT31EF.tmp, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\4e4cdc87-91f2-4632-b55d-4d80e1452be6.tmp, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: taskhostw.exe, Pid: 24776, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-29T01:28:22.667 ProcessImageName: RuntimeBroker.exe, Pid: 29092, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\BackgroundTransferApi\2ce82ac5-238e-4e56-b2d7-5aa5d8938522.down_data, EstimatedImpact: 3%

2025-11-29T01:28:22.667 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\logs\embyserver.txt, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: updater.exe, Pid: 22952, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ac158554-aa0e-45cd-82a6-e07ff7caabce.tmp, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: StoreDesktopExtension.exe, Pid: 15208, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\401d44483c00cbf832531ee06b1ff1d7f8a5c686.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-29T01:28:22.667 ProcessImageName: taskhostw.exe, Pid: 15860, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 3%

2025-11-29T01:28:22.667 ProcessImageName: updater.exe, Pid: 4012, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-29T01:28:22.667 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--kglcheck-.lnk, EstimatedImpact: 12%

2025-11-29T01:39:19.196 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #410699, FileId: 0x4e000000028d27, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T01:39:46.464 [AutoPurge] Verification Routine tasks have started.

2025-11-29T01:39:46.464 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-29T01:39:46.472 [AutoPurge] Routine task for Cache Maintenance has started.

2025-11-29T01:39:46.472 [AutoPurge] Routine task for Cache Maintenance ...

2025-11-29T01:39:46.472 [AutoPurge] Routine task for MpSFCBuild ...

2025-11-29T01:39:46.472 [AutoPurge] MpCmIsBuildCompleted() - S_OK

2025-11-29T01:39:46.472 [AutoPurge] MpSignalMaintenanceMode ...

2025-11-29T01:39:46.474 [AutoPurge] Cleanup Routine tasks have started.

2025-11-29T01:39:46.477 Detection State: Finished(1) Failed(0) CriticalFailed(0) Additional Actions(0)

2025-11-29T01:39:46.477 [AutoPurge] Purged 0 expired detection item(s) from a total of 1.

2025-11-29T01:39:46.477 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 4, expiration in 86400 seconds)

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:65538

Start time:11-29-2025 01:39:46

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-29-2025 01:39:46

2025-11-29T01:39:46.479 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ...

2025-11-29T01:39:46.479 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0 ...

2025-11-29T01:39:46.479 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0 ...

2025-11-29T01:39:46.479 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ...

2025-11-29T01:39:46.480 [AutoPurge] Cleanup Routine tasks have ended.

2025-11-29T01:39:46.480 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:86D0DB9A-65D4-4E92-ADB6-B2B46812C8CC, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1)

2025-11-29T01:39:46.480 Scheduled scan with Id 86D0DB9A-65D4-4E92-ADB6-B2B46812C8CC configured CPU priority: normal (LowCpuPriority: 0)

2025-11-29T01:39:46.481 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build.

2025-11-29T01:39:46.481 [SFC] System file cache build is not needed (already completed)

2025-11-29T01:39:46.481 QuickScan:ScanID:86D0DB9A-65D4-4E92-ADB6-B2B46812C8CC: Quick Scan skipped since it already ran during the past 7 days

2025-11-29T01:39:46.481 QuickScan:ScanID:86D0DB9A-65D4-4E92-ADB6-B2B46812C8CC: Quick scan finished with error 1223

2025-11-29T01:39:46.481 OnDemandScanWorker: Scan Cancelled! scanId:86D0DB9A-65D4-4E92-ADB6-B2B46812C8CC, hr = 0x80508018

!ERROR

Begin Quick Scan

Scan ID:{86D0DB9A-65D4-4E92-ADB6-B2B46812C8CC}

Scan Source:1

Start Time:11-29-2025 01:39:46

Unsuccessful Scan

Return Code:1223

************************************************************



2025-11-29T01:39:46.532 EnsureProtectedFolderAcls(), hr = 0x0

2025-11-29T01:39:46.534 [AutoPurge] MpReinforceServiceAcls: 0

2025-11-29T01:39:46.545 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0

2025-11-29T01:39:46.546 Engine:Setting original file name "WIARPC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiarpc.dll.mui_0c913b87", hr=0x0

2025-11-29T01:39:46.548 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed.

2025-11-29T01:39:46.549 [AutoPurge] Verification Routine tasks have ended.

2025-11-29T01:39:46.578 Engine:Setting original file name "nlsbres.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..ocale-nls.resources_31bf3856ad364e35_10.0.26100.4484_nb-no_339b02f7f61c146e\winnlsres.dll.mui", hr=0x0

2025-11-29T01:39:46.936 Engine:Setting original file name "IEXPLORE.EXE" for "c:\program files (x86)\internet explorer\en-us\iexplore.exe.mui", hr=0x0

2025-11-29T01:39:46.966 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_en-us_1258b52c940aadb7_winload.efi.mui_35ee487d", hr=0x0

2025-11-29T01:39:47.498 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sr-..-rs_d1943ecc8317ab66_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-29T01:39:47.655 Engine:Setting original file name " " for "c:\program files (x86)\steam\bin\cef\cef.win7x64\dxcompiler.dll", hr=0x0

2025-11-29T01:39:47.703 Engine:Setting original file name "dual_engine_adapter.dll" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\dual_engine_adapter_x64.dll", hr=0x0

2025-11-29T01:39:47.865 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\winsxs\wow64_microsoft-windows-bcp47languages_31bf3856ad364e35_10.0.26100.7019_none_40ac55a9bb1ab239\bcp47langs.dll", hr=0x0

2025-11-29T01:39:47.880 Engine:Setting original file name "MAPI32.DLL.MUI" for "c:\windows\system32\nb-no\mapistub.dll.mui", hr=0x0

2025-11-29T01:39:48.061 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-29T01:39:48.102 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_ar-sa_af75f4ef024a79a1_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-29T01:39:48.181 Engine:Setting original file name "Apphelp" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a4bb088d5aa4193f97a4bdef0c1f8c71\apphelp.dll.mui", hr=0x0

2025-11-29T01:39:48.237 Engine:Setting original file name "F12Chooser.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-ie-iechooser.resources_31bf3856ad364e35_11.0.26100.1_nb-no_a7630c027f26ac69\iechooser.exe.mui", hr=0x0

2025-11-29T01:39:48.278 Engine:Setting original file name "THEMESERVICE.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-themeservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_5e5bf64d5b3ca824_themeservice.dll.mui_9e71f1ab", hr=0x0

2025-11-29T01:39:48.313 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_ad141a64b8fd6038_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:48.407 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\wow64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.26100.712_none_5cfec91758ee0662\windows.security.credentials.ui.credentialpicker.dll", hr=0x0

2025-11-29T01:39:48.468 Engine:Setting original file name "mavinject32.exe" for "c:\windows\winsxs\wow64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_592d553ad6e77100\mavinject.exe", hr=0x0

2025-11-29T01:39:48.491 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-29T01:39:48.494 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-29T01:39:48.495 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-29T01:39:48.603 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_bfcde09794ad7074_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-29T01:39:48.612 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\zh-cn\memtest.efi.mui", hr=0x0

2025-11-29T01:39:48.753 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_nb-no_022ea2e874b2cab6_winresume.efi.mui_f412814e", hr=0x0

2025-11-29T01:39:48.824 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lt-lt_11cd7cc1c62eb609_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:49.130 Engine:Setting original file name "WmiApSrv.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiapsrv.exe.mui_b1567840", hr=0x0

2025-11-29T01:39:49.195 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kk-kz_bb9a512b689c9b87_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:49.223 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_b5793645604cae79_memtest.efi.mui_71e15c22", hr=0x0

2025-11-29T01:39:49.240 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_he-il_3abd6f82e93c03e5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:49.249 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.26100.1_en-us_c3d82ef5c0380efa_wudfpf.sys.mui_f61e9e86", hr=0x0

2025-11-29T01:39:49.518 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaihdrx.dll", hr=0x0

2025-11-29T01:39:49.687 Engine:Setting original file name "l3codec.acm.mui" for "c:\windows\system32\nb-no\l3codeca.acm.mui", hr=0x0

2025-11-29T01:39:49.801 Engine:Setting original file name "w32topl.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_10.0.26100.1_none_cbd0eec659c2eb5c_w32topl.dll_1a0f388b", hr=0x0

2025-11-29T01:39:49.816 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ms-my_6f80e6fda2cebe8f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:50.108 Engine:Setting original file name "NVPTXJITCOMPILER32.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvptxjitcompiler64.dll", hr=0x0

2025-11-29T01:39:50.153 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5de87d4a39ffc584310f0b06dff9fcd0\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-29T01:39:50.242 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_38f499759ea365c4_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:50.303 Engine:Setting original file name "ddputils.lib.mui" for "c:\windows\system32\nb-no\ddputils.dll.mui", hr=0x0

2025-11-29T01:39:50.438 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kn-in_6e7a81f857a45cbe_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:50.478 Engine:Setting original file name "officeimm.odf" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\office.odf", hr=0x0

2025-11-29T01:39:50.503 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-29T01:39:50.507 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-29T01:39:50.508 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-29T01:39:50.709 Engine:Setting original file name ""AcGenral.dll"" for "c:\windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_10.0.26100.7019_none_a8119654a230db44\acgenral.dll", hr=0x0

2025-11-29T01:39:50.800 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sr-..-rs_7327597d7718c882_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:50.818 Engine:Setting original file name "Hyper-V Host Compute Service Diagnostics Tool" for "c:\windows\winsxs\amd64_hyperv-compute-cont..sticstool.resources_31bf3856ad364e35_10.0.26100.1_en-us_61074b8c7d2f38cf\hcsdiag.exe.mui", hr=0x0

2025-11-29T01:39:50.835 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.32530.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-29T01:39:50.881 Engine:Setting original file name "davsvc.dll.mui" for "c:\windows\system32\nb-no\webclnt.dll.mui", hr=0x0

2025-11-29T01:39:50.913 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\nb-no\wsepno.dll.mui", hr=0x0

2025-11-29T01:39:50.928 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x0

2025-11-29T01:39:50.967 Engine:Setting original file name "bootstr.exe.mui" for "c:\windows\system32\nb-no\bootstr.dll.mui", hr=0x0

2025-11-29T01:39:50.986 Engine:Setting original file name "msvcp140_2_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_2_app.dll", hr=0x0

2025-11-29T01:39:51.244 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-libraryloader-l1-1-0.dll", hr=0x0

2025-11-29T01:39:51.251 Engine:Setting original file name "dvsvc.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..rationsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_5c873aff49ea76e6\dcsvc.dll.mui", hr=0x0

2025-11-29T01:39:51.285 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_qps-ploc_5c9773f9ea1ce396_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:51.288 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_cs-cz_7086b4650c9e547c_memtest.efi.mui_71e15c22", hr=0x0

2025-11-29T01:39:51.412 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa78d0db4729269ff4beb393d45ca94a\dnsapi.dll.mui", hr=0x0

2025-11-29T01:39:51.432 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hr-hr_86baa9ad7eed6d52_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:51.480 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ja-jp_ed01f249e53f7235_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-29T01:39:51.485 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-file-l1-1-0.dll", hr=0x0

2025-11-29T01:39:51.520 Engine:Setting original file name "D3DX10.dll" for "c:\windows\system32\d3dx10_43.dll", hr=0x0

2025-11-29T01:39:51.606 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_da-dk_f5abc0a0339bc397_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:51.844 Engine:Setting original file name "Auto Enrollment DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..utoenroll.resources_31bf3856ad364e35_10.0.26100.1_en-us_b82b35a9c2228d6b\pautoenr.dll.mui", hr=0x0

2025-11-29T01:39:51.942 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\windows\winsxs\amd64_microsoft-textinput-helpers.resources_31bf3856ad364e35_10.0.26100.1_nb-no_2c9a52bac4b766e3\ime_textinputhelpers.dll.mui", hr=0x0

2025-11-29T01:39:51.958 Engine:Setting original file name "Ribbons" for "c:\windows\winsxs\amd64_microsoft-windows-ribbons.resources_31bf3856ad364e35_10.0.26100.1_en-us_f85e1124efc279b5\ribbons.scr.mui", hr=0x0

2025-11-29T01:39:52.008 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_18153ede37451276\memtest.exe.mui", hr=0x0

2025-11-29T01:39:52.058 Engine:Setting original file name "scecli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\978b70ff94ed14c641fe52c5237facec\scecli.dll.mui", hr=0x0

2025-11-29T01:39:52.082 Engine:Setting original file name "mpsdrv.sys.mui" for "c:\windows\winsxs\backup\amd64_networking-mpssvc-drv.resources_31bf3856ad364e35_10.0.26100.1_nb-no_05849dc2762f9d2d_mpsdrv.sys.mui_b2aea3b6", hr=0x0

2025-11-29T01:39:52.106 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-tw_21b451d70c8c2957_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-29T01:39:52.281 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_2b309b875a6f3e1e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:52.359 Engine:Setting original file name "Vulkan Runtime" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\vulkan-1.dll", hr=0x0

2025-11-29T01:39:52.404 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-p..i-ntprint.resources_31bf3856ad364e35_10.0.26100.1_en-us_6ff199c21e8ad886\ntprint.dll.mui", hr=0x0

2025-11-29T01:39:52.474 Engine:Setting original file name "bootstr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..environment-strings_31bf3856ad364e35_10.0.26100.1_none_f575b80d757af501\bootstr.dll", hr=0x0

2025-11-29T01:39:52.505 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_zh-cn_fd81e6b68df3d1a9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:52.692 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-29T01:39:52.823 Engine:Setting original file name "liblzma.dll" for "c:\program files\windowsapps\microsoft.6365217ce6eb4_102.2509.19002.0_x64__8wekyb3d8bbwe\lzma.dll", hr=0x0

2025-11-29T01:39:52.937 Engine:Setting original file name "wuapi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\uus\x86\nb-no\c120e79170c204b0e5f1ece795e86e83\wuapicore.dll.mui", hr=0x0

2025-11-29T01:39:53.014 Engine:Setting original file name "Ontology.dll" for "c:\users\serverpc\appdata\local\nvidia corporation\nvidia app\nvbackend\applicationontology\ontology64.dll", hr=0x0

2025-11-29T01:39:53.165 Engine:Setting original file name "VpnSohDesktop.dll" for "c:\windows\system32\windows.perception.stub.dll", hr=0x0

2025-11-29T01:39:53.256 Engine:Setting original file name "kernel32" for "c:\windows\syswow64\kernel32.dll", hr=0x0

2025-11-29T01:39:53.289 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.549981c3f5f10_4.2308.1005.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-29T01:39:53.507 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_b38289243d899c4c_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:53.584 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_82eb3d34cd19fa50_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:53.730 Engine:Setting original file name "Steamclient.dll" for "c:\program files (x86)\steam\steamclient64.dll", hr=0x0

2025-11-29T01:39:53.809 Engine:Setting original file name "VrdUmde.dll" for "c:\windows\winsxs\amd64_gpuvirtualizationumed_31bf3856ad364e35_10.0.26100.1150_none_17421023ba072774\vrdumed.dll", hr=0x0

2025-11-29T01:39:53.824 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.efi.mui", hr=0x0

2025-11-29T01:39:53.940 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25102.64.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x0

2025-11-29T01:39:53.979 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.winmd", hr=0x0

2025-11-29T01:39:54.349 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_lt-lt_ba1ae95b692b9594_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-29T01:39:54.476 Engine:Setting original file name "windows.ui.xaml.resources.win81.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ctui-resourceswin81_31bf3856ad364e35_10.0.26100.1301_none_b7b52abe3d381205_windows.ui.xaml.resources.win81.dll_d426e245", hr=0x0

2025-11-29T01:39:54.617 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-timezone-l1-1-0.dll", hr=0x0

2025-11-29T01:39:54.669 Engine:Setting original file name "jscript9.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\c3275836e276aea69afa458336037853\jscript9legacy.dll.mui", hr=0x0

2025-11-29T01:39:55.009 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x0

2025-11-29T01:39:55.119 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-profile-l1-1-0.dll", hr=0x0

2025-11-29T01:39:55.365 Engine:Setting original file name "Windows.FileExplorer.Common.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\84c8a2171c12d91e854ffb6a27b39453\windows.fileexplorer.common.dll.mui", hr=0x0

2025-11-29T01:39:55.584 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.26100.1_en-us_99a73e6649d69102\ndisimplatcim.dll.mui", hr=0x0

2025-11-29T01:39:55.634 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-29T01:39:55.719 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-localization-l1-2-0.dll", hr=0x0

2025-11-29T01:39:55.792 Engine:Setting original file name "Placeholder.dll" for "c:\windows\winsxs\x86_netfx4-penimc_v0400_b03f5f7f11d50a3a_4.0.15920.102_none_21046749883d249b\penimc_v0400.dll", hr=0x0

2025-11-29T01:39:55.817 Engine:Setting original file name "NvCamera.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\nvcameraallowlisting32.dll", hr=0x0

2025-11-29T01:39:56.095 Engine:Setting original file name ".NET Host Policy -" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\hostpolicy.dll", hr=0x0

2025-11-29T01:39:56.521 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sv-se_cac4b549037c269f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:56.527 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-29T01:39:56.562 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-29T01:39:56.581 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\winsxs\amd64_microsoft-windows-appx-deployment-server_31bf3856ad364e35_10.0.26100.7171_none_fd3893d466902045\applytrustoffline.exe", hr=0x0

2025-11-29T01:39:56.750 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\wow64_microsoft-windows-a..on-logger.resources_31bf3856ad364e35_10.0.26100.1_en-us_a0e09b8ec526451d\aeevts.dll.mui", hr=0x0

2025-11-29T01:39:56.859 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-29T01:39:57.061 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\4f8d3bb436c7\apex_particleschecked_x86.dll", hr=0x0

2025-11-29T01:39:57.151 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_it-it_72537c4985790e22_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:39:57.284 Engine:Setting original file name "EsclWiaDriver.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_esclwiadriver.dll.mui_d4a5b959", hr=0x0

2025-11-29T01:39:57.423 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_da-dk_be356ba870c91e76\msprivs.dll.mui", hr=0x0

2025-11-29T01:39:57.426 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-29T01:39:57.442 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_es-es_bdfd06f72820647a_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-29T01:39:57.561 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pl-pl\msprivs.dll.mui", hr=0x0

2025-11-29T01:39:57.579 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-11-29T01:39:57.602 Engine:Setting original file name "rmactivate.exe.mui" for "c:\windows\syswow64\en-us\rmactivate_isv.exe.mui", hr=0x0

2025-11-29T01:39:57.874 Engine:Setting original file name "apex.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\73be2921551d\apex_turbulencefschecked_x86.dll", hr=0x0

2025-11-29T01:39:57.901 Engine:Setting original file name "ScrCons" for "c:\windows\winsxs\amd64_microsoft-windows-w..consumers.resources_31bf3856ad364e35_10.0.26100.1_en-us_5d0e2df387a86d5d\scrcons.exe.mui", hr=0x0

2025-11-29T01:39:57.910 Engine:Setting original file name "PtpProv" for "c:\windows\winsxs\amd64_microsoft-windows-t..-provider.resources_31bf3856ad364e35_10.0.26100.1_en-us_eec70481b215edf0\ptpprov.dll.mui", hr=0x0

2025-11-29T01:39:57.959 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\resources\themes\aero\nb-no\aerolite.msstyles.mui", hr=0x0

2025-11-29T01:39:58.148 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_cd255b4d1be69fe9_winload.efi.mui_35ee487d", hr=0x0

2025-11-29T01:39:58.185 Engine:Setting original file name "pegi.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_en-us_58f534214187451c\pegi.rs.mui", hr=0x0

2025-11-29T01:39:58.191 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-iexpress.resources_31bf3856ad364e35_11.0.26100.1_en-us_f84c0d683fdc407b\wextract.exe.mui", hr=0x0

2025-11-29T01:39:58.691 Engine:Setting original file name "updater.exe" for "c:\program files (x86)\google\update\googleupdate.exe", hr=0x0

2025-11-29T01:39:58.866 Engine:Setting original file name "ServicingBase.dll" for "c:\windows\system32\servicingcommon.dll", hr=0x0

2025-11-29T01:39:58.894 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.exe.mui", hr=0x0

2025-11-29T01:39:59.101 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\edgewebview\application\142.0.3595.80\vulkan-1.dll", hr=0x0

2025-11-29T01:39:59.154 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_c77eb7b609c47f12\diagpackage.dll.mui", hr=0x0

2025-11-29T01:39:59.288 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\system32\wbem\en-us\netadaptercim.dll.mui", hr=0x0

2025-11-29T01:39:59.315 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\syswow64\nb-no\wextract.exe.mui", hr=0x0

2025-11-29T01:39:59.434 Engine:Setting original file name "NvTelemetry.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvinstallerutil.dll", hr=0x0

2025-11-29T01:39:59.482 Engine:Setting original file name "NvMessageBusBroadcast.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\localsystem\_nvmsgbusbroadcast.dll", hr=0x0

2025-11-29T01:39:59.707 Engine:Setting original file name "NVOPENCL.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvopencl64.dll", hr=0x0

2025-11-29T01:39:59.715 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x0

2025-11-29T01:39:59.795 Engine:Setting original file name "Ribbons" for "c:\windows\system32\nb-no\ribbons.scr.mui", hr=0x0

2025-11-29T01:39:59.975 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_de-de_bb6100e4729f7310\msprivs.dll.mui", hr=0x0

2025-11-29T01:40:00.134 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_en-gb_943f70b729277031_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:00.171 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570\dnsapi.dll.mui", hr=0x0

2025-11-29T01:40:00.174 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x0

2025-11-29T01:40:00.270 Engine:Setting original file name "expediteupdater" for "c:\program files\microsoft update health tools\expediteupdater.exe", hr=0x0

2025-11-29T01:40:00.324 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5fc58c6fab06ca1651cc2f24f6b3294e\dnsapi.dll.mui", hr=0x0

2025-11-29T01:40:00.445 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-29T01:40:00.487 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-29T01:40:00.569 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pt-br\msprivs.dll.mui", hr=0x0

2025-11-29T01:40:00.629 Engine:Setting original file name "vcomp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-11-29T01:40:00.682 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_pt-br_45b1cef334010120_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-29T01:40:00.735 Engine:Setting original file name "DismProvPS.DLL" for "c:\windows\system32\dism\dismcoreps.dll", hr=0x0

2025-11-29T01:40:00.853 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x0

2025-11-29T01:40:00.891 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.efi", hr=0x0

2025-11-29T01:40:00.895 Engine:Setting original file name "ProfSvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-profsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_63afbc426d007f3f_profsvc.dll.mui_32482e9e", hr=0x0

2025-11-29T01:40:01.007 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2cfe4c864d785675f415b7e6aa962e4\msinfo32.exe.mui", hr=0x0

2025-11-29T01:40:01.255 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\6dfad87d7e49db84e1a96c1c1b32fef6\msidntld.dll.mui", hr=0x0

2025-11-29T01:40:01.273 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7\memtest.exe.mui", hr=0x0

2025-11-29T01:40:01.388 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pa-in_9c6b14ad918eaffd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:01.409 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ar-sa_51090f9ff64b96bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:01.458 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.26100.1_en-us_c94c280205b42295\bubbles.scr.mui", hr=0x0

2025-11-29T01:40:01.713 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\nb-no\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x0

2025-11-29T01:40:01.739 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-console-l1-2-0.dll", hr=0x0

2025-11-29T01:40:01.756 Engine:Setting original file name "SETUP.EXE.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-wow64-legacy.resources_31bf3856ad364e35_10.0.26100.1_nb-no_735ab890ce560efa\setup16.exe.mui", hr=0x0

2025-11-29T01:40:01.913 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x0

2025-11-29T01:40:01.947 Engine:Setting original file name "RarExt.dll" for "c:\program files\winrar\rarext32.dll", hr=0x0

2025-11-29T01:40:01.988 Engine:Setting original file name "pcw.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-pcw_31bf3856ad364e35_10.0.26100.1150_none_4bf8e6d5066a4f9f_pcw.sys_dbeb0bbd", hr=0x0

2025-11-29T01:40:02.083 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\syswow64\nb-no\ieadvpack.dll.mui", hr=0x0

2025-11-29T01:40:02.117 Engine:Setting original file name "EmbyServer.dll" for "c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe", hr=0x0

2025-11-29T01:40:02.229 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-environment-l1-1-0.dll", hr=0x0

2025-11-29T01:40:02.379 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2535f07be6867822893c0bd7f299affd\dwmcore.dll.mui", hr=0x0

2025-11-29T01:40:02.391 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_am-et_12002fbedc3ad139_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:02.434 Engine:Setting original file name "mavinject64.exe" for "c:\windows\winsxs\amd64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_4ed8aae8a286af05\mavinject.exe", hr=0x0

2025-11-29T01:40:02.595 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_b1cb38b404e84204\seclogon.dll.mui", hr=0x0

2025-11-29T01:40:02.638 Engine:Setting original file name "AuditPolicyGP.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\1e37baae98dce76981781b53776e70b9\auditpolicygpinterop.dll.mui", hr=0x0

2025-11-29T01:40:02.714 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9c4e95300400790b8d8a05d9bf7e1f5c\winnlsres.dll.mui", hr=0x0

2025-11-29T01:40:02.727 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e981bfd75ae177a858ec5c78a5cfda25\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-11-29T01:40:02.787 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-29T01:40:02.976 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ru-ru_e71c93fcf7d6f33e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:03.028 Engine:Setting original file name "qualityupdateassistant" for "c:\windows\system32\qualityupdateassistant.dll", hr=0x0

2025-11-29T01:40:03.039 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ro-ro_2c617f480dd85974_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:03.165 Engine:Setting original file name "wersvc" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2f884580919ab799dbe1ecd0f275799\wersvc.dll.mui", hr=0x0

2025-11-29T01:40:03.249 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_fa-ir_f7555235024374d9_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:03.280 Engine:Setting original file name "ClrCompression" for "c:\program files\windowsapps\microsoft.net.native.runtime.1.7_1.7.25531.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-29T01:40:03.313 Engine:Setting original file name "WIASERVC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiaservc.dll.mui_54051b53", hr=0x0

2025-11-29T01:40:03.315 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-29T01:40:03.345 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ru-ru_0752c1c778fe6e7c_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-29T01:40:03.447 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-29T01:40:03.830 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_id-id_6be80829898706a2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:03.835 Engine:Setting original file name "STI.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_en-us_d64b3cbf22b2a8d1_sti.dll.mui_00a4f15b", hr=0x0

2025-11-29T01:40:03.842 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9035fe481934c33719e75dea902d1698\bcastdvruserservice.dll.mui", hr=0x0

2025-11-29T01:40:03.874 Engine:Setting original file name "NVIDIA Debug Dump" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvdebugdump.exe", hr=0x0

2025-11-29T01:40:03.890 Engine:Setting original file name "acpiex.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-acpiex_31bf3856ad364e35_10.0.26100.1150_none_d0b1f61a88e2f0e9_acpiex.sys_6a8b9aed", hr=0x0

2025-11-29T01:40:03.905 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_60b47cf61af27adc_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-29T01:40:03.919 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x0

2025-11-29T01:40:04.108 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sv-se_29319a980f7b0983_msimsg.dll.mui_72e8994f", hr=0x0

2025-11-29T01:40:04.204 Engine:Setting original file name "pshed.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-pshed_31bf3856ad364e35_10.0.26100.1_none_633b3602ca01eb94_pshed.dll_f6ac239e", hr=0x0

2025-11-29T01:40:04.289 Engine:Setting original file name "ClipSVC.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-client-li..m-service.resources_31bf3856ad364e35_10.0.26100.1_en-us_3f436cbd520195fd_clipsvc.dll.mui_18823613", hr=0x0

2025-11-29T01:40:04.311 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_cy-gb_976c80cbdb5c65c1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:04.523 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_uk-ua_c5d15aec526b5235_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:04.586 Engine:Setting original file name "msfltr32.acm" for "c:\windows\winsxs\wow64_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_10.0.26100.1_none_e82ddbd17df6cb5b\msacm32.dll", hr=0x0

2025-11-29T01:40:04.638 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-29T01:40:04.652 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-11-29T01:40:04.704 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_6dcfa7c5391fe7a2_dnsapi.dll.mui_97465f8a", hr=0x0

2025-11-29T01:40:04.840 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_3cda2262e7ef70ab_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:04.937 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_10.0.26100.7171_none_f70fffd91c8f0404\winload.exe", hr=0x0

2025-11-29T01:40:05.117 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_et-ee_9786a4bcaafec5cb_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:05.384 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files\mozilla firefox\dxcompiler.dll", hr=0x0

2025-11-29T01:40:05.448 Engine:Setting original file name "Device_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\device\nb-no\edb83efa185c0a23d97fafe6a71cd608\diagpackage.dll.mui", hr=0x0

2025-11-29T01:40:05.468 Engine:Setting original file name "rtutils.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasrtutils_31bf3856ad364e35_10.0.26100.3037_none_a90518339a5ed736_rtutils.dll_243724ab", hr=0x0

2025-11-29T01:40:05.579 Engine:Setting original file name "udiapi.dll" for "c:\windows\system32\udiapiclient.dll", hr=0x0

2025-11-29T01:40:05.599 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-29T01:40:05.657 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaidvc.dll", hr=0x0

2025-11-29T01:40:05.662 Engine:Setting original file name "DWrite" for "c:\windows\winsxs\amd64_microsoft-windows-directwrite.resources_31bf3856ad364e35_10.0.26100.1_en-us_8e75f00536c95f8c\dwrite.dll.mui", hr=0x0

2025-11-29T01:40:05.669 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\windows\syswow64\nb-no\mfc40u.dll.mui", hr=0x0

2025-11-29T01:40:05.782 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.26100.1_en-us_12a038f1fa40c367_wlrmdr.exe.mui_ee563c83", hr=0x0

2025-11-29T01:40:05.868 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.xaml.winmd", hr=0x0

2025-11-29T01:40:05.945 Engine:Setting original file name "raspptp.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasbase-raspptp_31bf3856ad364e35_10.0.26100.1882_none_358d932997f7087d_raspptp.sys_25e89db1", hr=0x0

2025-11-29T01:40:06.036 Engine:Setting original file name "l3codec.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\17e7113a56f3171dc40844c9d3ee9e47\l3codeca.acm.mui", hr=0x0

2025-11-29T01:40:06.067 Engine:Setting original file name "bridgeres.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-networkbridge_31bf3856ad364e35_10.0.26100.2454_none_a3b07853b6183928_bridgeres.dll_55e40455", hr=0x0

2025-11-29T01:40:06.297 Engine:Setting original file name "mf.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..oundation.resources_31bf3856ad364e35_10.0.26100.1_en-us_8b9cc1ab2476fea1\mfpmp.exe.mui", hr=0x0

2025-11-29T01:40:06.365 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T01:40:06.387 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-processthreads-l1-1-1.dll", hr=0x0

2025-11-29T01:40:06.450 Engine:Setting original file name "FreeImage.dll" for "c:\program files (x86)\steam\steamapps\common\wallpaper_engine\bin\freeimage64.dll", hr=0x0

2025-11-29T01:40:06.455 Engine:Setting original file name "tier0_s.dll" for "c:\program files (x86)\steam\tier0_s64.dll", hr=0x0

2025-11-29T01:40:06.469 Engine:Setting original file name "nvaudcap.dll" for "c:\windows\syswow64\nvaudcap32v.dll", hr=0x0

2025-11-29T01:40:06.507 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mi-nz_b80bad72b6b0ee53_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:06.533 Engine:Setting original file name "CertCli" for "c:\windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_10.0.26100.1_en-us_61b2ff4b086153b8\certcli.dll.mui", hr=0x0

2025-11-29T01:40:06.537 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\en-us\wsepno.dll.mui", hr=0x0

2025-11-29T01:40:06.562 Engine:Setting original file name "ConfigurationRemotingServer.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\configurationremotingserver.exe", hr=0x0

2025-11-29T01:40:06.572 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_sr-..-rs_e67ffd847af5d250_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:06.576 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\power\en-us\diagpackage.dll.mui", hr=0x0

2025-11-29T01:40:06.600 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay8-payload_31bf3856ad364e35_1.0.26100.4202_none_bb7ce817a226517c\dpnaddr.dll", hr=0x0

2025-11-29T01:40:06.836 Engine:Setting original file name "msfltr32.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8836c193640d589410b5cc3dbe67e146\msacm32.dll.mui", hr=0x0

2025-11-29T01:40:06.930 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_6a24110114ad15ad_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-29T01:40:06.953 Engine:Setting original file name "usk.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\7c8e526d244ad657f882f8bbba0149ec\usk.rs.mui", hr=0x0

2025-11-29T01:40:06.965 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-29T01:40:06.984 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay4-payload_31bf3856ad364e35_1.0.26100.4202_none_186a372066698d60\dpmodemx.dll", hr=0x0

2025-11-29T01:40:07.166 Engine:Setting original file name "Register-CimProvider2.exe.mui" for "c:\windows\syswow64\en-us\register-cimprovider.exe.mui", hr=0x0

2025-11-29T01:40:07.258 Engine:Setting original file name "metabase.dll.mui" for "c:\windows\winsxs\wow64_microsoft-windows-iis-metabase.resources_31bf3856ad364e35_10.0.26100.1_en-us_8ff50fedc8451a7b\metadata.dll.mui", hr=0x0

2025-11-29T01:40:07.262 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x0

2025-11-29T01:40:07.340 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_de-de_ab2a1f0520f5ef2b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:07.408 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_6fced6fbf4c0e3e0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:07.534 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\en-us\diagpackage.dll.mui", hr=0x0

2025-11-29T01:40:07.554 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_7478bb53490dd7a8_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-11-29T01:40:07.608 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\windows\system32\nb-no\msidntld.dll.mui", hr=0x0

2025-11-29T01:40:07.613 Engine:Setting original file name "glu32" for "c:\windows\winsxs\amd64_microsoft-windows-opengl.resources_31bf3856ad364e35_10.0.26100.1_en-us_9c3b296d3d668ac3\glu32.dll.mui", hr=0x0

2025-11-29T01:40:07.635 Engine:Setting original file name "mf.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mediafoundation_31bf3856ad364e35_10.0.26100.7171_none_384874e2bca9ce3f\mfpmp.exe", hr=0x0

2025-11-29T01:40:07.667 Engine:Setting original file name "scesrv" for "c:\windows\system32\nb-no\scesrv.dll.mui", hr=0x0

2025-11-29T01:40:07.680 Engine:Setting original file name "DWWIN" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ae2b7dc24859d1fa2a509d5b642451b4\dwwin.exe.mui", hr=0x0

2025-11-29T01:40:07.824 Engine:Setting original file name "nvcuvid.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcuvid64.dll", hr=0x0

2025-11-29T01:40:07.858 Engine:Setting original file name "AppHostNameRegistrationVerifier.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\baf91a75f57ca8730dd9a6f926a58dd0\apphostregistrationverifier.exe.mui", hr=0x0

2025-11-29T01:40:07.868 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_en-gb_9672c12aaba943d2_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:07.976 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-rtlsupport-l1-1-0.dll", hr=0x0

2025-11-29T01:40:07.995 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-11-29T01:40:08.021 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_gu-in_97d53b15f69aaeca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:08.070 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_84875939fc6b99b1_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:08.086 Engine:Setting original file name "ServDeps.exe.mui" for "c:\windows\syswow64\wbem\nb-no\servdeps.dll.mui", hr=0x0

2025-11-29T01:40:08.116 Engine:Setting original file name "schtasks.exe" for "c:\windows\winsxs\amd64_microsoft-windows-sctasks_31bf3856ad364e35_10.0.26100.6725_none_25e27f3a6574108c\schtasks.exe", hr=0x0

2025-11-29T01:40:08.127 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_e38364b045f31518_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:08.174 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_el-gr_b382575af3d00da3_memtest.efi.mui_71e15c22", hr=0x0

2025-11-29T01:40:08.333 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.26100.1_en-us_0e875971ea5fda56\ieadvpack.dll.mui", hr=0x0

2025-11-29T01:40:08.374 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-datetime-l1-1-0.dll", hr=0x0

2025-11-29T01:40:08.396 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-29T01:40:08.424 Engine:Setting original file name "user32" for "c:\windows\system32\user32.dll", hr=0x0

2025-11-29T01:40:08.494 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.642.119.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-29T01:40:08.504 Engine:Setting original file name "shutdownui" for "c:\windows\winsxs\amd64_microsoft-windows-shutdownext.resources_31bf3856ad364e35_10.0.26100.1_en-us_9bd0f22e3578c871\shutdownext.dll.mui", hr=0x0

2025-11-29T01:40:08.652 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4\memtest.exe.mui", hr=0x0

2025-11-29T01:40:08.695 Engine:Setting original file name ".NET Host Resolver - 8.0.20" for "c:\users\serverpc\appdata\local\temp\emby-server-updater\hostfxr.dll", hr=0x0

2025-11-29T01:40:08.713 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_bs-..-ba_3017f7e2648d7e73_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:08.795 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_quz-pe_0266e81632046792_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:08.897 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lb-lu_cb546bb0b0d79a98_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:08.931 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\amd64_microsoft-windows-a..perience-ait-static_31bf3856ad364e35_10.0.26100.7019_none_ccd1f49f5e2b3b28\aitstatic.exe", hr=0x0

2025-11-29T01:40:09.019 Engine:Setting original file name "UNPShared.dll" for "c:\windows\winsxs\amd64_microsoft-windows-update-upshared_31bf3856ad364e35_10.0.26100.5074_none_29764f36135e6d4c\upshared.dll", hr=0x0

2025-11-29T01:40:09.094 Engine:Setting original file name "messagin.dll" for "c:\program files\bitdefender agent\27.1.1.23\messaging.dll", hr=0x0

2025-11-29T01:40:09.161 Engine:Setting original file name "WindowsCodecs" for "c:\windows\syswow64\windowscodecs.dll", hr=0x0

2025-11-29T01:40:09.196 Engine:Setting original file name "WerMgr" for "c:\windows\system32\wermgr.exe", hr=0x0

2025-11-29T01:40:09.240 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d\memtest.exe.mui", hr=0x0

2025-11-29T01:40:09.242 Engine:Setting original file name "imapi.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bd7c223153b9576fe4c4e66ebf1c6ece\imapi.dll.mui", hr=0x0

2025-11-29T01:40:09.360 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hi-in_8555c5797fc8795e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:09.432 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\esrb.rs.mui", hr=0x0

2025-11-29T01:40:09.445 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\updated\nmhproxy.exe", hr=0x0

2025-11-29T01:40:09.525 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-11-29T01:40:09.546 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_zh-tw_ff4ad39908e2da78_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:09.549 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-29T01:40:09.597 Engine:Setting original file name "microsoftedgedevtools.exe" for "c:\windows\system32\microsoftedgecp.exe", hr=0x0

2025-11-29T01:40:09.617 Engine:Setting original file name "la57setup.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ec428185df2994f7d7954c1efe1b2738\la57setup.exe.mui", hr=0x0

2025-11-29T01:40:09.624 Engine:Setting original file name "wuapi.dll" for "c:\windows\uus\x86\wuapicore.dll", hr=0x0

2025-11-29T01:40:09.695 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\system32\en-us\dsprop.dll.mui", hr=0x0

2025-11-29T01:40:09.938 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-29T01:40:09.959 Engine:Setting original file name "etweseproviderresources.dll" for "c:\windows\winsxs\backup\amd64_microsoft-etw-ese_31bf3856ad364e35_10.0.26100.1_none_cc4e7afeeee8d3b1_etweseproviderresources.dll_f21e8ea7", hr=0x0

2025-11-29T01:40:10.021 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_2821a024e044bada_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:10.023 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-11-29T01:40:10.067 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bf8ce2a53903d9e6d302aee07de95dd9\mfc40u.dll.mui", hr=0x0

2025-11-29T01:40:10.080 Engine:Setting original file name "TAPISRV.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-tapiservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_83c985f74a352be9\tapisrv.dll.mui", hr=0x0

2025-11-29T01:40:10.271 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lo-la_099683f3cb70d44f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:10.274 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x0

2025-11-29T01:40:10.364 Engine:Setting original file name "wininet.dll" for "c:\windows\systemresources\wininet.dll.mun", hr=0x0

2025-11-29T01:40:10.393 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\nb-no\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x0

2025-11-29T01:40:10.409 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_hu-hu_9dd052ebcaf187fd_memtest.efi.mui_71e15c22", hr=0x0

2025-11-29T01:40:10.412 Engine:Setting original file name "PrintBrmEng.exe.mui" for "c:\windows\system32\spool\tools\en-us\printbrmengine.exe.mui", hr=0x0

2025-11-29T01:40:10.414 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_it-it_4087c8eabdc39e5f_memtest.efi.mui_71e15c22", hr=0x0

2025-11-29T01:40:10.445 Engine:Setting original file name "audioadg.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f411807b0749e7d602e77baf3c1c4e60\audiodg.exe.mui", hr=0x0

2025-11-29T01:40:10.515 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x0

2025-11-29T01:40:10.586 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-t..iprovider.resources_31bf3856ad364e35_10.0.26100.1_en-us_41b711b4f2db4fe7\rdpsign.exe.mui", hr=0x0

2025-11-29T01:40:10.714 Engine:Setting original file name "Video_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\video\nb-no\2ca5a0690699da595bd35a22420a1c04\diagpackage.dll.mui", hr=0x0

2025-11-29T01:40:10.722 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-29T01:40:10.743 Engine:Setting original file name "FvSDKTestClientPublic" for "c:\program files\nvidia corporation\frameviewsdk\sdk\fvsdktestclient_public.exe", hr=0x0

2025-11-29T01:40:10.787 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\qps-ploc\msprivs.dll.mui", hr=0x0

2025-11-29T01:40:10.789 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-11-29T01:40:10.970 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files\mozilla firefox\updated\dxcompiler.dll", hr=0x0

2025-11-29T01:40:11.075 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\windows\system32\nb-no\pnpclean.dll.mui", hr=0x0

2025-11-29T01:40:11.087 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_or-in_f89501f89f876dc5_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:11.118 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.26100.7171_none_4ad020869b677502\taskmgr.exe.mun", hr=0x0

2025-11-29T01:40:11.166 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_ca98740be1962356_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:11.219 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x0

2025-11-29T01:40:11.271 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_it-it_f0fca0072ba86c5a\msprivs.dll.mui", hr=0x0

2025-11-29T01:40:11.312 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps-ploc_7ccda1c46b445ed4\memtest.exe.mui", hr=0x0

2025-11-29T01:40:11.329 Engine:Setting original file name "NETBIOS.SYS" for "c:\windows\winsxs\backup\amd64_microsoft-windows-netbios_31bf3856ad364e35_10.0.26100.1_none_56d5608ad3abe945_netbios.sys_6f23c4df", hr=0x0

2025-11-29T01:40:11.376 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-process-l1-1-0.dll", hr=0x0

2025-11-29T01:40:11.507 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\systemresources\etwcoreuicomponentsresources.dll.mun", hr=0x0

2025-11-29T01:40:11.519 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pt-br_55b72b827c87f88f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:11.633 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_0dc0948c02e4507b_memtest.efi.mui_71e15c22", hr=0x0

2025-11-29T01:40:11.646 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mt-mt_b4ebaa02b8bfece3_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:11.677 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.devices.winmd", hr=0x0

2025-11-29T01:40:11.713 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_576ce8a1070e9744_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:11.725 Engine:Setting original file name "FileInfo.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-fileinfominifilter_31bf3856ad364e35_10.0.26100.1150_none_729c4b9be137bb96_fileinfo.sys_9be2dfcd", hr=0x0

2025-11-29T01:40:11.803 Engine:Setting original file name "aclui.dll" for "c:\windows\winsxs\amd64_microsoft-windows-aclui_31bf3856ad364e35_10.0.26100.7019_none_f0f7bbb4638cf785\aclui.dll.mun", hr=0x0

2025-11-29T01:40:11.808 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\73be2921551d\apex_fieldsamplerchecked_x86.dll", hr=0x0

2025-11-29T01:40:11.865 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.777.2143.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-11-29T01:40:11.927 Engine:Setting original file name "qualityupdateassistant" for "c:\program files\microsoft update health tools\qualityupdateassistant.dll", hr=0x0

2025-11-29T01:40:11.950 Engine:Setting original file name "NVPPE.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvppex.dll", hr=0x0

2025-11-29T01:40:12.024 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_en-us_4761fcc7ecd6d884_winresume.efi.mui_f412814e", hr=0x0

2025-11-29T01:40:12.197 Engine:Setting original file name "NVPrxy.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvprxy32.dll", hr=0x0

2025-11-29T01:40:12.299 Engine:Setting original file name "Mystify" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\589bec7339e102473dc7566c3b9b0f45\mystify.scr.mui", hr=0x0

2025-11-29T01:40:12.324 Engine:Setting original file name "volmgrx.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..memanager.resources_31bf3856ad364e35_10.0.26100.1_en-us_a18734abf077f9b4_volmgrx.sys.mui_b0c205d7", hr=0x0

2025-11-29T01:40:12.358 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-11-29T01:40:12.458 Engine:Setting original file name "libcrypto" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\libcrypto-3-x64.dll", hr=0x0

2025-11-29T01:40:12.480 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-string-l1-1-0.dll", hr=0x0

2025-11-29T01:40:12.512 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hi-in_83227505fd46a5bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:12.552 Engine:Setting original file name "CertCa" for "c:\windows\winsxs\amd64_microsoft-windows-c..ertca-dll.resources_31bf3856ad364e35_10.0.26100.1_nb-no_25e015431023bb9b\certca.dll.mui", hr=0x0

2025-11-29T01:40:12.650 Engine:Setting original file name "PCW_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_ddc581f4a364804b\diagpackage.dll.mui", hr=0x0

2025-11-29T01:40:12.742 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..subsystem.resources_31bf3856ad364e35_10.0.26100.1_nb-no_ab8620bc0ed41a36\scardsvr.dll.mui", hr=0x0

2025-11-29T01:40:12.759 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_6.0.3624.51421.dll", hr=0x0

2025-11-29T01:40:12.850 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-29T01:40:12.884 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_06d4a9c0547686dc\msprivs.dll.mui", hr=0x0

2025-11-29T01:40:13.034 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mapi_31bf3856ad364e35_10.0.26100.7019_none_473a9ee5c9a5ebee\mapistub.dll", hr=0x0

2025-11-29T01:40:13.151 Engine:Setting original file name "mofcomp.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_nb-no_8c87dcbbb8114be3_mofcomp.exe.mui_35badf56", hr=0x0

2025-11-29T01:40:13.155 Engine:Setting original file name "MspsProv.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..oning-wmi.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd6de3cbb42de1cb\mspsprov.dll.mui", hr=0x0

2025-11-29T01:40:13.201 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x0

2025-11-29T01:40:13.291 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.26100.7019_none_4a484d6501b73a17\wwanapi.dll", hr=0x0

2025-11-29T01:40:13.360 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ne-np_591939d32e7d4223_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:13.433 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.xboxidentityprovider_12.130.16001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-11-29T01:40:13.589 Engine:Setting original file name "Operativsystemet Microsoft� Windows�" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e2a170892be5347a116ae0806fb5309d\pcalua.exe.mui", hr=0x0

2025-11-29T01:40:13.662 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x0

2025-11-29T01:40:13.678 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x0

2025-11-29T01:40:13.957 Engine:Setting original file name "imageres.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-imageres_31bf3856ad364e35_10.0.26100.1_none_d9b14b936072a0bc\imageres.dll.mun", hr=0x0

2025-11-29T01:40:14.167 Engine:Setting original file name "vcruntime140.dll" for "c:\config.msi\1c742.rbf", hr=0x0

2025-11-29T01:40:14.208 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-29T01:40:14.249 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_kk-kz_71b9c9e0d19e9ee0_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:14.435 Engine:Setting original file name "Apps_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\apps\nb-no\d2a92c7cfed83dc547a21508b5b0ea0f\diagpackage.dll.mui", hr=0x0

2025-11-29T01:40:14.451 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32.dll", hr=0x0

2025-11-29T01:40:14.504 Engine:Setting original file name "CertPKICmdlet" for "c:\windows\system32\en-us\certpkicmdlet.dll.mui", hr=0x0

2025-11-29T01:40:14.556 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ed4232cecc06e9efb72d2a7c142b63b4\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x0

2025-11-29T01:40:14.565 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.424.1611.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-29T01:40:14.626 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_0cb2119581e88ce0\diagpackage.dll.mui", hr=0x0

2025-11-29T01:40:14.781 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\system32\bcp47langs.dll", hr=0x0

2025-11-29T01:40:14.852 Engine:Setting original file name "gpapi.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-g..licy-base.resources_31bf3856ad364e35_10.0.26100.1_en-us_be2843fbd972ca37_gpapi.dll.mui_ef0a9748", hr=0x0

2025-11-29T01:40:14.905 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x0

2025-11-29T01:40:14.916 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\winsxs\amd64_microsoft-windows-aerolite.resources_31bf3856ad364e35_10.0.26100.1_en-us_bc993ceae8fc48bf\aerolite.msstyles.mui", hr=0x0

2025-11-29T01:40:15.192 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\en-us\utilman.exe.mui", hr=0x0

2025-11-29T01:40:15.228 Engine:Setting original file name "clrgc.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25102.64.0_x64__8wekyb3d8bbwe\clrgcexp.dll", hr=0x0

2025-11-29T01:40:15.330 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x0

2025-11-29T01:40:15.438 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-11-29T01:40:15.447 Engine:Setting original file name "sqlite3" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\sqlite3.dll", hr=0x0

2025-11-29T01:40:15.512 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x0

2025-11-29T01:40:15.561 Engine:Setting original file name "w32time.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-time-tool.resources_31bf3856ad364e35_10.0.26100.1_en-us_7b897a2738f484fc\w32tm.exe.mui", hr=0x0

2025-11-29T01:40:15.565 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd473133072db5bb\diagpackage.dll.mui", hr=0x0

2025-11-29T01:40:15.590 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_80a1d04cb31f8eca_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:15.595 Engine:Setting original file name "ERC" for "c:\windows\system32\nb-no\wercplsupport.dll.mui", hr=0x0

2025-11-29T01:40:15.625 Engine:Setting original file name "vdsutil.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-v..skservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_59d12af3dce743c1_vdsutil.dll.mui_0caf9b0e", hr=0x0

2025-11-29T01:40:15.710 Engine:Setting original file name "AppLockerCSP.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appidcore.resources_31bf3856ad364e35_10.0.26100.1_en-us_564c6ad9b132641f_applockercsp.dll.mui_d2a0df70", hr=0x0

2025-11-29T01:40:15.765 Engine:Setting original file name "dnsrslvr.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570_dnsrslvr.dll.mui_1e1a1ed1", hr=0x0

2025-11-29T01:40:15.834 Engine:Setting original file name "PSAPI" for "c:\windows\winsxs\backup\wow64_microsoft-windows-basedependencies_31bf3856ad364e35_10.0.26100.1_none_09ea4476c5bcc4c0_psapi.dll_e8b5b4d1", hr=0x0

2025-11-29T01:40:15.860 Engine:Setting original file name "AcPlugin.dll" for "c:\program files\windowsapps\microsoft.applicationcompatibilityenhancements_1.2511.9.0_x64__8wekyb3d8bbwe\amd64\acplugin_test.dll", hr=0x0

2025-11-29T01:40:15.870 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\426c2b1101abec586136a4bbd67a716e\narrator.exe.mui", hr=0x0

2025-11-29T01:40:15.887 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..tiator_ui.resources_31bf3856ad364e35_10.0.26100.1_en-us_7967a83a130d426e\iscsicpl.dll.mui", hr=0x0

2025-11-29T01:40:15.975 Engine:Setting original file name "WindowsMediaPlayerPlayDVD_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_587c1f8aa98a4a71\diagpackage.dll.mui", hr=0x0

2025-11-29T01:40:16.160 Engine:Setting original file name "scecli" for "c:\windows\system32\nb-no\scecli.dll.mui", hr=0x0

2025-11-29T01:40:16.177 Engine:Setting original file name "scesrv" for "c:\windows\winsxs\amd64_microsoft-windows-s..ionengine.resources_31bf3856ad364e35_10.0.26100.1_en-us_e63bd45b831a32e3\scesrv.dll.mui", hr=0x0

2025-11-29T01:40:16.206 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_bg-bg_af9bba51d24fbf0e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:16.264 Engine:Setting original file name "nvhda.sys" for "c:\windows\system32\driverstore\filerepository\nvhda.inf_amd64_c32d8360d192a82e\nvhda64v.sys", hr=0x0

2025-11-29T01:40:16.274 Engine:Setting original file name "wmiutils.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiutils.dll.mui_42583eaf", hr=0x0

2025-11-29T01:40:16.288 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_te-in_e10bae4a47776b9f_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:16.316 Engine:Setting original file name "BdncProxy.dll" for "c:\program files\bitdefender agent\27.1.1.23\crash_handler\bdnc.dll", hr=0x0

2025-11-29T01:40:16.388 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.26100.1_nb-no_e175a2f7bf27ee8d_ws2ifsl.sys.mui_b672c7b4", hr=0x0

2025-11-29T01:40:16.451 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_eu-es_e55e702bbb854a24_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:16.487 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-msinfo32-exe.resources_31bf3856ad364e35_10.0.26100.1_en-us_53ae64398a08feba\msinfo32.exe.mui", hr=0x0

2025-11-29T01:40:16.530 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-29T01:40:16.623 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x86__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-29T01:40:16.643 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x0

2025-11-29T01:40:16.737 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x0

2025-11-29T01:40:16.745 Engine:Setting original file name "NxCooking.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\v2.7.6\physxcooking.dll", hr=0x0

2025-11-29T01:40:16.773 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-11-29T01:40:16.910 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x0

2025-11-29T01:40:16.985 Engine:Setting original file name "filterLib.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\4fffc8576907b0b5da815790887fb244\fltlib.dll.mui", hr=0x0

2025-11-29T01:40:17.013 Engine:Setting original file name "srpuxgp.dll" for "c:\windows\systemresources\srpuxnativesnapin.dll.mun", hr=0x0

2025-11-29T01:40:17.015 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7_memtest.exe.mui_77b8cbcc", hr=0x0

2025-11-29T01:40:17.202 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_nl-nl_0d26e65c98dbf6f7_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:17.212 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sl-si_8549ba61ed8af84b_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:17.216 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x0

2025-11-29T01:40:17.381 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_pl-pl_9d43c82914fc6152_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:17.401 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.web.winmd", hr=0x0

2025-11-29T01:40:17.464 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-11-29T01:40:17.588 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ca-es_584cefb2c144b7d8_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:17.598 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\winsxs\amd64_microsoft-windows-qedwipes_31bf3856ad364e35_10.0.26100.1_none_5473011012d79dc1\qedwipes.dll.mun", hr=0x0

2025-11-29T01:40:17.757 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_et-ee_4da61d721400c924_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:17.797 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_fb2fbffb5205c552_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:18.017 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..xe-common.resources_31bf3856ad364e35_10.0.26100.1_en-us_58b62bf54b9ae38a\msinfo32.exe.mui", hr=0x0

2025-11-29T01:40:18.133 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.70.1338.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-11-29T01:40:18.137 Engine:Setting original file name "netcfgx.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-tcpip.resources_31bf3856ad364e35_10.0.26100.1_en-us_c93621b935b09922_tcpipcfg.dll.mui_a5479fc1", hr=0x0

2025-11-29T01:40:18.187 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_f4c1513bcd79893e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:18.233 Engine:Setting original file name "nvxdsync.exe" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\session\nvxdsyncplugin.dll", hr=0x0

2025-11-29T01:40:18.365 Engine:Setting original file name "ReShade" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\reshadefxc64.exe", hr=0x0

2025-11-29T01:40:18.408 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-11-29T01:40:18.451 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_0fbfb1c9f2926e3e_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:18.482 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\power\nb-no\2803551e72f3605cc0b181750700647e\diagpackage.dll.mui", hr=0x0

2025-11-29T01:40:18.543 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_th-th_25ee4fb15dc2e739_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:18.548 Engine:Setting original file name "Umpo.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-u..erservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_a887c532823d0a08_umpo.dll.mui_cac12e54", hr=0x0

2025-11-29T01:40:18.551 Engine:Setting original file name "bootres" for "c:\windows\boot\resources\nb-no\bootres.dll.mui", hr=0x0

2025-11-29T01:40:18.575 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\b74f41bc269d13282681d018820fb031\ddores.dll.mui", hr=0x0

2025-11-29T01:40:18.596 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x0

2025-11-29T01:40:18.604 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\mscordaccore_amd64_amd64_8.0.2125.47513.dll", hr=0x0

2025-11-29T01:40:18.629 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-namedpipe-l1-1-0.dll", hr=0x0

2025-11-29T01:40:18.726 Engine:Setting original file name "dxmasf.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_10.0.26100.7019_none_b1abcb083360b859\msdxm.ocx", hr=0x0

2025-11-29T01:40:18.853 Engine:Setting original file name "Bubbles" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ee15dd2b573766654f76694ac2f468d4\bubbles.scr.mui", hr=0x0

2025-11-29T01:40:18.891 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_tr-tr_2c24c8b8ddbbff8a_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:18.916 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_es-mx_9dca765f230af946_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:18.938 Engine:Setting original file name "CUDART64_65_19.DLL" for "c:\program files (x86)\nvidia corporation\physx\common\cudart64_65.dll", hr=0x0

2025-11-29T01:40:18.954 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-errorhandling-l1-1-0.dll", hr=0x0

2025-11-29T01:40:19.084 Engine:Setting original file name "wcp.dll" for "c:\windows\system32\ssshim.dll", hr=0x0

2025-11-29T01:40:19.183 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\winresume.exe", hr=0x0

2025-11-29T01:40:19.231 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-time-l1-1-0.dll", hr=0x0

2025-11-29T01:40:19.235 Engine:Setting original file name "SCardDlg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.26100.3323_en-us_fe960d41ea77a2e8_scarddlg.dll.mui_300ae9df", hr=0x0

2025-11-29T01:40:19.268 Engine:Setting original file name "reg.exe" for "c:\windows\winsxs\wow64_microsoft-windows-r..-commandline-editor_31bf3856ad364e35_10.0.26100.5074_none_d7dcabbe0ef09540\reg.exe", hr=0x0

2025-11-29T01:40:19.280 Engine:Setting original file name "TrustedSignalCredProv.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..-credprov.resources_31bf3856ad364e35_10.0.26100.1_en-us_080e5e17ad23b7b4_trustedsignalcredprov.dll.mui_5edc427b", hr=0x0

2025-11-29T01:40:19.315 Engine:Setting original file name "fpb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\fpb.rs.mui", hr=0x0

2025-11-29T01:40:19.453 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ta-in_72c4ac1bf2d12188_comctl32.dll.mui_0da4e682", hr=0x0

2025-11-29T01:40:19.696 OriginalFileName Maintenance::11638 files in Moac, 0 skipped (cached), 435 filename set

2025-11-29T01:40:19.696 [AutoPurge] Routine task for Cache Maintenance has ended.

2025-11-29T01:52:08.371 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #410855, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T01:52:08.373 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #410856, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T01:52:18.374 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #410863, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T01:52:18.378 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #410864, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T01:54:19.542 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #410870, FileId: 0x7000000033b09, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T01:55:11.359 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T02:07:06.873 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

2025-11-29T02:07:06.883 [DLP] DlpEngineConfigStorage::OnConfigChange DlpDwordSettingsMap:

2025-11-29T02:07:06.884 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-29T02:07:06.884 [RTP] Duplicating the current plugin configuration object...

2025-11-29T02:07:06.884 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-29T02:07:06.884 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-29T02:07:06.884 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-29T02:07:06.884 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-29T02:07:06.884 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-29T02:07:06.884 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-29T02:07:06.884 [RTP] No config change detected. Not updating plugin configuration.

2025-11-29T02:07:06.884 [RTP] No config changes found. No configuration switch.

2025-11-29T02:07:06.884 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-29T02:07:06.884 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-29T02:07:06.884 [RTP] [RtpConfig] Config change detected, type: 16

2025-11-29T02:07:06.884 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-29T02:07:06.884 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-29T02:07:06.884 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-29T02:07:06.884 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-29T02:07:06.884 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-29T02:07:06.884 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-29T02:07:06.884 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-29T02:07:06.884 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-29T02:07:06.884 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-29T02:07:06.884 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-29T02:07:06.884 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-29T02:07:06.885 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-29T02:07:06.885 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-29T02:07:06.885 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-29T02:07:06.885 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T02:07:06.886 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T02:07:06.888 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T02:07:06.889 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T02:07:06.891 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T02:07:06.893 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 689499(ms) from now at 03:18 (02:18 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-29T02:07:09.442 [RTP] Duplicating the current plugin configuration object...

2025-11-29T02:07:09.442 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-29T02:07:09.442 [RTP] Updating plugin configuration due to recent config changes (0x41e) ...

2025-11-29T02:07:09.442 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-29T02:07:09.443 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x218

2025-11-29T02:09:19.988 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #411005, FileId: 0x49000000037e5f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T02:09:55.892 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #411506, FileId: 0xcc00000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T02:10:16.347 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T02:24:20.514 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #411657, FileId: 0x21d00000000e38c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T02:25:21.354 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T02:39:21.040 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #411814, FileId: 0x4b000000038ed9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T02:40:26.352 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T02:52:05.025 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #412160, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T02:52:05.028 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #412161, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T02:52:15.033 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #412166, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T02:52:15.038 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #412167, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T02:54:21.326 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #412174, FileId: 0x51000000039005, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T02:55:31.343 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T03:09:21.834 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #412911, FileId: 0x9000000033fac, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T03:10:36.342 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T03:23:32.494 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T03:24:22.331 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #413152, FileId: 0xd900000005744a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T03:25:41.335 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T03:28:22.640 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3285, Count: 342, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\a4d0344c-ed1a-4f39-9008-41fc9cfacd38.tmp, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 3022, Count: 164, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2868, Count: 236, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\93d466bc-47fc-466d-9517-0610cc340ce2.tmp, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 739, Count: 139, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: RuntimeBroker.exe, Pid: 12368, TotalTime: 527, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 29%

2025-11-29T03:28:22.640 ProcessImageName: RuntimeBroker.exe, Pid: 17648, TotalTime: 496, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 27%

2025-11-29T03:28:22.640 ProcessImageName: DeviceCensus.exe, Pid: 28836, TotalTime: 356, Count: 14, MaxTime: 296, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-29T03:28:22.640 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 300, Count: 59, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 285, Count: 83, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 270, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 255, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 225, Count: 74, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\532001fc78e4e796.customDestinations-ms, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: taskhostw.exe, Pid: 3952, TotalTime: 225, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-29T03:28:22.640 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 170, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 165, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 28512, TotalTime: 135, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 2%

2025-11-29T03:28:22.640 ProcessImageName: backgroundTaskHost.exe, Pid: 14024, TotalTime: 135, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446, EstimatedImpact: 39%

2025-11-29T03:28:22.640 ProcessImageName: taskhostw.exe, Pid: 7376, TotalTime: 90, Count: 37, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\ctac.json, EstimatedImpact: 7%

2025-11-29T03:28:22.640 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: GameBar.exe, Pid: 19136, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_7.325.11061.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1822317515-1041744019-1682422708-1001-MergedResources-34.pri, EstimatedImpact: 9%

2025-11-29T03:28:22.640 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: svchost.exe, Pid: 8188, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT31EF.tmp, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\4e4cdc87-91f2-4632-b55d-4d80e1452be6.tmp, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: HxTsr.exe, Pid: 29256, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.7_7.2409.9001.0_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 17%

2025-11-29T03:28:22.640 ProcessImageName: taskhostw.exe, Pid: 24776, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-29T03:28:22.640 ProcessImageName: RuntimeBroker.exe, Pid: 29092, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\BackgroundTransferApi\2ce82ac5-238e-4e56-b2d7-5aa5d8938522.down_data, EstimatedImpact: 3%

2025-11-29T03:28:22.640 ProcessImageName: updater.exe, Pid: 22952, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ac158554-aa0e-45cd-82a6-e07ff7caabce.tmp, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\logs\embyserver.txt, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: updater.exe, Pid: 5268, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\401d44483c00cbf832531ee06b1ff1d7f8a5c686.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-29T03:28:22.640 ProcessImageName: StoreDesktopExtension.exe, Pid: 15208, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: taskhostw.exe, Pid: 15860, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 3%

2025-11-29T03:28:22.640 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--kglcheck-.lnk, EstimatedImpact: 12%

2025-11-29T03:28:22.640 ProcessImageName: updater.exe, Pid: 4012, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-29T03:28:22.640 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-29T03:39:22.783 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #413242, FileId: 0x62000000039f02, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T03:40:46.325 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

Internal signature match:subtype=Lowfi, sigseq=0x0000055508F3A39A, sigsha=adc296cf14a948811ec4fc94642d047458c25c9d, cached=false, source=2, resourceid=0xaab25df3

Internal signature match:subtype=Lowfi, sigseq=0x0000108090FCF4C4, sigsha=064f0536ffb97bb72d6c274c080aa4e2ffdf1b46, cached=false, source=2, resourceid=0xe9a0dc71

Internal signature match:subtype=Lowfi, sigseq=0x0000157E63AB3170, sigsha=e38cd0eab571423665adf9aa5888e28cacf8b14e, cached=false, source=2, resourceid=0x0e2f25c4

2025-11-29T03:49:29.022 Engine:Setting original file name "BM_IsPotentialSideLoad" for "c:\xampp\mercurymail\sqlite3.dll", hr=0x0

Internal signature match:subtype=Lowfi, sigseq=0x0006D3BDCFCEABEE, sigsha=c9c8b6b7c7b47b78581c804bcb01032bb84e2863, cached=false, source=2, resourceid=0x1605cb09

2025-11-29T03:52:06.838 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #414699, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T03:52:06.842 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #414700, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T03:52:16.853 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #414709, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T03:52:16.857 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #414710, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T03:54:23.310 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #414719, FileId: 0x3e00000003a117, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T03:55:51.329 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T04:09:24.022 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #414939, FileId: 0x2d00000005601d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T04:10:56.314 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T04:24:24.496 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #415034, FileId: 0xc00000007c473, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T04:26:01.319 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T04:39:25.238 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #415125, FileId: 0x1400000007c507, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T04:41:06.316 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T04:52:07.429 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #415238, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T04:52:07.433 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #415239, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T04:52:17.428 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #415244, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T04:52:17.432 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #415245, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T04:52:17.443 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #415246, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T04:52:17.446 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #415247, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T04:54:25.730 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #415252, FileId: 0x217000000002e60, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T04:56:11.299 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T05:09:26.293 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #415789, FileId: 0x35300000000ecde, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T05:11:16.293 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T05:23:34.430 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T05:24:26.714 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #416013, FileId: 0xf00000007c64e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T05:26:21.289 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T05:28:22.604 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 19036, Count: 1591, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume4\xampp\sendmail\sendmail.exe, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 4080, Count: 425, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\a4d0344c-ed1a-4f39-9008-41fc9cfacd38.tmp, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3483, Count: 289, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\93d466bc-47fc-466d-9517-0610cc340ce2.tmp, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 3022, Count: 164, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: RuntimeBroker.exe, Pid: 12368, TotalTime: 527, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 29%

2025-11-29T05:28:22.604 ProcessImageName: RuntimeBroker.exe, Pid: 17648, TotalTime: 496, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 27%

2025-11-29T05:28:22.604 ProcessImageName: WmiPrvSE.exe, Pid: 19256, TotalTime: 360, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\wstorvsp.inf, EstimatedImpact: 33%

2025-11-29T05:28:22.604 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 360, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: DeviceCensus.exe, Pid: 28836, TotalTime: 356, Count: 14, MaxTime: 296, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-29T05:28:22.604 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 315, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 300, Count: 87, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 300, Count: 59, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 255, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\532001fc78e4e796.customDestinations-ms, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: taskhostw.exe, Pid: 3952, TotalTime: 225, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-29T05:28:22.604 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 210, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 170, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 28512, TotalTime: 135, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 2%

2025-11-29T05:28:22.604 ProcessImageName: backgroundTaskHost.exe, Pid: 14024, TotalTime: 135, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446, EstimatedImpact: 39%

2025-11-29T05:28:22.604 ProcessImageName: taskhostw.exe, Pid: 7376, TotalTime: 90, Count: 37, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\ctac.json, EstimatedImpact: 7%

2025-11-29T05:28:22.604 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: GameBar.exe, Pid: 19136, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_7.325.11061.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1822317515-1041744019-1682422708-1001-MergedResources-34.pri, EstimatedImpact: 9%

2025-11-29T05:28:22.604 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\4e4cdc87-91f2-4632-b55d-4d80e1452be6.tmp, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: svchost.exe, Pid: 8188, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT31EF.tmp, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: HxTsr.exe, Pid: 29256, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.7_7.2409.9001.0_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 17%

2025-11-29T05:28:22.604 ProcessImageName: taskhostw.exe, Pid: 24776, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-29T05:28:22.604 ProcessImageName: updater.exe, Pid: 5268, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\logs\embyserver.txt, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: updater.exe, Pid: 22952, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ac158554-aa0e-45cd-82a6-e07ff7caabce.tmp, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: RuntimeBroker.exe, Pid: 29092, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\BackgroundTransferApi\2ce82ac5-238e-4e56-b2d7-5aa5d8938522.down_data, EstimatedImpact: 3%

2025-11-29T05:28:22.604 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\401d44483c00cbf832531ee06b1ff1d7f8a5c686.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-29T05:28:22.604 ProcessImageName: StoreDesktopExtension.exe, Pid: 15208, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: taskhostw.exe, Pid: 15860, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 3%

2025-11-29T05:28:22.604 ProcessImageName: StoreDesktopExtension.exe, Pid: 28496, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--kglcheck-.lnk, EstimatedImpact: 12%

2025-11-29T05:28:22.604 ProcessImageName: updater.exe, Pid: 4012, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: updater.exe, Pid: 24104, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\59332062-0403-47fa-8726-a62c76ad60c7.tmp, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-29T05:28:22.604 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-29T05:39:27.115 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #416092, FileId: 0x2600000007c6ab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T05:41:26.284 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T05:52:06.231 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #416255, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T05:52:06.234 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #416256, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T05:52:16.242 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #416263, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T05:52:16.246 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #416264, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T05:54:27.779 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #416273, FileId: 0x4100000007c722, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T05:56:31.286 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T06:09:28.374 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #416364, FileId: 0x2200000007c7ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T06:11:36.289 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T06:24:29.086 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #416584, FileId: 0x500000007c855, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T06:26:41.275 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T06:39:29.613 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #417896, FileId: 0x500000007c91a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T06:41:46.277 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T06:52:07.204 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #417998, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T06:52:07.207 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #417999, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T06:52:17.209 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #418004, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T06:52:17.213 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #418005, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T06:54:30.360 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #418012, FileId: 0xf8000000011f52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T06:56:51.262 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T07:09:30.764 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #418187, FileId: 0xd2000000011249, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T07:11:56.261 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T07:23:36.443 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T07:24:31.054 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #418350, FileId: 0x3600000007ca65, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T07:27:01.260 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T07:28:22.578 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 19036, Count: 1591, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume4\xampp\sendmail\sendmail.exe, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 4725, Count: 507, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\a4d0344c-ed1a-4f39-9008-41fc9cfacd38.tmp, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4144, Count: 343, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\93d466bc-47fc-466d-9517-0610cc340ce2.tmp, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 3022, Count: 164, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: RuntimeBroker.exe, Pid: 12368, TotalTime: 527, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 29%

2025-11-29T07:28:22.578 ProcessImageName: RuntimeBroker.exe, Pid: 17648, TotalTime: 496, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 27%

2025-11-29T07:28:22.578 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 375, Count: 63, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 375, Count: 50, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: WmiPrvSE.exe, Pid: 19256, TotalTime: 360, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\wstorvsp.inf, EstimatedImpact: 33%

2025-11-29T07:28:22.578 ProcessImageName: DeviceCensus.exe, Pid: 28836, TotalTime: 356, Count: 14, MaxTime: 296, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-29T07:28:22.578 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 315, Count: 95, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 300, Count: 59, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 255, Count: 83, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\532001fc78e4e796.customDestinations-ms, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 255, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: taskhostw.exe, Pid: 3952, TotalTime: 225, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-29T07:28:22.578 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 185, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 28512, TotalTime: 135, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 2%

2025-11-29T07:28:22.578 ProcessImageName: backgroundTaskHost.exe, Pid: 14024, TotalTime: 135, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446, EstimatedImpact: 39%

2025-11-29T07:28:22.578 ProcessImageName: svchost.exe, Pid: 29056, TotalTime: 121, Count: 16, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{6730ae82-6dfb-4d06-bda3-2da23776df75}_OnDiskSnapshotProp, EstimatedImpact: 80%

2025-11-29T07:28:22.578 ProcessImageName: taskhostw.exe, Pid: 7376, TotalTime: 90, Count: 37, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\ctac.json, EstimatedImpact: 7%

2025-11-29T07:28:22.578 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\480e6fb2-6955-43bb-9a6d-5a8376b1a3a3\content.phf, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: GameBar.exe, Pid: 19136, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_7.325.11061.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1822317515-1041744019-1682422708-1001-MergedResources-34.pri, EstimatedImpact: 9%

2025-11-29T07:28:22.578 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\4e4cdc87-91f2-4632-b55d-4d80e1452be6.tmp, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: svchost.exe, Pid: 8188, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT31EF.tmp, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: HxTsr.exe, Pid: 29256, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.UI.Xaml.2.7_7.2409.9001.0_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 17%

2025-11-29T07:28:22.578 ProcessImageName: taskhostw.exe, Pid: 24776, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-29T07:28:22.578 ProcessImageName: taskhostw.exe, Pid: 23120, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 1%

2025-11-29T07:28:22.578 ProcessImageName: RuntimeBroker.exe, Pid: 29092, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\BackgroundTransferApi\2ce82ac5-238e-4e56-b2d7-5aa5d8938522.down_data, EstimatedImpact: 3%

2025-11-29T07:28:22.578 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\logs\embyserver.txt, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: updater.exe, Pid: 5268, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: updater.exe, Pid: 22952, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ac158554-aa0e-45cd-82a6-e07ff7caabce.tmp, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: StoreDesktopExtension.exe, Pid: 15208, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 21140, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\401d44483c00cbf832531ee06b1ff1d7f8a5c686.tbres->(UTF-16LE), EstimatedImpact: 2%

2025-11-29T07:28:22.578 ProcessImageName: taskhostw.exe, Pid: 15860, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 3%

2025-11-29T07:28:22.578 ProcessImageName: StoreDesktopExtension.exe, Pid: 28496, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--kglcheck-.lnk, EstimatedImpact: 12%

2025-11-29T07:28:22.578 ProcessImageName: updater.exe, Pid: 4012, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: updater.exe, Pid: 24104, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\59332062-0403-47fa-8726-a62c76ad60c7.tmp, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-29T07:28:22.578 ProcessImageName: bdredline.exe, Pid: 3316, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\redline\bdredline.conf, EstimatedImpact: 0%

2025-11-29T07:39:32.009 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #418425, FileId: 0x500000007cab5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T07:42:06.261 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T07:52:06.067 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #418563, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T07:52:06.071 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #418564, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T07:52:16.073 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #418569, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T07:52:16.080 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #418570, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T07:54:32.852 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #418574, FileId: 0x140000000721af, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T07:57:11.249 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T08:09:33.469 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #418703, FileId: 0x7e00000003ac7c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T08:09:56.089 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #418835, FileId: 0x108000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T08:12:16.237 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T08:24:34.056 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #419295, FileId: 0x1600000007289b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T08:27:21.237 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T08:28:12.049 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\BEFE5FDC-1415-4A4E-8D23-7B428B3B7BE36f34.1dc610a18947755

2025-11-29T08:28:12.083 Verifying engine and signature files (source: 0) ...

2025-11-29T08:28:12.083 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30932278-4FDD-42FF-AEC2-1A8844F54626}\mpengine.dll] due to PPL.

2025-11-29T08:28:12.083 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30932278-4FDD-42FF-AEC2-1A8844F54626}\mpasbase.vdm] (file in cache)

2025-11-29T08:28:12.083 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30932278-4FDD-42FF-AEC2-1A8844F54626}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-29T08:28:12.095 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30932278-4FDD-42FF-AEC2-1A8844F54626}\mpasdlta.vdm]

2025-11-29T08:28:12.095 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30932278-4FDD-42FF-AEC2-1A8844F54626}\mpavbase.vdm] (file in cache)

2025-11-29T08:28:12.095 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30932278-4FDD-42FF-AEC2-1A8844F54626}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-29T08:28:12.105 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30932278-4FDD-42FF-AEC2-1A8844F54626}\mpavdlta.vdm]

2025-11-29T08:28:12.178 [Engine] IsHybridMode: 0

2025-11-29T08:28:12.178 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-29T08:28:12.189 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-ADA385C65D82BD34AE99E1F25D7B3A4DB5F649F8.bin): 0x00000002

2025-11-29T08:28:12.191 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-ADA385C65D82BD34AE99E1F25D7B3A4DB5F649F8.bin)

2025-11-29T08:28:12.191 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-29T08:28:12.191 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-29T08:28:12.191 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-29T08:28:12.191 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-29T08:28:17.700 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-29T08:28:17.701 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-29T08:28:17.706 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7225A660, lRefCount: 5, hr=0

2025-11-29T08:28:17.706 [Engine] New active engine 00007FFE6F7CA660 replacing engine 00007FFE7225A660. Number of active engines: 2

2025-11-29T08:28:17.713 EngineInit:Global ASOC is enabled

2025-11-29T08:28:17.713 EngineInit:ASOO is enabled for developer volumes

2025-11-29T08:28:17.744 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-29T08:28:17.745 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.745 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-29T08:28:17.746 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-29T08:28:17.746 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-29T08:28:17.746 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.746 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.747 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.747 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-29T08:28:17.747 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.747 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.748 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-29T08:28:17.748 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.748 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.749 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.749 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.750 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.750 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.750 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T08:28:17.750 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\600323d6a0b82a027026391ac362e3a2f8b56c6a

Dynamic Signature Compilation Timestamp:11-28-2025 07:01:04

Persistence Type:Duration

Time remaining:864000000

2025-11-29T08:28:17.751 Dynamic signature dropped

2025-11-29T08:28:17.752 MpWriteUupSignatureVersion 1.441.578.0, hr = 0

2025-11-29T08:28:17.753 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-29T08:28:17.766 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-29T08:28:17.767 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-29T08:28:17.767 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-29T08:28:17.767 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-29T08:28:17.767 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-29T08:28:17.782 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-29T08:28:17.782 [Plugin] Initializing RTP plugin state...

2025-11-29T08:28:17.782 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-29T08:28:17.782 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 28 - 2025 20:28:22

Last Perf: 11 - 28 - 2025 20:28:22

First RTP Scan: 11 - 28 - 2025 20:28:23

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1676

  Misses:9893

BM Queue:0,105,0

  Proc:0,40,0

  File:0,105,0

Plugin Queue:0,1,0

  Threat:0,1,0

  Susp:0,1,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:419470

  Pending:0

  RegSize:306586

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:-1527909716

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:21

  TotalStreamCon:32867

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:2565476

   TotalHits:3287408

   InstanceCacheInserts:149906

   InstanceCacheUpdates:0

   InstanceCacheDeletes:122916

   InstanceCacheHits:5268

   InstanceCacheMisses:564791

   InstanceCacheOverflows:10504

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (1198/1565)

   Success: 1565, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-29T08:28:17.782 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30932278-4FDD-42FF-AEC2-1A8844F54626}

2025-11-29T08:28:17.782 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D1DC849E-4D5A-47D1-B6B1-80F52BFF982C}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D1DC849E-4D5A-47D1-B6B1-80F52BFF982C}\mpasbase.vdm in use, hr=0x80070020

2025-11-29T08:28:17.782 [SCC][CID=377344953_22456] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-29T08:28:17.783 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-29T08:28:17.783 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-29T08:28:17.783 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-29T08:28:17.783 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-29T08:28:17.784 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-29T08:28:17.784 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-29-2025 08:28:17

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-29-2025 08:28:17

2025-11-29T08:28:17.786 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-29T08:28:17.786 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-29T08:28:17.787 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-29T08:28:17.787 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-29-2025 08:28:17

END TDT(U) telemetry



2025-11-29T08:28:17.789 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T08:28:17.790 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-29T08:28:17.790 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-29T08:28:17.790 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-29T08:28:17.790 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-29T08:28:17.790 MdCoreSvc is supported in this platform and OS

Signature updated on 11-29-2025 08:28:17

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.578.0

AV Signature Version: 1.441.578.0

************************************************************

2025-11-29T08:28:17.792 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-29T08:28:17.792 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\BEFE5FDC-1415-4A4E-8D23-7B428B3B7BE36f34.1dc610a18947755

2025-11-29T08:28:17.805 Process scan (postsignatureupdatescan) started.

2025-11-29T08:28:17.832 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-29T08:28:17.833 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-29T08:28:17.966 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-29T08:28:17.966 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-29T08:28:17.966 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-29T08:28:17.966 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-29T08:28:17.966 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-29T08:28:17.967 [Engine] Engine 00007FFE7225A660 no longer in use. Number of active engines: 1

2025-11-29T08:28:17.967 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-29T08:28:17.967 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-29T08:28:18.114 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 19036, Count: 1591, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume4\xampp\sendmail\sendmail.exe, EstimatedImpact: 0%

2025-11-29T08:28:18.114 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 5205, Count: 549, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\a4d0344c-ed1a-4f39-9008-41fc9cfacd38.tmp, EstimatedImpact: 0%

2025-11-29T08:28:18.114 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4536, Count: 371, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\93d466bc-47fc-466d-9517-0610cc340ce2.tmp, EstimatedImpact: 0%

2025-11-29T08:28:18.114 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 3022, Count: 164, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 0%

2025-11-29T08:28:18.114 ProcessImageName: RuntimeBroker.exe, Pid: 12368, TotalTime: 527, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 29%

2025-11-29T08:28:18.114 ProcessImageName: RuntimeBroker.exe, Pid: 17648, TotalTime: 496, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 27%

2025-11-29T08:28:18.114 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 435, Count: 78, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-29T08:28:18.114 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 435, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T08:28:18.114 ProcessImageName: WmiPrvSE.exe, Pid: 19256, TotalTime: 360, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\wstorvsp.inf, EstimatedImpact: 33%

2025-11-29T08:28:18.114 ProcessImageName: DeviceCensus.exe, Pid: 28836, TotalTime: 356, Count: 14, MaxTime: 296, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 10%

2025-11-29T08:28:18.114 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 330, Count: 97, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-11-29T08:28:18.114 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 300, Count: 59, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-29T08:28:18.114 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 270, Count: 55, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-29T08:28:18.115 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 255, Count: 83, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\532001fc78e4e796.customDestinations-ms, EstimatedImpact: 0%

2025-11-29T08:28:18.115 ProcessImageName: taskhostw.exe, Pid: 3952, TotalTime: 225, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 13%

2025-11-29T08:28:18.115 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 185, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-29T08:28:18.132 [Engine] RSIG_UNLOADENGINE, 00007FFE7225A660, err=0x0

2025-11-29T08:28:18.150 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D1DC849E-4D5A-47D1-B6B1-80F52BFF982C} removed

2025-11-29T08:28:18.282 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-29T08:28:18.289 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-29T08:28:18.289 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-29T08:28:18.289 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-29T08:28:18.289 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-29T08:28:18.289 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-29T08:28:18.289 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-29T08:28:18.293 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-29T08:28:18.293 [RTP] Duplicating the current plugin configuration object...

2025-11-29T08:28:18.293 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-29T08:28:18.293 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-29T08:28:18.293 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-29T08:28:18.293 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-29T08:28:18.293 [RTP] No config change detected. Not updating plugin configuration.

2025-11-29T08:28:18.293 [RTP] No config changes found. No configuration switch.

2025-11-29T08:28:18.293 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-29T08:28:18.293 [RTP] Duplicating the current plugin configuration object...

2025-11-29T08:28:18.293 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-29T08:28:18.293 [RTP] Updating plugin configuration due to recent config changes (0x2) ...

2025-11-29T08:28:18.293 [RTP] No config change detected. Not updating plugin configuration.

2025-11-29T08:28:18.293 [RTP] No config changes found. No configuration switch.

2025-11-29T08:28:18.293 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0

2025-11-29T08:28:18.293 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-29T08:28:18.293 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-29T08:28:18.293 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-29T08:28:18.293 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-29T08:28:18.293 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-29T08:28:18.294 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-29T08:28:18.294 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-29T08:28:18.294 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-29T08:28:18.294 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-29T08:28:18.294 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-29T08:28:18.294 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-29T08:28:18.294 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-29T08:28:18.294 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-29T08:28:18.294 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-29T08:28:18.294 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-29T08:28:18.294 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-29T08:28:18.294 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T08:28:18.296 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T08:28:18.297 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T08:28:18.299 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T08:28:18.300 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T08:28:18.301 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 63062409(ms) from now at 02:59 (01:59 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-29T08:28:19.802 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-29T08:28:19.806 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-29T08:28:19.807 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-29T08:28:20.829 [RTP] Duplicating the current plugin configuration object...

2025-11-29T08:28:20.829 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-29T08:28:20.829 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-29T08:28:20.829 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-29T08:28:20.829 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157ED7C270CE, sigsha=5eded354160aa060b3f2a16db0725661264de9cd, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF9518016, sigsha=8fa60ffaf004b3696b5767c35f78f1425d04eb09, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0xa85b3f00

2025-11-29T08:28:23.100 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-29T08:28:23.100 [Cloud] Start of cloud request. Passive mode: 0

2025-11-29T08:28:23.100 [Cloud] Queued cloud request.

2025-11-29T08:28:23.100 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-29T08:28:23.100 [Cloud] Dequeued cloud request.

2025-11-29T08:28:23.100 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\45a4841411dd2583c0abb7809d7473933a4902bd

Dynamic Signature Compilation Timestamp:11-29-2025 08:28:23

Persistence Type:Duration

Time remaining:864000000

2025-11-29T08:28:23.319 Dynamic signature received

2025-11-29T08:28:23.319 [Cloud] End of cloud request.

2025-11-29T08:28:23.320 RTSD:RTSD recieved, rescanning impacted resources

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-29T08:28:23.830 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T08:28:33.271 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-29T08:28:33.271 Process scan (postsignatureupdatescan) completed.

2025-11-29T08:28:33.280 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-29T08:28:34.569 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-29T08:28:34.570 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-29T08:28:36.619 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext)

2025-11-29T08:28:36.619 [Cloud] Start of cloud request. Passive mode: 0

2025-11-29T08:28:36.619 [Cloud] Queued cloud request.

2025-11-29T08:28:36.619 [Cloud] Dequeued cloud request.

2025-11-29T08:28:36.641 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-29T08:28:36.697 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-29T08:28:36.697 [Cloud] End of cloud request.

2025-11-29T08:28:37.206 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T08:33:17.733 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-29T08:39:34.506 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #419561, FileId: 0x5b00000003b237, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T08:42:26.234 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T08:52:07.102 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #419813, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T08:52:07.105 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #419814, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T08:52:17.102 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #419820, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T08:52:17.107 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #419821, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T08:54:35.174 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #419829, FileId: 0x500000007cb5d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T08:57:31.226 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T09:09:35.686 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #419960, FileId: 0x500000007cbb9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T09:12:36.220 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T09:24:36.324 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #420522, FileId: 0x500000007cc8f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T09:27:41.223 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T09:39:36.880 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #420620, FileId: 0x4300000007ccf1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T09:42:46.221 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T09:45:41.184 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #420782, FileId: 0xcd00000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T09:52:07.187 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #420828, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T09:52:07.191 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #420829, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T09:52:17.199 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #420838, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T09:52:17.202 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #420839, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T09:52:17.203 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #420840, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T09:54:37.702 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #420850, FileId: 0xe00000007cd77, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T09:57:51.208 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T10:09:38.368 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #421100, FileId: 0x4700000007cdf0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T10:12:56.207 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T10:23:39.447 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T10:24:38.681 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #421367, FileId: 0x1200000007ce8b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T10:28:01.208 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T10:28:17.683 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 855, Count: 84, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\a0c0946f-2b2c-4179-a291-6665e1f23a19.tmp, EstimatedImpact: 0%

2025-11-29T10:28:17.683 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 660, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\b344bc8f-004c-4d57-a593-34369e129953.tmp, EstimatedImpact: 0%

2025-11-29T10:28:17.683 ProcessImageName: RuntimeBroker.exe, Pid: 29256, TotalTime: 526, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-29T10:28:17.683 ProcessImageName: taskhostw.exe, Pid: 19356, TotalTime: 300, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 16%

2025-11-29T10:28:17.683 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 135, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T10:28:17.683 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-29T10:28:17.683 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-29T10:28:17.683 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-29T10:28:17.683 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-29T10:28:17.683 ProcessImageName: HxTsr.exe, Pid: 29536, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 23%

2025-11-29T10:28:17.683 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-29T10:28:17.683 ProcessImageName: StoreDesktopExtension.exe, Pid: 25920, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-29T10:28:17.683 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\c391e315-cef1-4612-b44c-0e17e749d8ce.tmp, EstimatedImpact: 0%

2025-11-29T10:28:17.683 ProcessImageName: updater.exe, Pid: 29252, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\003ea419-0d22-472e-9d3b-a377661113f5.tmp, EstimatedImpact: 0%

2025-11-29T10:28:17.683 ProcessImageName: updater.exe, Pid: 21940, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\63975ad7-1a32-4d57-b5a2-ee809308a243.tmp, EstimatedImpact: 0%

2025-11-29T10:39:39.409 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #421471, FileId: 0x500000007cf05, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T10:43:06.196 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T10:52:07.575 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #421585, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T10:52:07.578 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #421586, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T10:52:17.586 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #421591, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T10:52:17.590 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #421592, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T10:54:39.967 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #421600, FileId: 0x1300000007cf8e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T10:58:11.195 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T11:09:40.399 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #421816, FileId: 0xd00000007d01f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T11:13:16.183 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T11:24:40.889 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #422025, FileId: 0x500000007d0ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T11:28:21.177 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T11:39:41.554 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #422104, FileId: 0x500000007d14b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T11:43:26.181 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T11:52:06.999 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #422387, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T11:52:07.001 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #422388, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T11:52:17.002 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #422395, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T11:52:17.005 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #422396, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T11:54:41.967 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #422403, FileId: 0x600000007d1de, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T11:58:31.170 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T12:09:42.573 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #422507, FileId: 0x18000000024c6f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T12:13:36.166 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T12:23:41.567 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T12:24:42.894 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #422709, FileId: 0x500000007d300, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T12:28:17.658 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1712, Count: 170, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\4158a338-f45b-4487-abd5-303f2232ce3d.tmp, EstimatedImpact: 0%

2025-11-29T12:28:17.658 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1321, Count: 108, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\18cef9b6-06ae-407e-9f9c-95b917e78aa8.tmp, EstimatedImpact: 0%

2025-11-29T12:28:17.658 ProcessImageName: RuntimeBroker.exe, Pid: 29256, TotalTime: 526, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-29T12:28:17.658 ProcessImageName: taskhostw.exe, Pid: 19356, TotalTime: 300, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 16%

2025-11-29T12:28:17.658 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 195, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T12:28:17.658 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-29T12:28:17.658 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 75, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-29T12:28:17.658 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 75, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-29T12:28:17.658 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-29T12:28:17.658 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-29T12:28:17.658 ProcessImageName: taskhostw.exe, Pid: 29264, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-29T12:28:17.658 ProcessImageName: HxTsr.exe, Pid: 29536, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 23%

2025-11-29T12:28:17.658 ProcessImageName: StoreDesktopExtension.exe, Pid: 25920, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-29T12:28:17.658 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\c391e315-cef1-4612-b44c-0e17e749d8ce.tmp, EstimatedImpact: 0%

2025-11-29T12:28:17.658 ProcessImageName: updater.exe, Pid: 29252, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\003ea419-0d22-472e-9d3b-a377661113f5.tmp, EstimatedImpact: 0%

2025-11-29T12:28:17.658 ProcessImageName: updater.exe, Pid: 21940, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\63975ad7-1a32-4d57-b5a2-ee809308a243.tmp, EstimatedImpact: 0%

2025-11-29T12:28:41.166 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T12:39:43.472 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #422802, FileId: 0x13b000000003bde, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T12:43:46.168 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T12:52:07.767 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #423389, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T12:52:07.771 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #423390, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T12:52:17.771 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #423397, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T12:52:17.774 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #423398, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T12:54:43.867 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #423407, FileId: 0x165000000001e40, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T12:58:51.148 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T13:09:44.713 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #423570, FileId: 0x1900000005610c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T13:13:56.146 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T13:24:44.988 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #423798, FileId: 0x500000007d521, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T13:29:01.141 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T13:39:45.533 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #423902, FileId: 0x7a000000009209, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T13:44:06.141 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T13:52:07.092 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #424052, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T13:52:07.098 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #424053, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T13:52:17.100 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #424060, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T13:52:17.104 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #424061, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T13:54:46.340 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #424082, FileId: 0x500000007d68a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T13:59:11.145 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T14:09:46.840 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #424391, FileId: 0x500000007d746, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T14:09:56.042 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #424446, FileId: 0x109000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T14:14:16.136 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T14:23:43.492 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T14:24:47.825 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #424540, FileId: 0x600000007d7f3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T14:28:17.633 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2447, Count: 257, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\4158a338-f45b-4487-abd5-303f2232ce3d.tmp, EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2011, Count: 162, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\18cef9b6-06ae-407e-9f9c-95b917e78aa8.tmp, EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1502, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 85%

2025-11-29T14:28:17.633 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 646, Count: 125, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 40%

2025-11-29T14:28:17.633 ProcessImageName: RuntimeBroker.exe, Pid: 29256, TotalTime: 526, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-29T14:28:17.633 ProcessImageName: taskhostw.exe, Pid: 19356, TotalTime: 300, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 16%

2025-11-29T14:28:17.633 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 240, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 120, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 105, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 105, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 90, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: taskhostw.exe, Pid: 29264, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-29T14:28:17.633 ProcessImageName: HxTsr.exe, Pid: 29536, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 23%

2025-11-29T14:28:17.633 ProcessImageName: taskhostw.exe, Pid: 30436, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-29T14:28:17.633 ProcessImageName: StoreDesktopExtension.exe, Pid: 25920, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: taskhostw.exe, Pid: 29556, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 27%

2025-11-29T14:28:17.633 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\c391e315-cef1-4612-b44c-0e17e749d8ce.tmp, EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0D1686C3FBB7F7352C5A7B6BA00CB0A6, EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: updater.exe, Pid: 29252, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\003ea419-0d22-472e-9d3b-a377661113f5.tmp, EstimatedImpact: 0%

2025-11-29T14:28:17.633 ProcessImageName: updater.exe, Pid: 21940, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\63975ad7-1a32-4d57-b5a2-ee809308a243.tmp, EstimatedImpact: 0%

2025-11-29T14:29:21.131 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T14:39:48.259 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #424654, FileId: 0x700000007d5e3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T14:44:26.125 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T14:52:06.763 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #424736, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T14:52:06.766 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #424737, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T14:52:16.770 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #424742, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T14:52:16.771 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #424743, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T14:52:16.774 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #424744, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T14:52:16.775 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #424745, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T14:54:49.225 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #424754, FileId: 0x20500000007d8a1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T14:59:31.123 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T15:09:49.750 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #425197, FileId: 0x800000007d68b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T15:14:36.116 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T15:24:50.278 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #425296, FileId: 0x1300000007db3d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T15:29:41.117 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T15:39:51.328 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #425683, FileId: 0x900000007d9e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T15:41:10.118 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume4\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #425774, FileId: 0x3700000001d190, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T15:44:46.110 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T15:52:06.312 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #425946, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T15:52:06.315 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #425947, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T15:52:16.326 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #425956, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T15:52:16.330 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #425957, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T15:54:51.871 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #425978, FileId: 0xa00000007dc66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T15:59:51.095 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T16:09:52.501 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #426272, FileId: 0x1500000007dd1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T16:14:56.098 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T16:23:45.593 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T16:24:53.282 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #426383, FileId: 0x1100000007ddd2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T16:28:17.599 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3183, Count: 344, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\4158a338-f45b-4487-abd5-303f2232ce3d.tmp, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2642, Count: 215, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\18cef9b6-06ae-407e-9f9c-95b917e78aa8.tmp, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1502, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 85%

2025-11-29T16:28:17.599 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 646, Count: 125, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 40%

2025-11-29T16:28:17.599 ProcessImageName: RuntimeBroker.exe, Pid: 29256, TotalTime: 526, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-29T16:28:17.599 ProcessImageName: taskhostw.exe, Pid: 19356, TotalTime: 300, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 16%

2025-11-29T16:28:17.599 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 300, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 165, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 135, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 135, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: ngentask.exe, Pid: 23788, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 16%

2025-11-29T16:28:17.599 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 120, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: ngentask.exe, Pid: 30136, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-29T16:28:17.599 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: ngentask.exe, Pid: 27716, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 14%

2025-11-29T16:28:17.599 ProcessImageName: ngentask.exe, Pid: 12932, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 55%

2025-11-29T16:28:17.599 ProcessImageName: ngentask.exe, Pid: 28724, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 34%

2025-11-29T16:28:17.599 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\c391e315-cef1-4612-b44c-0e17e749d8ce.tmp, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: ngentask.exe, Pid: 7620, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 10%

2025-11-29T16:28:17.599 ProcessImageName: taskhostw.exe, Pid: 29264, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-29T16:28:17.599 ProcessImageName: taskhostw.exe, Pid: 28892, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\BTHUSB.SYS, EstimatedImpact: 2%

2025-11-29T16:28:17.599 ProcessImageName: HxTsr.exe, Pid: 29536, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 23%

2025-11-29T16:28:17.599 ProcessImageName: taskhostw.exe, Pid: 29556, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 27%

2025-11-29T16:28:17.599 ProcessImageName: taskhostw.exe, Pid: 30436, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-29T16:28:17.599 ProcessImageName: StoreDesktopExtension.exe, Pid: 25920, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: taskhostw.exe, Pid: 29156, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-29T16:28:17.599 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0D1686C3FBB7F7352C5A7B6BA00CB0A6, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: updater.exe, Pid: 29252, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\003ea419-0d22-472e-9d3b-a377661113f5.tmp, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: updater.exe, Pid: 21940, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\63975ad7-1a32-4d57-b5a2-ee809308a243.tmp, EstimatedImpact: 0%

2025-11-29T16:28:17.599 ProcessImageName: updater.exe, Pid: 28964, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ca79e0d7-6c2e-4afe-9231-553ba72c3c09.tmp, EstimatedImpact: 0%

2025-11-29T16:30:01.092 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T16:39:54.003 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #426452, FileId: 0xc00000007dc2a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T16:45:06.094 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T16:52:07.589 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #426546, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T16:52:07.592 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #426547, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T16:52:17.592 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #426552, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T16:52:17.596 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #426553, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T16:54:55.008 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #426585, FileId: 0x1500000007df99, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T17:00:11.089 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T17:09:55.936 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #426824, FileId: 0x800000007e07c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T17:15:16.077 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T17:18:50.870 Bm signature throttled:0x00002db31bed458f

2025-11-29T17:24:56.619 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #427377, FileId: 0xd00000007e158, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T17:30:21.067 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T17:39:57.372 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #427642, FileId: 0xd00000007e9e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T17:45:26.072 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T17:52:07.499 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #428416, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T17:52:07.503 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #428417, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T17:52:17.501 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #428424, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T17:52:17.505 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #428425, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T17:54:58.172 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #429227, FileId: 0xc00000007f306, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T18:00:31.065 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T18:01:37.234 Bm signature throttled:0x00002db31bed458f

2025-11-29T18:09:58.787 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #429498, FileId: 0x700000007fcd6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T18:15:36.058 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T18:23:47.460 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T18:24:59.683 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #429634, FileId: 0x70000000806fc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T18:28:17.574 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3978, Count: 432, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\4158a338-f45b-4487-abd5-303f2232ce3d.tmp, EstimatedImpact: 0%

2025-11-29T18:28:17.574 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3303, Count: 268, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\18cef9b6-06ae-407e-9f9c-95b917e78aa8.tmp, EstimatedImpact: 0%

2025-11-29T18:28:17.574 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1700, Count: 207, MaxTime: 421, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\ffprobe.exe, EstimatedImpact: 0%

2025-11-29T18:28:17.574 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1502, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 85%

2025-11-29T18:28:17.575 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1381, Count: 202, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\c22240d10e740a82102fd50f7dc1099334779849f9064b86d4a7a082ff23e813\Ontology64.dll, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 646, Count: 125, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 40%

2025-11-29T18:28:17.575 ProcessImageName: RuntimeBroker.exe, Pid: 29256, TotalTime: 526, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-29T18:28:17.575 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 360, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: taskhostw.exe, Pid: 19356, TotalTime: 300, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 16%

2025-11-29T18:28:17.575 ProcessImageName: WmiPrvSE.exe, Pid: 29560, TotalTime: 276, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 82%

2025-11-29T18:28:17.575 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 225, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 180, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 150, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 135, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: ngentask.exe, Pid: 23788, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 16%

2025-11-29T18:28:17.575 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: ngentask.exe, Pid: 30136, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-29T18:28:17.575 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: ngentask.exe, Pid: 27716, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 14%

2025-11-29T18:28:17.575 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\c391e315-cef1-4612-b44c-0e17e749d8ce.tmp, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: ngentask.exe, Pid: 12932, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 55%

2025-11-29T18:28:17.575 ProcessImageName: ngentask.exe, Pid: 28724, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 34%

2025-11-29T18:28:17.575 ProcessImageName: ngentask.exe, Pid: 7620, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 10%

2025-11-29T18:28:17.575 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 20%

2025-11-29T18:28:17.575 ProcessImageName: taskhostw.exe, Pid: 29264, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-29T18:28:17.575 ProcessImageName: taskhostw.exe, Pid: 28892, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\BTHUSB.SYS, EstimatedImpact: 2%

2025-11-29T18:28:17.575 ProcessImageName: HxTsr.exe, Pid: 29536, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 23%

2025-11-29T18:28:17.575 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 30, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0D1686C3FBB7F7352C5A7B6BA00CB0A6, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: taskhostw.exe, Pid: 30436, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-29T18:28:17.575 ProcessImageName: taskhostw.exe, Pid: 29556, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 27%

2025-11-29T18:28:17.575 ProcessImageName: StoreDesktopExtension.exe, Pid: 25920, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: taskhostw.exe, Pid: 29156, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-29T18:28:17.575 ProcessImageName: nvngx_update.exe, Pid: 1748, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 5%

2025-11-29T18:28:17.575 ProcessImageName: taskhostw.exe, Pid: 30260, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 14%

2025-11-29T18:28:17.575 ProcessImageName: updater.exe, Pid: 29252, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\003ea419-0d22-472e-9d3b-a377661113f5.tmp, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: steamwebhelper.exe, Pid: 16236, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Steam\htmlcache\Network\5089b7d2-3f39-436c-81b7-d11872f7ea5f.tmp, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NvProfileUpdaterPlugin\drs\metadata.json, EstimatedImpact: 1%

2025-11-29T18:28:17.575 ProcessImageName: nvngx_update.exe, Pid: 18728, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: updater.exe, Pid: 28964, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ca79e0d7-6c2e-4afe-9231-553ba72c3c09.tmp, EstimatedImpact: 0%

2025-11-29T18:28:17.575 ProcessImageName: updater.exe, Pid: 21940, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\63975ad7-1a32-4d57-b5a2-ee809308a243.tmp, EstimatedImpact: 0%

2025-11-29T18:30:41.053 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T18:40:00.124 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #430094, FileId: 0x7000000080feb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T18:45:46.048 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T18:52:06.534 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #430216, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T18:52:06.537 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #430217, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T18:52:16.534 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #430223, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T18:52:16.538 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #430224, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T18:55:00.576 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #430252, FileId: 0x70000000818ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T19:00:51.044 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T19:10:00.888 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #430698, FileId: 0xc00000008214f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T19:15:56.039 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T19:25:00.974 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #430783, FileId: 0x7000000082a2a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T19:31:01.034 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T19:40:01.448 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #430932, FileId: 0x8000000083326, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T19:46:06.024 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T19:52:08.035 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #431092, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T19:52:08.038 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #431093, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T19:52:18.043 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #431101, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T19:52:18.046 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #431102, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T19:52:18.046 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #431103, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T20:01:11.022 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T20:16:16.018 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T20:23:15.124 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T20:28:17.545 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 4789, Count: 520, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\4158a338-f45b-4487-abd5-303f2232ce3d.tmp, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3994, Count: 320, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\18cef9b6-06ae-407e-9f9c-95b917e78aa8.tmp, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1700, Count: 207, MaxTime: 421, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\ffprobe.exe, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1502, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 85%

2025-11-29T20:28:17.545 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1381, Count: 203, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\c22240d10e740a82102fd50f7dc1099334779849f9064b86d4a7a082ff23e813\Ontology64.dll, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 661, Count: 126, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: RuntimeBroker.exe, Pid: 29256, TotalTime: 526, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-29T20:28:17.545 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 405, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: taskhostw.exe, Pid: 19356, TotalTime: 300, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 16%

2025-11-29T20:28:17.545 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 285, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: WmiPrvSE.exe, Pid: 29560, TotalTime: 276, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 82%

2025-11-29T20:28:17.545 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 210, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 180, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 150, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: ngentask.exe, Pid: 23788, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 16%

2025-11-29T20:28:17.545 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: ngentask.exe, Pid: 30136, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 11%

2025-11-29T20:28:17.545 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\c391e315-cef1-4612-b44c-0e17e749d8ce.tmp, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: ngentask.exe, Pid: 27716, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 14%

2025-11-29T20:28:17.545 ProcessImageName: ngentask.exe, Pid: 12932, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 55%

2025-11-29T20:28:17.545 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 60, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0D1686C3FBB7F7352C5A7B6BA00CB0A6, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: ngentask.exe, Pid: 28724, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 34%

2025-11-29T20:28:17.545 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 45, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: ngentask.exe, Pid: 7620, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 10%

2025-11-29T20:28:17.545 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 20%

2025-11-29T20:28:17.545 ProcessImageName: taskhostw.exe, Pid: 29264, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-29T20:28:17.545 ProcessImageName: taskhostw.exe, Pid: 28892, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\BTHUSB.SYS, EstimatedImpact: 2%

2025-11-29T20:28:17.545 ProcessImageName: HxTsr.exe, Pid: 29536, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\apppatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 23%

2025-11-29T20:28:17.545 ProcessImageName: taskhostw.exe, Pid: 17304, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 5%

2025-11-29T20:28:17.545 ProcessImageName: taskhostw.exe, Pid: 29556, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 27%

2025-11-29T20:28:17.545 ProcessImageName: taskhostw.exe, Pid: 30436, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 18%

2025-11-29T20:28:17.545 ProcessImageName: taskhostw.exe, Pid: 29156, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 18%

2025-11-29T20:28:17.545 ProcessImageName: StoreDesktopExtension.exe, Pid: 25920, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\timezoneTypes.res, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: nvngx_update.exe, Pid: 1748, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 5%

2025-11-29T20:28:17.545 ProcessImageName: updater.exe, Pid: 29856, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\08b5e10a-eb32-444d-82a5-51b4ce9413a3.tmp, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: taskhostw.exe, Pid: 30260, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 14%

2025-11-29T20:28:17.545 ProcessImageName: updater.exe, Pid: 29252, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\003ea419-0d22-472e-9d3b-a377661113f5.tmp, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: steamwebhelper.exe, Pid: 16236, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Steam\htmlcache\Network\5089b7d2-3f39-436c-81b7-d11872f7ea5f.tmp, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NvProfileUpdaterPlugin\drs\metadata.json, EstimatedImpact: 1%

2025-11-29T20:28:17.545 ProcessImageName: updater.exe, Pid: 21940, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\63975ad7-1a32-4d57-b5a2-ee809308a243.tmp, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: nvngx_update.exe, Pid: 18728, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-29T20:28:17.545 ProcessImageName: updater.exe, Pid: 28964, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\ca79e0d7-6c2e-4afe-9231-553ba72c3c09.tmp, EstimatedImpact: 0%

2025-11-29T20:31:21.012 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T20:46:26.015 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T20:54:37.823 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T20:55:03.979 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #431986, FileId: 0x7000000084f1b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T21:01:31.001 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T21:16:35.992 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T21:28:25.573 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\1604996B-3010-4D54-8F7F-88AED9F8DAEA6470.1dc6177179c1b6d

2025-11-29T21:28:25.604 Verifying engine and signature files (source: 0) ...

2025-11-29T21:28:25.604 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36D20956-4F88-47AA-8AEE-8E382BC4D2CD}\mpengine.dll] due to PPL.

2025-11-29T21:28:25.604 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36D20956-4F88-47AA-8AEE-8E382BC4D2CD}\mpasbase.vdm] (file in cache)

2025-11-29T21:28:25.604 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36D20956-4F88-47AA-8AEE-8E382BC4D2CD}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-29T21:28:25.614 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36D20956-4F88-47AA-8AEE-8E382BC4D2CD}\mpasdlta.vdm]

2025-11-29T21:28:25.614 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36D20956-4F88-47AA-8AEE-8E382BC4D2CD}\mpavbase.vdm] (file in cache)

2025-11-29T21:28:25.614 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36D20956-4F88-47AA-8AEE-8E382BC4D2CD}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-29T21:28:25.626 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36D20956-4F88-47AA-8AEE-8E382BC4D2CD}\mpavdlta.vdm]

2025-11-29T21:28:25.701 [Engine] IsHybridMode: 0

2025-11-29T21:28:25.702 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-29T21:28:25.711 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-9B5AB0D215DFDBF35E2D0281B51C3EC73DACD8B4.bin): 0x00000002

2025-11-29T21:28:25.712 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-9B5AB0D215DFDBF35E2D0281B51C3EC73DACD8B4.bin)

2025-11-29T21:28:25.712 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-29T21:28:25.712 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-29T21:28:25.712 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-29T21:28:25.712 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-29T21:28:31.273 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-29T21:28:31.273 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-29T21:28:31.279 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE6F7CA660, lRefCount: 5, hr=0

2025-11-29T21:28:31.280 [Engine] New active engine 00007FFE7225A660 replacing engine 00007FFE6F7CA660. Number of active engines: 2

2025-11-29T21:28:31.287 EngineInit:Global ASOC is enabled

2025-11-29T21:28:31.287 EngineInit:ASOO is enabled for developer volumes

2025-11-29T21:28:31.318 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-29T21:28:31.318 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-29T21:28:31.319 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2d9fe51e19761f881d22c6fc2367e9b402dc25f5

Dynamic Signature Compilation Timestamp:11-19-2025 14:09:46

Persistence Type:Duration

Time remaining:50065408

2025-11-29T21:28:31.320 Dynamic signature dropped

2025-11-29T21:28:31.321 MpWriteUupSignatureVersion 1.441.591.0, hr = 0

2025-11-29T21:28:31.322 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-29T21:28:31.334 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-29T21:28:31.336 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-29T21:28:31.336 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-29T21:28:31.336 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-29T21:28:31.336 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-29T21:28:31.350 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-29T21:28:31.350 [Plugin] Initializing RTP plugin state...

2025-11-29T21:28:31.350 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-29T21:28:31.350 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 29 - 2025 09:28:17

Last Perf: 11 - 29 - 2025 09:28:17

First RTP Scan: 11 - 29 - 2025 09:28:18

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1009

  Misses:10872

BM Queue:0,50,0

  Proc:0,42,0

  File:0,50,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:434802

  Pending:0

  RegSize:306586

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:-1339936344

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:21

  TotalStreamCon:28730

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:2693116

   TotalHits:3597960

   InstanceCacheInserts:154626

   InstanceCacheUpdates:0

   InstanceCacheDeletes:125028

   InstanceCacheHits:5405

   InstanceCacheMisses:594071

   InstanceCacheOverflows:10504

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (1154/1580)

   Success: 1580, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-29T21:28:31.350 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36D20956-4F88-47AA-8AEE-8E382BC4D2CD}

2025-11-29T21:28:31.351 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30932278-4FDD-42FF-AEC2-1A8844F54626}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30932278-4FDD-42FF-AEC2-1A8844F54626}\mpasbase.vdm in use, hr=0x80070020

2025-11-29T21:28:31.351 [SCC][CID=1136942578_29328] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-29T21:28:31.352 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-29T21:28:31.352 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-29T21:28:31.352 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-29T21:28:31.352 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-29T21:28:31.352 MdCoreSvc is supported in this platform and OS

2025-11-29T21:28:31.352 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-29-2025 21:28:31

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-29-2025 21:28:31

2025-11-29T21:28:31.355 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-29T21:28:31.355 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-29T21:28:31.356 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-29T21:28:31.356 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-29-2025 21:28:31

END TDT(U) telemetry



2025-11-29T21:28:31.358 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T21:28:31.358 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-29T21:28:31.358 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-29T21:28:31.358 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-29T21:28:31.358 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-29T21:28:31.359 MdCoreSvc is supported in this platform and OS

Signature updated on 11-29-2025 21:28:31

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.591.0

AV Signature Version: 1.441.591.0

************************************************************

2025-11-29T21:28:31.360 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-29T21:28:31.360 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\1604996B-3010-4D54-8F7F-88AED9F8DAEA6470.1dc6177179c1b6d

2025-11-29T21:28:31.369 Process scan (postsignatureupdatescan) started.

2025-11-29T21:28:31.400 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-29T21:28:31.401 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-29T21:28:31.534 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-29T21:28:31.534 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-29T21:28:31.534 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-29T21:28:31.534 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-29T21:28:31.534 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-29T21:28:31.535 [Engine] Engine 00007FFE6F7CA660 no longer in use. Number of active engines: 1

2025-11-29T21:28:31.535 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-29T21:28:31.535 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-29T21:28:31.705 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 5164, Count: 562, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\4158a338-f45b-4487-abd5-303f2232ce3d.tmp, EstimatedImpact: 0%

2025-11-29T21:28:31.705 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4294, Count: 347, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\18cef9b6-06ae-407e-9f9c-95b917e78aa8.tmp, EstimatedImpact: 0%

2025-11-29T21:28:31.705 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 1790, Count: 225, MaxTime: 421, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\ffprobe.exe, EstimatedImpact: 0%

2025-11-29T21:28:31.705 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1502, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 85%

2025-11-29T21:28:31.705 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1381, Count: 203, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA app\NvBackend\DAO\c22240d10e740a82102fd50f7dc1099334779849f9064b86d4a7a082ff23e813\Ontology64.dll, EstimatedImpact: 0%

2025-11-29T21:28:31.705 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 661, Count: 126, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\htdocs\tinyfilemanager.php, EstimatedImpact: 0%

2025-11-29T21:28:31.705 ProcessImageName: RuntimeBroker.exe, Pid: 29256, TotalTime: 526, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 28%

2025-11-29T21:28:31.705 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 435, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T21:28:31.705 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 360, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-29T21:28:31.705 ProcessImageName: taskhostw.exe, Pid: 19356, TotalTime: 300, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 16%

2025-11-29T21:28:31.705 ProcessImageName: WmiPrvSE.exe, Pid: 29560, TotalTime: 276, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\afd.sys, EstimatedImpact: 82%

2025-11-29T21:28:31.705 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 225, Count: 55, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-29T21:28:31.705 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 195, Count: 46, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\component_crx_cache\9d42e9a423abaad24665c97036f5833b322738038c28ab0625a825f588345a03, EstimatedImpact: 0%

2025-11-29T21:28:31.705 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 195, Count: 44, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-29T21:28:31.705 ProcessImageName: ngentask.exe, Pid: 23788, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 16%

2025-11-29T21:28:31.705 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 123, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-29T21:28:31.721 [Engine] RSIG_UNLOADENGINE, 00007FFE6F7CA660, err=0x0

2025-11-29T21:28:31.739 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30932278-4FDD-42FF-AEC2-1A8844F54626} removed

2025-11-29T21:28:31.844 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-29T21:28:31.851 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-29T21:28:31.851 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-29T21:28:31.851 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-29T21:28:31.851 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-29T21:28:31.851 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-29T21:28:31.851 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-29T21:28:31.854 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-29T21:28:31.854 [RTP] Duplicating the current plugin configuration object...

2025-11-29T21:28:31.854 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-29T21:28:31.854 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-29T21:28:31.854 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-29T21:28:31.854 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-29T21:28:31.854 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-29T21:28:31.854 [RTP] No config change detected. Not updating plugin configuration.

2025-11-29T21:28:31.854 [RTP] No config changes found. No configuration switch.

2025-11-29T21:28:31.854 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-29T21:28:31.854 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-29T21:28:31.855 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-29T21:28:31.855 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-29T21:28:31.855 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-29T21:28:31.855 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-29T21:28:31.855 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-29T21:28:31.855 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-29T21:28:31.855 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-29T21:28:31.855 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-29T21:28:31.855 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-29T21:28:31.855 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-29T21:28:31.855 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-29T21:28:31.855 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-29T21:28:31.855 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-29T21:28:31.855 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-29T21:28:31.856 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T21:28:31.857 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T21:28:31.859 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T21:28:31.860 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T21:28:31.862 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T21:28:31.863 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 17295190(ms) from now at 03:16 (02:16 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-29T21:28:33.366 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-29T21:28:33.369 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-29T21:28:33.370 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-29T21:28:34.389 [RTP] Duplicating the current plugin configuration object...

2025-11-29T21:28:34.389 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-29T21:28:34.389 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-29T21:28:34.389 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-29T21:28:34.389 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-29T21:28:45.312 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-29T21:28:45.312 Process scan (postsignatureupdatescan) completed.

2025-11-29T21:28:45.321 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-29T21:28:46.665 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-29T21:28:46.665 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-29T21:28:48.695 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext)

2025-11-29T21:28:48.695 [Cloud] Start of cloud request. Passive mode: 0

2025-11-29T21:28:48.695 [Cloud] Queued cloud request.

2025-11-29T21:28:48.695 [Cloud] Dequeued cloud request.

2025-11-29T21:28:48.718 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-29T21:28:48.863 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-29T21:28:48.863 [Cloud] End of cloud request.

2025-11-29T21:28:49.375 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-29T21:31:41.001 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T21:33:31.303 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-29T21:40:05.203 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #435926, FileId: 0xd000000088a54, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T21:46:45.986 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T21:52:06.379 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #437869, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T21:52:06.382 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #437870, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T21:52:16.379 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #437897, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T21:52:16.382 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #437898, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T21:52:16.403 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #437899, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T21:52:16.414 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #437900, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T21:55:05.324 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #438337, FileId: 0x1000000008ab72, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T22:01:50.980 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T22:10:05.345 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #440560, FileId: 0x2e00000008cd16, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T22:16:55.975 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T22:25:05.530 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #442603, FileId: 0xd00000008f1f9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T22:32:00.974 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T22:32:50.741 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\setup\logs\Install_2025-11-28_202313_29184-28024.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #443660, FileId: 0xd00000007b965, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T22:32:50.817 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T22:40:05.980 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #444573, FileId: 0xe0000000919cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T22:47:05.967 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T22:52:07.294 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #445483, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T22:52:07.298 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #445484, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T22:52:17.303 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #445506, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T22:52:17.307 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #445507, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T22:55:06.682 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #445535, FileId: 0xe000000093024, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T23:02:10.961 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T23:10:07.540 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #446050, FileId: 0x4600000008c83d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T23:17:15.956 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T23:25:08.081 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #446224, FileId: 0xe00000008e65c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T23:28:31.248 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1564, Count: 84, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys, EstimatedImpact: 83%

2025-11-29T23:28:31.248 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 975, Count: 83, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Cache\Cache_Data\f_0009ac, EstimatedImpact: 0%

2025-11-29T23:28:31.248 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 870, Count: 85, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\b9ab3b41-7365-4e5c-b16d-2b06a8e6c8e6.tmp, EstimatedImpact: 0%

2025-11-29T23:28:31.248 ProcessImageName: RuntimeBroker.exe, Pid: 17592, TotalTime: 618, Count: 21, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-29T23:28:31.248 ProcessImageName: taskhostw.exe, Pid: 29812, TotalTime: 196, Count: 42, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 8%

2025-11-29T23:28:31.248 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 180, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 22%

2025-11-29T23:28:31.248 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 150, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Data\e8\e8ad62c3b5281903cc40ddef9c43f0fac142f2ad.file, EstimatedImpact: 0%

2025-11-29T23:28:31.248 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\Public\Desktop\Google Chrome.lnk, EstimatedImpact: 69%

2025-11-29T23:28:31.248 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 17192, TotalTime: 120, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 2%

2025-11-29T23:28:31.248 ProcessImageName: backgroundTaskHost.exe, Pid: 29644, TotalTime: 105, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446, EstimatedImpact: 21%

2025-11-29T23:28:31.248 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 90, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 0%

2025-11-29T23:28:31.248 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-29T23:28:31.248 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 75, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-29T23:28:31.248 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-29T23:28:31.248 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-29T23:28:31.248 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-11-29T23:28:31.248 ProcessImageName: svchost.exe, Pid: 9528, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT3FDD.tmp, EstimatedImpact: 0%

2025-11-29T23:28:31.248 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 22896, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 2%

2025-11-29T23:28:31.248 ProcessImageName: StoreDesktopExtension.exe, Pid: 2396, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\zoneinfo64.res, EstimatedImpact: 0%

2025-11-29T23:28:31.248 ProcessImageName: updater.exe, Pid: 8688, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\f99b7bea-14ef-41fd-9e4a-e07b8d0bde90.tmp, EstimatedImpact: 0%

2025-11-29T23:28:31.248 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 0, Count: 6, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\OneDrive\Bilder\Camera Roll\20251129_230116.jpg, EstimatedImpact: 0%

2025-11-29T23:32:20.950 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T23:33:04.526 Bm signature throttled:0x0000fab3228bcd4d

2025-11-29T23:40:08.678 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #446389, FileId: 0xf00000008fe8b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T23:47:25.948 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-29T23:52:05.983 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #446544, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T23:52:05.985 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #446545, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T23:52:15.987 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #446553, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T23:52:15.990 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #446555, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-29T23:55:08.876 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #446583, FileId: 0xe000000091b87, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T00:02:30.951 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T00:10:09.414 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #446853, FileId: 0xe0000000932ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T00:17:05.951 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3

2025-11-30T00:17:05.958 Job Notification: New process added to job (27484)

2025-11-30T00:17:05.960 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched

2025-11-30T00:17:05.961 Aggressive catchup quick scan threshold: 4270406977919 / 25920000000000

2025-11-30T00:17:05.965 Job Notification: New process added to job (28932)

2025-11-30T00:17:05.972 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:27484] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:28932]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-30T00:17:06.022 Job Notification: New process added to job (29704)

2025-11-30T00:17:06.025 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched

2025-11-30T00:17:06.027 Job Notification: New process added to job (27060)

2025-11-30T00:17:06.034 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:29704] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:27060]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-11-30T00:17:06.078 Job Notification: New process added to job (27028)

2025-11-30T00:17:06.080 Task(GetDeviceTicket -AccessKey 61577A61-FBD3-7E31-8D23-D74D4AC9621E ) launched as network service

2025-11-30T00:17:06.471 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-30T00:17:06.471 [RTP] Duplicating the current plugin configuration object...

2025-11-30T00:17:06.471 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-30T00:17:06.471 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-30T00:17:06.471 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-30T00:17:06.471 [RTP] No config change detected. Not updating plugin configuration.

2025-11-30T00:17:06.471 [RTP] No config changes found. No configuration switch.

2025-11-30T00:17:06.471 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-30T00:17:06.642 Job Notification: Process exited from job (27028)

2025-11-30T00:17:06.838 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-30T00:17:06.838 [Cloud] Start of cloud request. Passive mode: 0

2025-11-30T00:17:06.838 [Cloud] Queued cloud request.

2025-11-30T00:17:06.838 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-30T00:17:06.839 [Cloud] Dequeued cloud request.

2025-11-30T00:17:06.839 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-30T00:17:06.839 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0

2025-11-30T00:17:06.839 [Cloud] Start of cloud request. Passive mode: 0

2025-11-30T00:17:06.839 [Cloud] Queued cloud request.

2025-11-30T00:17:06.839 [Cloud] Dequeued cloud request.

2025-11-30T00:17:06.840 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-30T00:17:06.955 [Cloud] End of cloud request.

2025-11-30T00:17:07.001 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-30T00:17:07.001 [Cloud] End of cloud request.

2025-11-30T00:17:07.356 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T00:17:19.632 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\2409B0AC-C89E-471C-9EB4-6B1D4CC36FC56ea4.1dc618eb0020275

2025-11-30T00:17:19.668 Verifying engine and signature files (source: 0) ...

2025-11-30T00:17:19.668 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D6713FD8-A8ED-4533-8C05-D3C4ED7F1423}\mpengine.dll] due to PPL.

2025-11-30T00:17:19.668 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D6713FD8-A8ED-4533-8C05-D3C4ED7F1423}\mpasbase.vdm] (file in cache)

2025-11-30T00:17:19.668 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D6713FD8-A8ED-4533-8C05-D3C4ED7F1423}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-30T00:17:19.679 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D6713FD8-A8ED-4533-8C05-D3C4ED7F1423}\mpasdlta.vdm]

2025-11-30T00:17:19.679 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D6713FD8-A8ED-4533-8C05-D3C4ED7F1423}\mpavbase.vdm] (file in cache)

2025-11-30T00:17:19.679 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D6713FD8-A8ED-4533-8C05-D3C4ED7F1423}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-30T00:17:19.690 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D6713FD8-A8ED-4533-8C05-D3C4ED7F1423}\mpavdlta.vdm]

2025-11-30T00:17:19.766 [Engine] IsHybridMode: 0

2025-11-30T00:17:19.766 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-30T00:17:19.777 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3BEC8E5A0214EC763C971958D5637CED452D8132.bin): 0x00000002

2025-11-30T00:17:19.780 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3BEC8E5A0214EC763C971958D5637CED452D8132.bin)

2025-11-30T00:17:19.780 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-30T00:17:19.780 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-30T00:17:19.780 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-30T00:17:19.780 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-30T00:17:25.187 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-30T00:17:25.187 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-30T00:17:25.191 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7225A660, lRefCount: 5, hr=0

2025-11-30T00:17:25.191 [Engine] New active engine 00007FFE4C3EA660 replacing engine 00007FFE7225A660. Number of active engines: 2

2025-11-30T00:17:25.194 EngineInit:Global ASOC is enabled

2025-11-30T00:17:25.194 EngineInit:ASOO is enabled for developer volumes

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.224 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.225 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.225 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.225 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.225 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.225 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.225 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T00:17:25.226 MpWriteUupSignatureVersion 1.441.594.0, hr = 0

2025-11-30T00:17:25.227 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-30T00:17:25.239 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-30T00:17:25.241 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-30T00:17:25.241 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-30T00:17:25.241 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-30T00:17:25.241 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-30T00:17:25.255 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-30T00:17:25.256 [Plugin] Initializing RTP plugin state...

2025-11-30T00:17:25.256 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-30T00:17:25.256 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 29 - 2025 22:28:31

Last Perf: 11 - 29 - 2025 22:28:31

First RTP Scan: 11 - 29 - 2025 22:28:31

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:624

  Misses:10510

BM Queue:0,73,0

  Proc:0,73,0

  File:0,13,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:447016

  Pending:0

  RegSize:306586

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:-1241254150

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:21

  TotalStreamCon:27912

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:2837878

   TotalHits:3674547

   InstanceCacheInserts:155776

   InstanceCacheUpdates:0

   InstanceCacheDeletes:129611

   InstanceCacheHits:5534

   InstanceCacheMisses:650449

   InstanceCacheOverflows:10504

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (289/404)

   Success: 404, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-30T00:17:25.256 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D6713FD8-A8ED-4533-8C05-D3C4ED7F1423}

2025-11-30T00:17:25.256 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36D20956-4F88-47AA-8AEE-8E382BC4D2CD}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36D20956-4F88-47AA-8AEE-8E382BC4D2CD}\mpasbase.vdm in use, hr=0x80070020

2025-11-30T00:17:25.256 [SCC][CID=1147076546_26000] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-30T00:17:25.257 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-30T00:17:25.257 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-30T00:17:25.257 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-30T00:17:25.257 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-30T00:17:25.257 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-30T00:17:25.258 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-30-2025 00:17:25

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-30-2025 00:17:25

2025-11-30T00:17:25.260 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-30T00:17:25.260 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-30-2025 00:17:25

END TDT(U) telemetry



2025-11-30T00:17:25.261 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-30T00:17:25.261 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0

2025-11-30T00:17:25.263 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T00:17:25.263 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-30T00:17:25.263 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-30T00:17:25.263 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-30T00:17:25.264 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-30T00:17:25.264 MdCoreSvc is supported in this platform and OS

Signature updated on 11-30-2025 00:17:25

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.594.0

AV Signature Version: 1.441.594.0

************************************************************

2025-11-30T00:17:25.265 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-30T00:17:25.265 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\2409B0AC-C89E-471C-9EB4-6B1D4CC36FC56ea4.1dc618eb0020275

2025-11-30T00:17:25.269 Process scan (postsignatureupdatescan) started.

2025-11-30T00:17:25.306 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-30T00:17:25.308 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

Signature updated via MicrosoftUpdateServer on 11-30-2025 00:17:25

************************************************************

2025-11-30T00:17:25.345 Job Notification: Process exited from job (29704)

2025-11-30T00:17:25.346 Job Notification: Process exited from job (27060)

2025-11-30T00:17:25.378 Job Notification: Process exited from job (27484)

2025-11-30T00:17:25.379 Job Notification: Process exited from job (28932)

2025-11-30T00:17:25.442 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-30T00:17:25.442 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-30T00:17:25.443 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-30T00:17:25.443 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-30T00:17:25.443 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-30T00:17:25.444 [Engine] Engine 00007FFE7225A660 no longer in use. Number of active engines: 1

2025-11-30T00:17:25.444 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-30T00:17:25.444 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-30T00:17:25.594 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1564, Count: 84, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys, EstimatedImpact: 83%

2025-11-30T00:17:25.594 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1276, Count: 106, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\3cf25ab0-f61f-4271-8739-546b77054aa9.tmp, EstimatedImpact: 0%

2025-11-30T00:17:25.594 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1275, Count: 120, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\b9ab3b41-7365-4e5c-b16d-2b06a8e6c8e6.tmp, EstimatedImpact: 0%

2025-11-30T00:17:25.594 ProcessImageName: RuntimeBroker.exe, Pid: 17592, TotalTime: 618, Count: 21, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 39%

2025-11-30T00:17:25.594 ProcessImageName: php-cgi.exe, Pid: 23520, TotalTime: 490, Count: 19, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\xampp\php\php8ts.dll, EstimatedImpact: 100%

2025-11-30T00:17:25.594 ProcessImageName: taskhostw.exe, Pid: 29812, TotalTime: 196, Count: 42, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 8%

2025-11-30T00:17:25.594 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 29184, TotalTime: 180, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 22%

2025-11-30T00:17:25.594 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 150, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Data\e8\e8ad62c3b5281903cc40ddef9c43f0fac142f2ad.file, EstimatedImpact: 0%

2025-11-30T00:17:25.594 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\Public\Desktop\Google Chrome.lnk, EstimatedImpact: 69%

2025-11-30T00:17:25.594 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 17192, TotalTime: 120, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 2%

2025-11-30T00:17:25.594 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T00:17:25.594 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 105, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 0%

2025-11-30T00:17:25.594 ProcessImageName: backgroundTaskHost.exe, Pid: 29644, TotalTime: 105, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446, EstimatedImpact: 21%

2025-11-30T00:17:25.594 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 75, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\system32\ctac.json, EstimatedImpact: 0%

2025-11-30T00:17:25.594 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0%

2025-11-30T00:17:25.594 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-30T00:17:25.608 [Engine] RSIG_UNLOADENGINE, 00007FFE7225A660, err=0x0

2025-11-30T00:17:25.623 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36D20956-4F88-47AA-8AEE-8E382BC4D2CD} removed

2025-11-30T00:17:25.750 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-30T00:17:25.758 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-30T00:17:25.758 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-30T00:17:25.758 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-30T00:17:25.759 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-30T00:17:25.759 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-30T00:17:25.759 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-30T00:17:25.762 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-30T00:17:25.762 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-30T00:17:25.762 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-30T00:17:25.762 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-30T00:17:25.762 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-30T00:17:25.762 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-30T00:17:25.762 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-30T00:17:25.762 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-30T00:17:25.762 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-30T00:17:25.762 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-30T00:17:25.762 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-30T00:17:25.762 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-30T00:17:25.762 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-30T00:17:25.762 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-30T00:17:25.762 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-30T00:17:25.762 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-30T00:17:25.763 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-30T00:17:25.763 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-30T00:17:25.765 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T00:17:25.766 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T00:17:25.767 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T00:17:25.769 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T00:17:25.771 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 8256110(ms) from now at 03:35 (02:35 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-30T00:17:25.771 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T00:17:27.272 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-30T00:17:27.276 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-30T00:17:27.277 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-30T00:17:28.300 [RTP] Duplicating the current plugin configuration object...

2025-11-30T00:17:28.300 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-30T00:17:28.300 [RTP] Updating plugin configuration due to recent config changes (0x42e) ...

2025-11-30T00:17:28.300 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-30T00:17:28.300 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-30T00:17:28.300 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x42e, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-30T00:17:35.947 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T00:17:39.041 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-30T00:17:39.041 Process scan (postsignatureupdatescan) completed.

2025-11-30T00:17:39.043 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-30T00:17:40.320 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-30T00:17:40.320 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-30T00:17:42.318 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext)

2025-11-30T00:17:42.318 [Cloud] Start of cloud request. Passive mode: 0

2025-11-30T00:17:42.318 [Cloud] Queued cloud request.

2025-11-30T00:17:42.318 [Cloud] Dequeued cloud request.

2025-11-30T00:17:42.340 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-30T00:17:42.395 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-30T00:17:42.396 [Cloud] End of cloud request.

2025-11-30T00:17:42.908 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T00:22:25.214 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-30T00:25:09.891 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #447095, FileId: 0x14000000090d20, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T00:32:40.944 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T00:40:11.361 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #447564, FileId: 0xe0000000937b9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T00:47:45.933 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T00:52:07.503 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #447787, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T00:52:07.506 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #447788, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T00:52:17.506 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #447794, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T00:52:17.509 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #447795, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T00:52:17.510 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #447796, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T00:55:11.684 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #447826, FileId: 0xd00000009386e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T01:02:50.935 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T01:10:11.926 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #448390, FileId: 0xd000000093929, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T01:17:55.924 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T01:25:12.497 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #448550, FileId: 0xe0000000939e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T01:33:00.921 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T01:33:06.547 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T01:39:46.459 [AutoPurge] Verification Routine tasks have started.

2025-11-30T01:39:46.459 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-30T01:39:46.463 [AutoPurge] Routine task for Cache Maintenance has started.

2025-11-30T01:39:46.463 [AutoPurge] Routine task for Cache Maintenance ...

2025-11-30T01:39:46.463 [AutoPurge] Routine task for MpSFCBuild ...

2025-11-30T01:39:46.463 [AutoPurge] MpCmIsBuildCompleted() - S_OK

2025-11-30T01:39:46.463 [AutoPurge] MpSignalMaintenanceMode ...

2025-11-30T01:39:46.463 [AutoPurge] Routine task for Cache Maintenance has ended.

2025-11-30T01:39:46.467 [AutoPurge] Cleanup Routine tasks have started.

2025-11-30T01:39:46.472 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0)

2025-11-30T01:39:46.472 [AutoPurge] Purged 0 expired detection item(s) from a total of 1.

2025-11-30T01:39:46.473 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds)

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:65538

Start time:11-30-2025 01:39:46

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-30-2025 01:39:46

2025-11-30T01:39:46.474 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:2A4D1A81-996A-4598-A393-13E0E0828BFE, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1)

2025-11-30T01:39:46.474 Scheduled scan with Id 2A4D1A81-996A-4598-A393-13E0E0828BFE configured CPU priority: normal (LowCpuPriority: 0)

2025-11-30T01:39:46.474 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ...

2025-11-30T01:39:46.475 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0 ...

2025-11-30T01:39:46.475 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0 ...

2025-11-30T01:39:46.475 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ...

2025-11-30T01:39:46.475 [AutoPurge] Cleanup Routine tasks have ended.

2025-11-30T01:39:46.475 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build.

2025-11-30T01:39:46.475 [SFC] System file cache build is not needed (already completed)

2025-11-30T01:39:46.476 QuickScan:ScanID:2A4D1A81-996A-4598-A393-13E0E0828BFE: Quick Scan skipped since it already ran during the past 7 days

2025-11-30T01:39:46.476 QuickScan:ScanID:2A4D1A81-996A-4598-A393-13E0E0828BFE: Quick scan finished with error 1223

2025-11-30T01:39:46.476 OnDemandScanWorker: Scan Cancelled! scanId:2A4D1A81-996A-4598-A393-13E0E0828BFE, hr = 0x80508018

!ERROR

Begin Quick Scan

Scan ID:{2A4D1A81-996A-4598-A393-13E0E0828BFE}

Scan Source:1

Start Time:11-30-2025 01:39:46

Unsuccessful Scan

Return Code:1223

************************************************************



2025-11-30T01:39:46.530 EnsureProtectedFolderAcls(), hr = 0x0

2025-11-30T01:39:46.533 [AutoPurge] MpReinforceServiceAcls: 0

2025-11-30T01:39:46.543 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0

2025-11-30T01:39:46.546 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed.

2025-11-30T01:39:46.547 [AutoPurge] Verification Routine tasks have ended.

2025-11-30T01:39:48.480 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-30T01:39:48.484 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-30T01:39:48.485 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-30T01:39:50.497 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-30T01:39:50.500 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-30T01:39:50.501 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-30T01:40:13.136 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #448729, FileId: 0xe0000000937c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T01:48:05.922 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T01:52:07.253 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #448867, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T01:52:07.256 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #448868, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T01:52:17.265 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #448875, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T01:52:17.269 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #448876, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T01:55:13.712 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #448905, FileId: 0xd000000093b44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T01:57:56.258 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #448985, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T02:03:10.912 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T02:07:06.429 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

2025-11-30T02:07:06.440 [DLP] DlpEngineConfigStorage::OnConfigChange DlpDwordSettingsMap:

2025-11-30T02:07:06.440 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-30T02:07:06.440 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-30T02:07:06.440 [RTP] Duplicating the current plugin configuration object...

2025-11-30T02:07:06.440 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-30T02:07:06.440 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-30T02:07:06.440 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-30T02:07:06.440 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-30T02:07:06.440 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-30T02:07:06.440 [RTP] No config change detected. Not updating plugin configuration.

2025-11-30T02:07:06.440 [RTP] No config changes found. No configuration switch.

2025-11-30T02:07:06.440 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-30T02:07:06.440 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-30T02:07:06.440 [RTP] [RtpConfig] Config change detected, type: 16

2025-11-30T02:07:06.440 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-30T02:07:06.440 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-30T02:07:06.440 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-30T02:07:06.440 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-30T02:07:06.440 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-30T02:07:06.441 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-30T02:07:06.441 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-30T02:07:06.441 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-30T02:07:06.441 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-30T02:07:06.441 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-30T02:07:06.441 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-30T02:07:06.441 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-30T02:07:06.441 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-30T02:07:06.441 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-30T02:07:06.441 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T02:07:06.443 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T02:07:06.444 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T02:07:06.446 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T02:07:06.447 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T02:07:06.448 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 4641752(ms) from now at 04:24 (03:24 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-30T02:07:08.993 [RTP] Duplicating the current plugin configuration object...

2025-11-30T02:07:08.993 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-30T02:07:08.993 [RTP] Updating plugin configuration due to recent config changes (0x41e) ...

2025-11-30T02:07:08.993 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-30T02:07:08.993 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x218

2025-11-30T02:10:13.963 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #449404, FileId: 0xd000000093bf8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T02:17:25.165 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 975, Count: 85, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\172896a9-9107-46a6-8e8b-6ed38b5c3b9a.tmp, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: RuntimeBroker.exe, Pid: 26052, TotalTime: 960, Count: 42, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 570, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\024eb9b0-6190-404d-bd4f-20eb46e8b114.tmp, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 225, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: taskhostw.exe, Pid: 30524, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 11%

2025-11-30T02:17:25.165 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 60, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\8b41c630-6785-42e0-bbcf-dc78cadbdfd7.tmp, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 30, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\9c3ae3a1-2c99-4224-aca8-f6bfe81bba05.tmp, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: updater.exe, Pid: 15088, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-30T02:17:25.165 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-30T02:18:15.900 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T02:25:14.654 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #449505, FileId: 0xd000000093cab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T02:33:20.897 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T02:40:15.230 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #450473, FileId: 0xe000000093d42, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T02:48:25.889 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T02:52:07.374 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #450588, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T02:52:07.377 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #450589, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T02:52:17.374 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #450594, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T02:52:17.378 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #450595, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T02:55:15.708 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #450607, FileId: 0x10000000093e14, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T03:03:30.895 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T03:10:16.211 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #450996, FileId: 0xd000000093ec4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T03:18:35.893 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T03:25:16.689 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #451083, FileId: 0xd000000093f7b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T03:33:08.608 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T03:33:40.885 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T03:40:17.432 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #451345, FileId: 0xd000000094005, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0xe20ed903

2025-11-30T03:48:45.872 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T03:52:07.043 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #451812, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T03:52:07.046 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #451813, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T03:52:17.049 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #451820, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T03:52:17.054 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #451821, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T03:55:17.863 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #451835, FileId: 0x3a00000005510e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T04:03:50.874 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T04:10:18.272 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #452130, FileId: 0xd000000094181, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T04:17:25.134 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1800, Count: 170, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\172896a9-9107-46a6-8e8b-6ed38b5c3b9a.tmp, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1470, Count: 83, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys, EstimatedImpact: 82%

2025-11-30T04:17:25.134 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1275, Count: 108, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\024eb9b0-6190-404d-bd4f-20eb46e8b114.tmp, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: RuntimeBroker.exe, Pid: 26052, TotalTime: 960, Count: 42, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 225, Count: 64, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: taskhostw.exe, Pid: 30524, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 11%

2025-11-30T04:17:25.134 ProcessImageName: taskhostw.exe, Pid: 28972, TotalTime: 195, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 8%

2025-11-30T04:17:25.134 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 150, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 139, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 125, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\DO4399.tmp, EstimatedImpact: 36%

2025-11-30T04:17:25.134 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 105, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 75, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 60, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\8b41c630-6785-42e0-bbcf-dc78cadbdfd7.tmp, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: DeviceCensus.exe, Pid: 29244, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3, EstimatedImpact: 1%

2025-11-30T04:17:25.134 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\9c3ae3a1-2c99-4224-aca8-f6bfe81bba05.tmp, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\oem20.PNF, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: StoreDesktopExtension.exe, Pid: 23224, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: svchost.exe, Pid: 18256, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\UUS\State\_active.uusver, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: updater.exe, Pid: 15088, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-30T04:17:25.134 ProcessImageName: updater.exe, Pid: 9500, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-30T04:18:55.874 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T04:25:18.954 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #452230, FileId: 0xe000000094241, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T04:34:00.864 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T04:40:19.184 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #452383, FileId: 0xb0000000942eb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T04:49:05.855 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T04:52:06.770 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #452495, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T04:52:06.773 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #452496, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T04:52:16.778 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #452501, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T04:52:16.782 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #452502, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T04:55:19.576 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #452526, FileId: 0xd0000000943a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T05:04:10.859 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T05:10:19.883 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #452824, FileId: 0xd000000094452, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T05:19:15.846 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T05:25:20.301 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #452924, FileId: 0xd000000094505, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T05:33:10.484 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T05:34:20.841 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T05:40:20.305 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #453130, FileId: 0xd0000000945b4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T05:49:25.847 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T05:52:05.097 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #453269, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T05:52:05.101 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #453270, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T05:52:15.101 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #453275, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T05:52:15.103 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #453276, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T05:52:15.105 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #453277, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T05:52:15.106 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #453278, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T05:55:20.736 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #453285, FileId: 0xd00000009466a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T06:04:30.837 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T06:10:21.426 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #453585, FileId: 0xd00000009471e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T06:17:25.102 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2611, Count: 253, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\4c334f03-e3ac-4753-8c04-db4367eb34d7.tmp, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1905, Count: 160, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\024eb9b0-6190-404d-bd4f-20eb46e8b114.tmp, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1470, Count: 83, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys, EstimatedImpact: 82%

2025-11-30T06:17:25.102 ProcessImageName: RuntimeBroker.exe, Pid: 26052, TotalTime: 960, Count: 42, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 255, Count: 72, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: taskhostw.exe, Pid: 30524, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 11%

2025-11-30T06:17:25.102 ProcessImageName: taskhostw.exe, Pid: 28972, TotalTime: 195, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 8%

2025-11-30T06:17:25.102 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 180, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 150, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 139, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 125, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\DO4399.tmp, EstimatedImpact: 36%

2025-11-30T06:17:25.102 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 120, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 105, Count: 52, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\8b41c630-6785-42e0-bbcf-dc78cadbdfd7.tmp, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: DeviceCensus.exe, Pid: 29244, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3, EstimatedImpact: 1%

2025-11-30T06:17:25.102 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\9c3ae3a1-2c99-4224-aca8-f6bfe81bba05.tmp, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\oem20.PNF, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: StoreDesktopExtension.exe, Pid: 23224, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: updater.exe, Pid: 28124, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\180699fb-6a28-49ef-8b3f-42bc27f2d1f3.tmp, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: svchost.exe, Pid: 18256, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\UUS\State\_active.uusver, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: updater.exe, Pid: 15088, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: updater.exe, Pid: 9500, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-30T06:17:25.102 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-30T06:19:35.831 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T06:25:22.479 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #453656, FileId: 0xd0000000947d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T06:34:40.820 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T06:40:23.030 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #453791, FileId: 0xe00000009487e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T06:49:45.826 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T06:52:07.228 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #453871, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T06:52:07.232 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #453872, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T06:52:17.242 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #453877, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T06:52:17.246 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #453878, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T06:55:23.435 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #453904, FileId: 0xd000000094933, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T07:04:50.814 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T07:10:23.682 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #454180, FileId: 0xd0000000949e6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T07:19:55.812 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T07:25:24.397 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #454291, FileId: 0xe000000094a92, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T07:28:49.544 [RTP] 28 newly mounted volumes accumulated, forcing a config update ...

2025-11-30T07:28:49.544 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy20\pagefile.sys

2025-11-30T07:28:49.544 [RTP] Duplicating the current plugin configuration object...

2025-11-30T07:28:49.544 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-30T07:28:49.544 [RTP] Updating plugin configuration due to recent config changes (0x1) ...

2025-11-30T07:28:49.544 [RTP] Calling GenerateEngineConfigStruct (0) ...

2025-11-30T07:28:49.545 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200

2025-11-30T07:28:51.326 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy20\pagefile.sys

2025-11-30T07:28:59.888 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy21\pagefile.sys

2025-11-30T07:29:01.609 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy21\pagefile.sys

2025-11-30T07:29:10.845 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy22\pagefile.sys

2025-11-30T07:29:12.513 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy22\pagefile.sys

2025-11-30T07:33:12.574 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T07:35:00.810 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T07:40:24.679 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #456000, FileId: 0xe000000094b57, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T07:50:05.798 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T07:52:06.980 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #456123, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T07:52:06.984 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #456124, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T07:52:16.982 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #456131, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T07:52:16.986 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #456132, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T07:55:24.890 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #456155, FileId: 0xf000000094c0d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T07:59:56.429 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #456236, FileId: 0xcf00000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T08:05:10.790 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T08:10:25.119 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #456462, FileId: 0xe000000094cbd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T08:17:25.073 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3421, Count: 341, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\4c334f03-e3ac-4753-8c04-db4367eb34d7.tmp, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2580, Count: 212, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\024eb9b0-6190-404d-bd4f-20eb46e8b114.tmp, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1470, Count: 83, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys, EstimatedImpact: 82%

2025-11-30T08:17:25.073 ProcessImageName: RuntimeBroker.exe, Pid: 26052, TotalTime: 960, Count: 42, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: , Pid: 4, TotalTime: 765, Count: 114, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy20\System Volume Information\{35f377ec-bd30-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 3%

2025-11-30T08:17:25.073 ProcessImageName: svchost.exe, Pid: 29520, TotalTime: 383, Count: 25, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\snapshot-2, EstimatedImpact: 1%

2025-11-30T08:17:25.073 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 315, Count: 81, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 240, Count: 55, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: taskhostw.exe, Pid: 30524, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 11%

2025-11-30T08:17:25.073 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 225, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 200, Count: 9, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\DO4399.tmp, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: taskhostw.exe, Pid: 28972, TotalTime: 195, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 8%

2025-11-30T08:17:25.073 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 180, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 154, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 105, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\8b41c630-6785-42e0-bbcf-dc78cadbdfd7.tmp, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: DeviceCensus.exe, Pid: 29244, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3, EstimatedImpact: 1%

2025-11-30T08:17:25.073 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\9c3ae3a1-2c99-4224-aca8-f6bfe81bba05.tmp, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: backgroundTaskHost.exe, Pid: 19644, TotalTime: 30, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1764456953, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: SrTasks.exe, Pid: 8968, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\oem20.PNF, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: taskhostw.exe, Pid: 26388, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 4%

2025-11-30T08:17:25.073 ProcessImageName: StoreDesktopExtension.exe, Pid: 23224, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: svchost.exe, Pid: 18256, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\UUS\State\_active.uusver, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: updater.exe, Pid: 28124, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\180699fb-6a28-49ef-8b3f-42bc27f2d1f3.tmp, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: updater.exe, Pid: 15088, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: updater.exe, Pid: 9500, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-30T08:17:25.073 ProcessImageName: bdredline.exe, Pid: 3316, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\redline\bdredline.conf, EstimatedImpact: 0%

2025-11-30T08:20:15.791 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T08:25:25.225 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #456537, FileId: 0x8700000002c082, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T08:35:20.793 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T08:40:25.422 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #456647, FileId: 0x10000000094b5c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T08:50:25.786 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T08:52:05.736 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #456737, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T08:52:05.739 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #456738, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T08:52:15.738 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #456743, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T08:52:15.742 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #456744, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T08:55:26.069 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #456768, FileId: 0x1200000009472f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T09:05:30.784 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T09:09:56.162 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #457044, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T09:10:26.529 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #457061, FileId: 0xe000000094f8b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T09:20:35.781 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T09:25:27.050 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #457132, FileId: 0xe00000009503d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T09:33:14.517 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T09:35:40.775 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T09:40:27.596 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #457281, FileId: 0x120000000950b7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T09:50:45.759 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T09:50:56.023 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #457378, FileId: 0xd000000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T09:52:07.881 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #457386, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T09:52:07.884 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #457387, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T09:52:17.891 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #457392, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T09:52:17.895 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #457393, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T09:55:27.816 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #457422, FileId: 0xf000000095197, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T10:05:50.761 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T10:10:28.058 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #457657, FileId: 0xe000000095232, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T10:17:25.048 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 4321, Count: 428, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\4c334f03-e3ac-4753-8c04-db4367eb34d7.tmp, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3300, Count: 264, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\024eb9b0-6190-404d-bd4f-20eb46e8b114.tmp, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1470, Count: 83, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys, EstimatedImpact: 82%

2025-11-30T10:17:25.048 ProcessImageName: RuntimeBroker.exe, Pid: 26052, TotalTime: 960, Count: 42, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: , Pid: 4, TotalTime: 765, Count: 114, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy20\System Volume Information\{35f377ec-bd30-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 3%

2025-11-30T10:17:25.048 ProcessImageName: svchost.exe, Pid: 29520, TotalTime: 383, Count: 25, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\snapshot-2, EstimatedImpact: 1%

2025-11-30T10:17:25.048 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 360, Count: 89, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 285, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 255, Count: 59, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: taskhostw.exe, Pid: 30524, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 11%

2025-11-30T10:17:25.048 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 200, Count: 9, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\DO4399.tmp, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: taskhostw.exe, Pid: 28972, TotalTime: 195, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 8%

2025-11-30T10:17:25.048 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 154, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 105, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\8b41c630-6785-42e0-bbcf-dc78cadbdfd7.tmp, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: DeviceCensus.exe, Pid: 29244, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3, EstimatedImpact: 1%

2025-11-30T10:17:25.048 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\9c3ae3a1-2c99-4224-aca8-f6bfe81bba05.tmp, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html, EstimatedImpact: 3%

2025-11-30T10:17:25.048 ProcessImageName: backgroundTaskHost.exe, Pid: 19644, TotalTime: 30, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1764456953, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_228980.acf, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: SrTasks.exe, Pid: 8968, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\oem20.PNF, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: taskhostw.exe, Pid: 26388, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 4%

2025-11-30T10:17:25.048 ProcessImageName: StoreDesktopExtension.exe, Pid: 23224, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\version.json, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: svchost.exe, Pid: 18256, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\UUS\State\_active.uusver, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: updater.exe, Pid: 28124, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\180699fb-6a28-49ef-8b3f-42bc27f2d1f3.tmp, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: updater.exe, Pid: 15088, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: updater.exe, Pid: 9500, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-11-30T10:17:25.048 ProcessImageName: bdredline.exe, Pid: 3316, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\redline\bdredline.conf, EstimatedImpact: 0%

2025-11-30T10:20:55.754 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T10:25:28.450 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #457762, FileId: 0xf000000095304, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T10:27:56.893 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\7D3F79CE-7E44-47A4-8C38-FA5E374FF6AA2854.1dc61e3fd823c5e

2025-11-30T10:27:56.947 Verifying engine and signature files (source: 0) ...

2025-11-30T10:27:56.947 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79DD1250-8DFF-48A3-8A4E-9E0E40788266}\mpengine.dll] due to PPL.

2025-11-30T10:27:56.947 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79DD1250-8DFF-48A3-8A4E-9E0E40788266}\mpasbase.vdm] (file in cache)

2025-11-30T10:27:56.947 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79DD1250-8DFF-48A3-8A4E-9E0E40788266}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-30T10:27:56.957 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79DD1250-8DFF-48A3-8A4E-9E0E40788266}\mpasdlta.vdm]

2025-11-30T10:27:56.957 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79DD1250-8DFF-48A3-8A4E-9E0E40788266}\mpavbase.vdm] (file in cache)

2025-11-30T10:27:56.957 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79DD1250-8DFF-48A3-8A4E-9E0E40788266}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-30T10:27:56.968 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79DD1250-8DFF-48A3-8A4E-9E0E40788266}\mpavdlta.vdm]

2025-11-30T10:27:57.039 [Engine] IsHybridMode: 0

2025-11-30T10:27:57.040 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-30T10:27:57.050 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-7DE4EF5A4F9C0121A1C5BFE24C09236F09B47C1F.bin): 0x00000002

2025-11-30T10:27:57.052 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-7DE4EF5A4F9C0121A1C5BFE24C09236F09B47C1F.bin)

2025-11-30T10:27:57.052 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-30T10:27:57.052 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-30T10:27:57.052 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-30T10:27:57.052 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-30T10:28:02.531 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-30T10:28:02.532 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-30T10:28:02.536 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE4C3EA660, lRefCount: 5, hr=0

2025-11-30T10:28:02.536 [Engine] New active engine 00007FFE7225A660 replacing engine 00007FFE4C3EA660. Number of active engines: 2

2025-11-30T10:28:02.539 EngineInit:Global ASOC is enabled

2025-11-30T10:28:02.539 EngineInit:ASOO is enabled for developer volumes

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T10:28:02.569 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

Dynamic Signature has been dropped

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\45a4841411dd2583c0abb7809d7473933a4902bd

Dynamic Signature Compilation Timestamp:11-29-2025 08:28:23

Persistence Type:Duration

Time remaining:864000000

2025-11-30T10:28:02.570 Dynamic signature dropped

2025-11-30T10:28:02.570 MpWriteUupSignatureVersion 1.441.604.0, hr = 0

2025-11-30T10:28:02.572 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-30T10:28:02.584 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-30T10:28:02.586 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-30T10:28:02.586 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-30T10:28:02.586 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-30T10:28:02.586 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-30T10:28:02.600 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-30T10:28:02.600 [Plugin] Initializing RTP plugin state...

2025-11-30T10:28:02.601 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-30T10:28:02.601 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 30 - 2025 01:17:25

Last Perf: 11 - 30 - 2025 01:17:25

First RTP Scan: 11 - 30 - 2025 01:17:25

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:1246

  Misses:6989

BM Queue:0,40,0

  Proc:0,39,0

  File:0,13,0

Plugin Queue:0,0,0

  Threat:0,0,0

  Susp:0,0,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:457904

  Pending:0

  RegSize:306586

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:-1145366556

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:24

  TotalStreamCon:18419

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:2896365

   TotalHits:3825911

   InstanceCacheInserts:159657

   InstanceCacheUpdates:0

   InstanceCacheDeletes:131563

   InstanceCacheHits:5627

   InstanceCacheMisses:670088

   InstanceCacheOverflows:10504

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (925/1211)

   Success: 1211, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-30T10:28:02.601 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79DD1250-8DFF-48A3-8A4E-9E0E40788266}

2025-11-30T10:28:02.601 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D6713FD8-A8ED-4533-8C05-D3C4ED7F1423}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D6713FD8-A8ED-4533-8C05-D3C4ED7F1423}\mpasbase.vdm in use, hr=0x80070020

2025-11-30T10:28:02.601 [SCC][CID=1183714078_29924] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-30T10:28:02.602 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-30T10:28:02.602 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-30T10:28:02.602 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-30T10:28:02.602 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-30T10:28:02.602 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-30T10:28:02.602 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-30-2025 10:28:02

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-30-2025 10:28:02

2025-11-30T10:28:02.604 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-30T10:28:02.604 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-30T10:28:02.605 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-30T10:28:02.605 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-30-2025 10:28:02

END TDT(U) telemetry



2025-11-30T10:28:02.607 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T10:28:02.607 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-30T10:28:02.607 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-30T10:28:02.607 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-30T10:28:02.607 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-30T10:28:02.608 MdCoreSvc is supported in this platform and OS

Signature updated on 11-30-2025 10:28:02

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.604.0

AV Signature Version: 1.441.604.0

************************************************************

2025-11-30T10:28:02.609 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-30T10:28:02.609 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\7D3F79CE-7E44-47A4-8C38-FA5E374FF6AA2854.1dc61e3fd823c5e

2025-11-30T10:28:02.624 Process scan (postsignatureupdatescan) started.

2025-11-30T10:28:02.647 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-30T10:28:02.648 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-30T10:28:02.784 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-30T10:28:02.784 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-30T10:28:02.784 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-30T10:28:02.784 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-30T10:28:02.784 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-30T10:28:02.786 [Engine] Engine 00007FFE4C3EA660 no longer in use. Number of active engines: 1

2025-11-30T10:28:02.786 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-30T10:28:02.786 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-30T10:28:02.944 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 4411, Count: 435, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\4c334f03-e3ac-4753-8c04-db4367eb34d7.tmp, EstimatedImpact: 0%

2025-11-30T10:28:02.944 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3375, Count: 270, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\024eb9b0-6190-404d-bd4f-20eb46e8b114.tmp, EstimatedImpact: 0%

2025-11-30T10:28:02.944 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1470, Count: 83, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys, EstimatedImpact: 82%

2025-11-30T10:28:02.944 ProcessImageName: RuntimeBroker.exe, Pid: 26052, TotalTime: 960, Count: 42, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 0%

2025-11-30T10:28:02.944 ProcessImageName: , Pid: 4, TotalTime: 765, Count: 114, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy20\System Volume Information\{35f377ec-bd30-11f0-b6dc-000acd3b8d8d}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 3%

2025-11-30T10:28:02.944 ProcessImageName: svchost.exe, Pid: 29520, TotalTime: 383, Count: 25, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\snapshot-2, EstimatedImpact: 1%

2025-11-30T10:28:02.944 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 360, Count: 89, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-30T10:28:02.944 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 300, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T10:28:02.944 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 270, Count: 63, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0%

2025-11-30T10:28:02.944 ProcessImageName: taskhostw.exe, Pid: 30524, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 11%

2025-11-30T10:28:02.944 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 225, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-30T10:28:02.944 ProcessImageName: svchost.exe, Pid: 2344, TotalTime: 200, Count: 9, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\DO4399.tmp, EstimatedImpact: 0%

2025-11-30T10:28:02.944 ProcessImageName: taskhostw.exe, Pid: 28972, TotalTime: 195, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 8%

2025-11-30T10:28:02.944 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 154, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-30T10:28:02.944 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 105, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\8b41c630-6785-42e0-bbcf-dc78cadbdfd7.tmp, EstimatedImpact: 0%

2025-11-30T10:28:02.944 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-11-30T10:28:02.959 [Engine] RSIG_UNLOADENGINE, 00007FFE4C3EA660, err=0x0

2025-11-30T10:28:02.976 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D6713FD8-A8ED-4533-8C05-D3C4ED7F1423} removed

2025-11-30T10:28:03.091 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-30T10:28:03.098 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-30T10:28:03.098 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-30T10:28:03.098 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-30T10:28:03.098 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-30T10:28:03.098 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-30T10:28:03.098 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-30T10:28:03.101 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-30T10:28:03.101 [RTP] Duplicating the current plugin configuration object...

2025-11-30T10:28:03.101 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-30T10:28:03.101 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-30T10:28:03.101 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-30T10:28:03.101 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-30T10:28:03.101 [RTP] No config change detected. Not updating plugin configuration.

2025-11-30T10:28:03.101 [RTP] No config changes found. No configuration switch.

2025-11-30T10:28:03.101 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-30T10:28:03.101 [RTP] Duplicating the current plugin configuration object...

2025-11-30T10:28:03.101 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-30T10:28:03.101 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-30T10:28:03.101 [RTP] Updating plugin configuration due to recent config changes (0x2) ...

2025-11-30T10:28:03.101 [RTP] No config change detected. Not updating plugin configuration.

2025-11-30T10:28:03.101 [RTP] No config changes found. No configuration switch.

2025-11-30T10:28:03.102 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0

2025-11-30T10:28:03.102 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-30T10:28:03.102 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-30T10:28:03.102 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-30T10:28:03.102 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-30T10:28:03.102 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-30T10:28:03.102 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-30T10:28:03.102 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-30T10:28:03.102 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-30T10:28:03.102 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-30T10:28:03.102 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-30T10:28:03.102 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-30T10:28:03.102 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-30T10:28:03.102 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-30T10:28:03.102 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-30T10:28:03.102 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-30T10:28:03.102 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T10:28:03.104 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T10:28:03.106 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T10:28:03.107 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T10:28:03.109 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T10:28:03.111 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 65013490(ms) from now at 05:31 (04:31 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-30T10:28:04.616 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-30T10:28:04.619 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-30T10:28:04.620 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-30T10:28:05.614 [RTP] Duplicating the current plugin configuration object...

2025-11-30T10:28:05.614 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-30T10:28:05.614 [RTP] Updating plugin configuration due to recent config changes (0x40c) ...

2025-11-30T10:28:05.614 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-30T10:28:05.614 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40c, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157ED7C270CE, sigsha=5eded354160aa060b3f2a16db0725661264de9cd, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF9518016, sigsha=8fa60ffaf004b3696b5767c35f78f1425d04eb09, cached=false, source=0, resourceid=0xa85b3f00

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0xa85b3f00

2025-11-30T10:28:07.937 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-30T10:28:07.937 [Cloud] Start of cloud request. Passive mode: 0

2025-11-30T10:28:07.937 [Cloud] Queued cloud request.

2025-11-30T10:28:07.937 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-30T10:28:07.937 [Cloud] Dequeued cloud request.

2025-11-30T10:28:07.938 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\43166e962abe64cee43e894010e6467fdb9a94a5

Dynamic Signature Compilation Timestamp:11-30-2025 10:28:08

Persistence Type:Duration

Time remaining:864000000

2025-11-30T10:28:08.220 Dynamic signature received

2025-11-30T10:28:08.221 [Cloud] End of cloud request.

2025-11-30T10:28:08.221 RTSD:RTSD recieved, rescanning impacted resources

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-30T10:28:08.729 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T10:28:18.479 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-30T10:28:18.479 Process scan (postsignatureupdatescan) completed.

2025-11-30T10:28:18.488 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-30T10:28:19.769 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-30T10:28:19.770 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xebc88da77ffffffe

2025-11-30T10:28:21.754 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext)

2025-11-30T10:28:21.754 [Cloud] Start of cloud request. Passive mode: 0

2025-11-30T10:28:21.754 [Cloud] Queued cloud request.

2025-11-30T10:28:21.754 [Cloud] Dequeued cloud request.

2025-11-30T10:28:21.775 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-30T10:28:21.835 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-30T10:28:21.835 [Cloud] End of cloud request.

2025-11-30T10:28:22.346 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T10:33:02.551 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-30T10:36:00.748 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T10:40:28.510 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #458276, FileId: 0x100000000953b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T10:51:05.739 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T10:52:07.108 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #458414, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T10:52:07.111 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #458415, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T10:52:17.117 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #458421, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T10:52:17.121 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #458422, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T10:52:17.122 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #458423, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T10:55:28.786 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #458655, FileId: 0xe000000095472, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T11:06:10.746 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T11:10:29.248 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #459083, FileId: 0xe000000095526, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

Internal signature match:subtype=Lowfi, sigseq=0x00005CE7CC5A3752, sigsha=7e1afd9d794bc98262152514a242044b80de6fc9, cached=false, source=5, resourceid=0xc1609626

2025-11-30T11:12:54.608 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\component_crx_cache\temp_1.bf93c8c43222975d486a882222be89c2ddcbe545dbb54120a94757e2f00f46b2. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x5ce7cc5a3752

2025-11-30T11:21:15.734 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T11:25:29.556 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #459633, FileId: 0xd0000000955bf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

Internal signature match:subtype=Lowfi, sigseq=0x0000108090FCF4C4, sigsha=064f0536ffb97bb72d6c274c080aa4e2ffdf1b46, cached=false, source=2, resourceid=0xe9a0dc71

Internal signature match:subtype=Lowfi, sigseq=0x0000157E4E50F357, sigsha=9c083f3159c7030387555a678b869916416c4a65, cached=false, source=2, resourceid=0x687a17a3

2025-11-30T11:33:16.455 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T11:36:20.735 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T11:40:30.305 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #461604, FileId: 0xe000000095689, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T11:51:25.730 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T11:52:06.108 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #461704, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T11:52:06.112 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #461705, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T11:52:16.115 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #461710, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T11:52:16.119 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #461711, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T11:55:30.678 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #462213, FileId: 0xe000000095741, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T12:06:30.729 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T12:10:31.311 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #462594, FileId: 0x60000000957f7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T12:21:35.730 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T12:25:31.726 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #462687, FileId: 0x4000000095899, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T12:28:02.511 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 13319, Count: 861, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume4\xampp\sendmail\sendmail.exe, EstimatedImpact: 24%

2025-11-30T12:28:02.511 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1535, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 85%

2025-11-30T12:28:02.511 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 780, Count: 88, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\5e94927f-8ccf-4201-a6c6-4e9bee7d79a8.tmp, EstimatedImpact: 0%

2025-11-30T12:28:02.511 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 630, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\e5eb7107-cdb0-4660-927b-50df489c0248.tmp, EstimatedImpact: 0%

2025-11-30T12:28:02.511 ProcessImageName: RuntimeBroker.exe, Pid: 28720, TotalTime: 540, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-30T12:28:02.511 ProcessImageName: taskhostw.exe, Pid: 6500, TotalTime: 420, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 24%

2025-11-30T12:28:02.511 ProcessImageName: WmiPrvSE.exe, Pid: 19664, TotalTime: 315, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\wstorvsp.inf->(UTF-16LE), EstimatedImpact: 26%

2025-11-30T12:28:02.511 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-30T12:28:02.511 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T12:28:02.511 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-30T12:28:02.511 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-30T12:28:02.511 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-30T12:28:02.511 ProcessImageName: StoreDesktopExtension.exe, Pid: 29536, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-30T12:28:02.511 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\886aa96a-282a-4a0a-bb27-0df7e5a0f78b.tmp, EstimatedImpact: 0%

2025-11-30T12:28:02.511 ProcessImageName: taskhostw.exe, Pid: 27120, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-30T12:28:02.511 ProcessImageName: updater.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\35583fa7-6de8-4d40-890b-637e3d445738.tmp, EstimatedImpact: 0%

2025-11-30T12:36:40.715 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T12:40:32.177 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #462801, FileId: 0x28000000095993, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T12:51:45.716 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T12:52:06.412 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #462886, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T12:52:06.415 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #462887, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T12:52:16.413 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #462893, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T12:52:16.418 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #462894, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T12:55:32.588 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #462919, FileId: 0x5000000095ad9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T13:06:50.706 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T13:10:33.028 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #463174, FileId: 0xd000000095c17, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T13:21:55.700 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T13:25:33.527 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #463244, FileId: 0x8000000095d03, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T13:33:18.590 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T13:37:00.709 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T13:40:34.079 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #463409, FileId: 0x110000000956b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T13:52:05.701 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T13:52:06.405 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #463521, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T13:52:06.408 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #463522, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T13:52:16.407 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #463527, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T13:52:16.411 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #463528, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T13:55:34.742 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #463552, FileId: 0xc000000095ff6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T14:01:56.256 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #463647, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T14:07:10.692 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T14:10:34.837 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #463865, FileId: 0xe0000000960d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T14:22:15.683 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T14:25:35.240 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #463949, FileId: 0x500000009620a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T14:28:02.492 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 13319, Count: 861, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume4\xampp\sendmail\sendmail.exe, EstimatedImpact: 24%

2025-11-30T14:28:02.492 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 1681, Count: 176, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\1736ea23-1215-4886-89d8-581503f36dde.tmp, EstimatedImpact: 0%

2025-11-30T14:28:02.492 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1535, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 85%

2025-11-30T14:28:02.492 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1275, Count: 107, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\e5eb7107-cdb0-4660-927b-50df489c0248.tmp, EstimatedImpact: 0%

2025-11-30T14:28:02.492 ProcessImageName: RuntimeBroker.exe, Pid: 28720, TotalTime: 540, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-30T14:28:02.492 ProcessImageName: taskhostw.exe, Pid: 6500, TotalTime: 420, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 24%

2025-11-30T14:28:02.492 ProcessImageName: WmiPrvSE.exe, Pid: 19664, TotalTime: 315, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\wstorvsp.inf->(UTF-16LE), EstimatedImpact: 26%

2025-11-30T14:28:02.492 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 180, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T14:28:02.492 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 120, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-30T14:28:02.492 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 105, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-30T14:28:02.492 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-30T14:28:02.492 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 90, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-30T14:28:02.492 ProcessImageName: StoreDesktopExtension.exe, Pid: 29536, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-30T14:28:02.492 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 0%

2025-11-30T14:28:02.492 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\886aa96a-282a-4a0a-bb27-0df7e5a0f78b.tmp, EstimatedImpact: 0%

2025-11-30T14:28:02.492 ProcessImageName: taskhostw.exe, Pid: 27120, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-30T14:28:02.492 ProcessImageName: updater.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\35583fa7-6de8-4d40-890b-637e3d445738.tmp, EstimatedImpact: 0%

2025-11-30T14:28:02.492 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\ce439a86-2b66-4b21-be89-5a7223017056.tmp, EstimatedImpact: 0%

2025-11-30T14:37:20.686 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T14:40:35.762 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #464068, FileId: 0x30000000962d6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T14:52:06.989 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #464135, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T14:52:06.992 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #464136, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T14:52:16.991 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #464141, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T14:52:16.995 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #464142, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T14:52:25.679 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T14:55:35.783 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #464271, FileId: 0x100000000963fc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T15:07:30.681 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T15:10:36.221 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #464518, FileId: 0x19000000077a51, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T15:22:35.671 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T15:25:36.292 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #464623, FileId: 0xd000000096562, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T15:33:20.478 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T15:34:21.525 [RTP] [Mini-filter] Copy hint telemetry notification (\Device\HarddiskVolume4\Windows\System32\svchost.exe) sent successfully.

2025-11-30T15:37:40.672 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

Internal signature match:subtype=Lowfi, sigseq=0x0002B1BD9E1A2199, sigsha=2d3e5dea97dd42cf08d7b1acc7f7dbc2350c80dd, cached=false, source=12, resourceid=0xb6ab16e7

Internal signature match:subtype=Lowfi, sigseq=0x0002C7BD6F0B1013, sigsha=8bb06083c03020ac23ff7c874afe346f250526db, cached=false, source=12, resourceid=0xb6ab16e7

AMSI Result:LoFi

AMSI Originating Process:0000172C

2025-11-30T15:40:01.228 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 1 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: TRUE

Internal signature match:subtype=Lowfi, sigseq=0x0002B1BD9E1A2199, sigsha=2d3e5dea97dd42cf08d7b1acc7f7dbc2350c80dd, cached=false, source=12, resourceid=0xff68fc40

Internal signature match:subtype=Lowfi, sigseq=0x0002C7BD6F0B1013, sigsha=8bb06083c03020ac23ff7c874afe346f250526db, cached=false, source=12, resourceid=0xff68fc40

AMSI Result:LoFi

AMSI Originating Process:0000172C

2025-11-30T15:40:01.261 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xb268edb7ffffffe

2025-11-30T15:40:01.261 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xb268edb7ffffffe

2025-11-30T15:40:01.275 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext)

2025-11-30T15:40:01.275 [Cloud] Start of cloud request. Passive mode: 0

2025-11-30T15:40:01.275 [Cloud] Queued cloud request.

2025-11-30T15:40:01.275 [Cloud] Dequeued cloud request.

2025-11-30T15:40:01.301 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Internal signature match:subtype=Lowfi, sigseq=0x0002B1BD9E1A2199, sigsha=2d3e5dea97dd42cf08d7b1acc7f7dbc2350c80dd, cached=false, source=12, resourceid=0xe89242cd

Internal signature match:subtype=Lowfi, sigseq=0x0002C7BD6F0B1013, sigsha=8bb06083c03020ac23ff7c874afe346f250526db, cached=false, source=12, resourceid=0xe89242cd

AMSI Result:LoFi

AMSI Originating Process:0000172C

2025-11-30T15:40:01.469 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-30T15:40:01.469 [Cloud] End of cloud request.

2025-11-30T15:40:01.980 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T15:40:16.298 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 1 (0 - Regular, 1 - MemScan), 2 resources, RtpIoavOnly: TRUE

2025-11-30T15:40:16.300 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x178701417ffffffe

2025-11-30T15:40:16.300 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xaab393447ffffffe

2025-11-30T15:40:16.300 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x178701417ffffffe

2025-11-30T15:40:16.300 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xaab393447ffffffe

2025-11-30T15:40:16.312 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext)

2025-11-30T15:40:16.313 [Cloud] Start of cloud request. Passive mode: 0

2025-11-30T15:40:16.313 [Cloud] Queued cloud request.

2025-11-30T15:40:16.313 [Cloud] Dequeued cloud request.

2025-11-30T15:40:16.335 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-30T15:40:16.405 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-30T15:40:16.405 [Cloud] End of cloud request.

2025-11-30T15:40:16.909 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T15:40:36.690 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #467479, FileId: 0x7f000000019a6f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T15:41:41.998 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume4\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #467548, FileId: 0x2b000000028807, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T15:52:06.541 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #467682, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T15:52:06.544 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #467683, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T15:52:16.551 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #467690, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T15:52:16.554 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #467691, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T15:52:16.555 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #467692, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T15:52:45.666 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T15:55:37.299 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #467719, FileId: 0xc000000096689, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T16:07:50.657 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T16:10:37.752 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #468121, FileId: 0xf00000009674f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T16:22:55.661 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T16:25:37.828 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #468217, FileId: 0xd000000096802, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T16:28:02.468 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 13319, Count: 861, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume4\xampp\sendmail\sendmail.exe, EstimatedImpact: 24%

2025-11-30T16:28:02.468 ProcessImageName: SrTasks.exe, Pid: 19504, TotalTime: 3019, Count: 857, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{2e2e64e3-2827-42b9-90f3-f869793f41d9}_OnDiskSnapshotProp, EstimatedImpact: 10%

2025-11-30T16:28:02.468 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 2581, Count: 262, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\1736ea23-1215-4886-89d8-581503f36dde.tmp, EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1905, Count: 160, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\e5eb7107-cdb0-4660-927b-50df489c0248.tmp, EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1535, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 85%

2025-11-30T16:28:02.468 ProcessImageName: RuntimeBroker.exe, Pid: 28720, TotalTime: 540, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-30T16:28:02.468 ProcessImageName: taskhostw.exe, Pid: 6500, TotalTime: 420, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 24%

2025-11-30T16:28:02.468 ProcessImageName: WmiPrvSE.exe, Pid: 19664, TotalTime: 315, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\wstorvsp.inf->(UTF-16LE), EstimatedImpact: 26%

2025-11-30T16:28:02.468 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 225, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: php-cgi.exe, Pid: 15844, TotalTime: 212, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\php\ext\php_bz2.dll, EstimatedImpact: 85%

2025-11-30T16:28:02.468 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 165, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 135, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: ngentask.exe, Pid: 28420, TotalTime: 135, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 13%

2025-11-30T16:28:02.468 ProcessImageName: ngentask.exe, Pid: 8312, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 13%

2025-11-30T16:28:02.468 ProcessImageName: ngentask.exe, Pid: 19836, TotalTime: 135, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 26%

2025-11-30T16:28:02.468 ProcessImageName: WmiPrvSE.exe, Pid: 22576, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 100%

2025-11-30T16:28:02.468 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 105, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: ngentask.exe, Pid: 6228, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 15%

2025-11-30T16:28:02.468 ProcessImageName: taskhostw.exe, Pid: 14168, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 3%

2025-11-30T16:28:02.468 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 60, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping11060_1301338752\manifest.json, EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\886aa96a-282a-4a0a-bb27-0df7e5a0f78b.tmp, EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: ngentask.exe, Pid: 29596, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 31%

2025-11-30T16:28:02.468 ProcessImageName: ngentask.exe, Pid: 22056, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 28%

2025-11-30T16:28:02.468 ProcessImageName: StoreDesktopExtension.exe, Pid: 29536, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\system\dashboard-ui\index.html->(UTF-8), EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: tzsync.exe, Pid: 29608, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Globalization\Time Zone\timezones.xml->(UTF-8), EstimatedImpact: 3%

2025-11-30T16:28:02.468 ProcessImageName: ngentask.exe, Pid: 21860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 28%

2025-11-30T16:28:02.468 ProcessImageName: taskhostw.exe, Pid: 27120, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-30T16:28:02.468 ProcessImageName: updater.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\35583fa7-6de8-4d40-890b-637e3d445738.tmp, EstimatedImpact: 0%

2025-11-30T16:28:02.468 ProcessImageName: updater.exe, Pid: 2212, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\0f165b58-4606-4b01-a765-9e423175d087.tmp, EstimatedImpact: 0%

2025-11-30T16:38:00.647 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T16:40:38.520 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #468750, FileId: 0x40000000968b6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T16:46:05.819 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #469014, FileId: 0xd100000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T16:48:37.411 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #469037, FileId: 0x10d000000006c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T16:52:06.593 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #469073, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T16:52:06.597 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #469074, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T16:52:16.598 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #469081, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T16:52:16.602 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #469082, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T16:53:05.648 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T16:55:39.238 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #469115, FileId: 0xe0000000969ac, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T17:08:10.646 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T17:10:39.759 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #469463, FileId: 0x3000000096b01, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T17:15:21.927 Bm signature throttled:0x00002db31bed458f

2025-11-30T17:23:15.637 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T17:25:40.110 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #469617, FileId: 0x3000000096bb3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T17:33:22.480 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T17:38:20.625 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T17:40:40.707 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #469760, FileId: 0xf000000096084, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T17:52:05.627 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #470472, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T17:52:05.630 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #470473, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T17:52:15.632 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #470478, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T17:52:15.636 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #470479, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T17:53:25.631 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T17:55:41.260 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #470503, FileId: 0x3000000096cf3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T18:01:37.114 Bm signature throttled:0x00002db31bed458f

2025-11-30T18:08:30.623 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T18:10:41.581 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #470774, FileId: 0x3000000096dac, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T18:23:35.624 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T18:25:21.645 Bm signature throttled:0x00002db31bed458f

2025-11-30T18:25:42.208 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #471044, FileId: 0x3000000096e56, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T18:25:56.630 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #471045, FileId: 0xd200000000395e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2000, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T18:28:02.447 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 13334, Count: 862, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume4\xampp\sendmail\sendmail.exe, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3451, Count: 348, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\1736ea23-1215-4886-89d8-581503f36dde.tmp, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: SrTasks.exe, Pid: 19504, TotalTime: 3019, Count: 857, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{2e2e64e3-2827-42b9-90f3-f869793f41d9}_OnDiskSnapshotProp, EstimatedImpact: 10%

2025-11-30T18:28:02.447 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2565, Count: 211, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\e5eb7107-cdb0-4660-927b-50df489c0248.tmp, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1535, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 85%

2025-11-30T18:28:02.447 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1200, Count: 195, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 916, Count: 148, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Media\Filmer\2160p\Mufasa.The.Lion.King.2024.2160p.4K.WEB.x265.10bit.AAC5.1-[YTS.MX].mkv, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: RuntimeBroker.exe, Pid: 28720, TotalTime: 540, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-30T18:28:02.447 ProcessImageName: taskhostw.exe, Pid: 6500, TotalTime: 420, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 24%

2025-11-30T18:28:02.447 ProcessImageName: WmiPrvSE.exe, Pid: 19664, TotalTime: 315, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\wstorvsp.inf->(UTF-16LE), EstimatedImpact: 26%

2025-11-30T18:28:02.447 ProcessImageName: WmiPrvSE.exe, Pid: 3456, TotalTime: 307, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\smbdirect.sys, EstimatedImpact: 84%

2025-11-30T18:28:02.447 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 285, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 255, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: php-cgi.exe, Pid: 15844, TotalTime: 212, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\php\ext\php_bz2.dll, EstimatedImpact: 85%

2025-11-30T18:28:02.447 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 195, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 150, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 135, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: ngentask.exe, Pid: 28420, TotalTime: 135, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 13%

2025-11-30T18:28:02.447 ProcessImageName: ngentask.exe, Pid: 8312, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 13%

2025-11-30T18:28:02.447 ProcessImageName: ngentask.exe, Pid: 19836, TotalTime: 135, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 26%

2025-11-30T18:28:02.447 ProcessImageName: WmiPrvSE.exe, Pid: 22576, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 100%

2025-11-30T18:28:02.447 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 105, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping11060_1301338752\manifest.json, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 105, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: ngentask.exe, Pid: 6228, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 15%

2025-11-30T18:28:02.447 ProcessImageName: taskhostw.exe, Pid: 14168, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 3%

2025-11-30T18:28:02.447 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\886aa96a-282a-4a0a-bb27-0df7e5a0f78b.tmp, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: ngentask.exe, Pid: 29596, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 31%

2025-11-30T18:28:02.447 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: ngentask.exe, Pid: 22056, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 28%

2025-11-30T18:28:02.447 ProcessImageName: StoreDesktopExtension.exe, Pid: 29536, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: taskhostw.exe, Pid: 8684, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-30T18:28:02.447 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: PhoneExperienceHost.exe, Pid: 1316, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Desktop\desktop.ini->(UTF-16LE), EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: tzsync.exe, Pid: 29608, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Globalization\Time Zone\timezones.xml->(UTF-8), EstimatedImpact: 3%

2025-11-30T18:28:02.447 ProcessImageName: ngentask.exe, Pid: 21860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 28%

2025-11-30T18:28:02.447 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: taskhostw.exe, Pid: 27120, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-30T18:28:02.447 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 4%

2025-11-30T18:28:02.447 ProcessImageName: updater.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\35583fa7-6de8-4d40-890b-637e3d445738.tmp, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: nvngx_update.exe, Pid: 22732, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 2%

2025-11-30T18:28:02.447 ProcessImageName: nvngx_update.exe, Pid: 29152, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-30T18:28:02.447 ProcessImageName: updater.exe, Pid: 2212, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\0f165b58-4606-4b01-a765-9e423175d087.tmp, EstimatedImpact: 0%

Internal signature match:subtype=Lowfi, sigseq=0x0000157EBAD029E3, sigsha=a80b7cfbca5c0e7f9fba5768d931c4e463118bd7, cached=false, source=2, resourceid=0x7213b5df

Internal signature match:subtype=Lowfi, sigseq=0x0000157E6A855602, sigsha=0994c4a442027631466fa0fa9a785e5f4c9a4e22, cached=false, source=2, resourceid=0x7213b5df

Internal signature match:subtype=Lowfi, sigseq=0x0000157E79D31496, sigsha=ea85fbc31c099b374f0738a1e88ece004ab148bb, cached=false, source=2, resourceid=0x7213b5df

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=2, resourceid=0x7213b5df

Internal signature match:subtype=Lowfi, sigseq=0x0000157E3741FAAC, sigsha=a00e9ed2e65840846a4e1debb10f38e5c808e92f, cached=false, source=2, resourceid=0x7213b5df

Internal signature match:subtype=Lowfi, sigseq=0x0000157E9980FB5F, sigsha=caf2d4b8acf0dd2f2a221a939d778df328f65b6e, cached=false, source=2, resourceid=0x7213b5df

2025-11-30T18:34:11.955 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume4\Program Files\qBittorrent\uninst.exe. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x157ebad029e3

2025-11-30T18:38:40.611 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T18:40:42.864 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #471669, FileId: 0x3000000096f07, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T18:52:07.008 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #471746, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T18:52:07.012 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #471747, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T18:52:17.019 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #471752, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T18:52:17.023 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #471753, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T18:53:45.606 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T18:55:43.602 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #471875, FileId: 0x3000000096fba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:08:50.609 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T19:10:44.043 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #472082, FileId: 0x300000009703c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

Internal signature match:subtype=Lowfi, sigseq=0x0000108014CC4618, sigsha=534926cb80e789ed6654502a80a7b29f6fd18bdc, cached=false, source=2, resourceid=0x8df50202

2025-11-30T19:21:03.068 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume4\Program Files\WinRAR\Default.SFX. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x108014cc4618

2025-11-30T19:23:55.601 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T19:25:44.827 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #473749, FileId: 0x4000000097117, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:31:31.229 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvdrsdb0.bin. Process: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\Display.NvContainer\NVDisplay.Container.exe, Status: 0xc000004b, State: 0, ScanRequest #474028, FileId: 0x200000001b72c, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:31:31.297 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\NvContainer\NvContainerSession3.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #474043, FileId: 0x11000000014565, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:31:31.298 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume4\ProgramData\NVIDIA\DisplaySessionContainer3.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #474045, FileId: 0x1920000000086ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:31:31.364 Bm signature throttled:0x00002db31bed458f

2025-11-30T19:31:32.106 Task(MpCmdRun.exe AdvertiseSso) launched under the given user session

2025-11-30T19:31:33.232 Bm signature throttled:0x00002db31bed458f

2025-11-30T19:31:33.657 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\console.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #474278, FileId: 0x143000000000321, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:31:35.901 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\GallerySettings.json. Process: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA Overlay.exe, Status: 0xc0000001, State: 0, ScanRequest #474558, FileId: 0x40000000792d2, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:31:44.096 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #474870, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:32:23.426 Bm signature throttled:0x00002db31bed458f

Internal signature match:subtype=Lowfi, sigseq=0x00005CE7CC5A3752, sigsha=7e1afd9d794bc98262152514a242044b80de6fc9, cached=false, source=5, resourceid=0x1bce12e8

2025-11-30T19:33:07.809 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\component_crx_cache\temp_1.d236120008c5ce6b63bd11f8e3ab3ec8a394c01957f3b974a3b6c2fea5ef3406. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x5ce7cc5a3752

2025-11-30T19:33:24.630 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T19:34:59.478 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume4\ProgramData\NVIDIA\DisplaySessionContainer3.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #475340, FileId: 0x270000000002d9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:34:59.486 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\NvContainer\NvContainerSession3.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #475343, FileId: 0x1ec000000007930, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:36:12.773 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Ookla.SpeedtestbyOokla_43tkc6nmykmb6\TempState\UnityPlayer.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #475574, FileId: 0x2e20000000079fc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=0, resourceid=0x41ad0158

2025-11-30T19:37:24.493 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xd76081d27ffffffe

2025-11-30T19:37:24.495 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=0, resourceid=0x41ad0158

2025-11-30T19:37:24.583 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xd76081d27ffffffe

2025-11-30T19:37:24.585 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xd76081d27ffffffe

2025-11-30T19:37:24.874 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext)

2025-11-30T19:37:24.874 [Cloud] Start of cloud request. Passive mode: 0

2025-11-30T19:37:24.874 [Cloud] Queued cloud request.

2025-11-30T19:37:24.874 [Cloud] Dequeued cloud request.

2025-11-30T19:37:24.894 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-30T19:37:25.040 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-30T19:37:25.041 [Cloud] End of cloud request.

2025-11-30T19:37:25.555 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=2, resourceid=0x889fb73a

Internal signature match:subtype=Lowfi, sigseq=0x000078E7B6D8B30B, sigsha=7e39caa16cef41cd13040adae6e049354306a445, cached=false, source=2, resourceid=0x889fb73a



BEGIN BM telemetry

GUID:{5155F327-BE6C-48D6-9E90-46EB25D84449}

SignatureID:23861928738038

SigSha:f1adf5e0e5276dcabdc2fcc8752893f23861e181

ThreatLevel:0

ProcessID:32268

ProcessCreationTime:134090050438551286

SessionID:1

CreationTime:11-30-2025 19:38:33

ImagePath:C:\Users\ServerPC\Downloads\FileZilla_Server_1.12.0_win64-setup.exe

Taint Info:Friendly: N; Reason: ; Modules: C:\Users\ServerPC\AppData\Local\Temp\nsdFF0B.tmp\System.dll:25,C:\Users\ServerPC\AppData\Local\Temp\nsdFF0B.tmp\StartMenu.dll:25,C:\Users\ServerPC\AppData\Local\Temp\nsdFF0B.tmp\nsDialogs.dll:25,C:\Users\ServerPC\AppData\Local\Temp\nsdFF0B.tmp\nsExec.dll:25,C:\Users\ServerPC\AppData\Local\Temp\nseB7A.tmp\System.dll:25,; Parents: C:\Program Files\FileZilla Server\filezilla-server-gui.exe:30560:1,C:\Windows\System32\svchost.exe:8600:2,C:\Windows\System32\csrss.exe:880:2,C:\Windows\System32\csrss.exe:944:2,C:\Windows\System32\svchost.exe:9032:2,

Operations:None

END BM telemetry



2025-11-30T19:38:33.635 ReportLowfi(c:\program files\filezilla server\filezilla-server-gui.exe, 0x437a0835) from 0x0006b6bd6566d2d9

Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0xd8437bd4

Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=2, resourceid=0x8488c6f6

2025-11-30T19:38:33.789 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-30T19:38:33.789 [Cloud] Start of cloud request. Passive mode: 0

2025-11-30T19:38:33.789 [Cloud] Queued cloud request.

2025-11-30T19:38:33.789 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-30T19:38:33.789 [Cloud] Dequeued cloud request.

2025-11-30T19:38:33.789 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-30T19:38:33.816 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume4\Program Files\FileZilla Server\Uninstall.exe. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x157ef1bef48f

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\59788c7cc57f497c04c8780c05096c323af44cc9

Dynamic Signature Compilation Timestamp:11-30-2025 19:38:34

Persistence Type:Duration

Time remaining:150196224

2025-11-30T19:38:34.081 [Cloud] End of cloud request.

Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0xd8437bd4

Internal signature match:subtype=Lowfi, sigseq=0x00000070DE3CA1F0, sigsha=da39a3ee5e6b4b0d3255bfef95601890afd80709, cached=false, source=0, resourceid=0xd8437bd4

2025-11-30T19:38:34.119 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x4ed6aa527ffffffe

2025-11-30T19:38:34.119 Dynamic signature received

2025-11-30T19:38:34.125 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE

Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0xd8437bd4

2025-11-30T19:38:34.598 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T19:38:34.907 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-30T19:38:34.907 [Cloud] Start of cloud request. Passive mode: 0

2025-11-30T19:38:34.907 [Cloud] Queued cloud request.

2025-11-30T19:38:34.907 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-30T19:38:34.907 [Cloud] Dequeued cloud request.

2025-11-30T19:38:34.908 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d60e92147ac470cf1e28e9672445dbe3518ce944

Dynamic Signature Compilation Timestamp:11-30-2025 19:38:35

Persistence Type:Duration

Time remaining:150196224

2025-11-30T19:38:35.223 Dynamic signature received

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2bb9eb11398598df38b1810bde55de44526463af

Dynamic Signature Compilation Timestamp:11-30-2025 19:38:35

Persistence Type:Duration

Time remaining:150196224

2025-11-30T19:38:35.226 Dynamic signature received

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\afd2c8f21320d1f130176c32ef19c411eb013451

Dynamic Signature Compilation Timestamp:11-30-2025 19:38:35

Persistence Type:Duration

Time remaining:150196224

2025-11-30T19:38:35.227 Dynamic signature received

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\502e5460a38c9b82adeaa589c0c33f8d40491656

Dynamic Signature Compilation Timestamp:11-30-2025 19:38:35

Persistence Type:Duration

Time remaining:150196224

2025-11-30T19:38:35.229 Dynamic signature received

2025-11-30T19:38:35.231 [Cloud] End of cloud request.

2025-11-30T19:38:35.310 [Cloud] SubmitReport(CMpBmSpyNetReportContext)

2025-11-30T19:38:35.310 [Cloud] Start of cloud request. Passive mode: 0

2025-11-30T19:38:35.310 [Cloud] Queued cloud request.

2025-11-30T19:38:35.311 [Cloud] Dequeued cloud request.

2025-11-30T19:38:35.314 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-30T19:38:35.456 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-11-30T19:38:35.456 [Cloud] End of cloud request.

2025-11-30T19:38:35.762 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T19:39:00.601 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T19:40:45.530 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #475989, FileId: 0x4000000097164, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:52:07.485 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #476064, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:52:07.488 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #476065, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:52:17.489 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #476076, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:52:17.492 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #476077, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T19:54:05.590 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T19:55:45.777 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #476142, FileId: 0x2000000097330, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T20:03:41.646 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #476193, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T20:06:12.066 Bm signature throttled:0x00002db31bed458f

2025-11-30T20:09:10.581 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T20:10:46.042 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #478448, FileId: 0x80000000957f0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T20:24:15.581 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T20:25:47.472 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #478541, FileId: 0x200000009744f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T20:28:02.415 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 32837, Count: 2425, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume4\xampp\sendmail\sendmail.exe, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3871, Count: 393, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\1736ea23-1215-4886-89d8-581503f36dde.tmp, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 3227, Count: 264, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\b07e42fc-1469-488c-8828-bc63ffde08a4.tmp, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: SrTasks.exe, Pid: 19504, TotalTime: 3019, Count: 857, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{2e2e64e3-2827-42b9-90f3-f869793f41d9}_OnDiskSnapshotProp, EstimatedImpact: 10%

2025-11-30T20:28:02.416 ProcessImageName: NVIDIA Overlay.exe, Pid: 30592, TotalTime: 2039, Count: 208, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\osc\main.497d57969ef1c036.js, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1535, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 85%

2025-11-30T20:28:02.416 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1215, Count: 197, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 976, Count: 158, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Media\Filmer\2160p\Mufasa.The.Lion.King.2024.2160p.4K.WEB.x265.10bit.AAC5.1-[YTS.MX].mkv, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 33524, TotalTime: 774, Count: 26, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2509.19002.0_x64__8wekyb3d8bbwe\MicrosoftSecurityApp\Microsoft.Unified.Telemetry.dll, EstimatedImpact: 2%

2025-11-30T20:28:02.416 ProcessImageName: FileZilla_Server_1.12.0_win64-setup.exe, Pid: 32268, TotalTime: 739, Count: 37, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\nsdFF0B.tmp\Uninstall.exe, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: RuntimeBroker.exe, Pid: 28720, TotalTime: 540, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-30T20:28:02.416 ProcessImageName: NVIDIA Overlay.exe, Pid: 26688, TotalTime: 527, Count: 54, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\8ad7e701-76a3-4654-9380-724c52b0ea83.tmp, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 435, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: taskhostw.exe, Pid: 6500, TotalTime: 420, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 24%

2025-11-30T20:28:02.416 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 420, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Fonts\SegoeIcons.ttf, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: filezilla-server.exe, Pid: 26760, TotalTime: 417, Count: 15, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\libstdc++-6.dll, EstimatedImpact: 100%

2025-11-30T20:28:02.416 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 405, Count: 61, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: filezilla-server-gui.exe, Pid: 21940, TotalTime: 374, Count: 4, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\wxmsw32u_core_gcc_custom.dll, EstimatedImpact: 100%

2025-11-30T20:28:02.416 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 330, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: powershell.exe, Pid: 29536, TotalTime: 320, Count: 38, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\4acfdbda9fe7d2c227cd2d57ea292ba9\System.Management.Automation.ni.dll, EstimatedImpact: 29%

2025-11-30T20:28:02.416 ProcessImageName: WmiPrvSE.exe, Pid: 19664, TotalTime: 315, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\wstorvsp.inf->(UTF-16LE), EstimatedImpact: 26%

2025-11-30T20:28:02.416 ProcessImageName: WmiPrvSE.exe, Pid: 3456, TotalTime: 307, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\smbdirect.sys, EstimatedImpact: 84%

2025-11-30T20:28:02.416 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 285, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\886aa96a-282a-4a0a-bb27-0df7e5a0f78b.tmp, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: nvcontainer.exe, Pid: 12680, TotalTime: 242, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\UXD\Log.nvcontainer.exe.log, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 225, Count: 36, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 225, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: php-cgi.exe, Pid: 15844, TotalTime: 212, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\php\ext\php_bz2.dll, EstimatedImpact: 85%

2025-11-30T20:28:02.416 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 210, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: filezilla-server-gui.exe, Pid: 30560, TotalTime: 168, Count: 16, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\libstdc++-6.dll, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: nvcontainer.exe, Pid: 21216, TotalTime: 136, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\UXD\Log.nvcontainer.exe.log, EstimatedImpact: 6%

2025-11-30T20:28:02.416 ProcessImageName: ngentask.exe, Pid: 28420, TotalTime: 135, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 13%

2025-11-30T20:28:02.416 ProcessImageName: ngentask.exe, Pid: 8312, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 13%

2025-11-30T20:28:02.416 ProcessImageName: ngentask.exe, Pid: 19836, TotalTime: 135, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 26%

2025-11-30T20:28:02.416 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: WmiPrvSE.exe, Pid: 22576, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 100%

2025-11-30T20:28:02.416 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 105, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping11060_1301338752\manifest.json, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: ngentask.exe, Pid: 6228, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 15%

2025-11-30T20:28:02.416 ProcessImageName: taskhostw.exe, Pid: 14168, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 3%

2025-11-30T20:28:02.416 ProcessImageName: ffdetect.exe, Pid: 34384, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 14%

2025-11-30T20:28:02.416 ProcessImageName: wallpaper32.exe, Pid: 32536, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 19%

2025-11-30T20:28:02.416 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: ngentask.exe, Pid: 29596, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 31%

2025-11-30T20:28:02.416 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: ffdetect.exe, Pid: 34552, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 8%

2025-11-30T20:28:02.416 ProcessImageName: ngentask.exe, Pid: 22056, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 28%

2025-11-30T20:28:02.416 ProcessImageName: StoreDesktopExtension.exe, Pid: 29536, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: nvcontainer.exe, Pid: 32644, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\UXD\Log.nvcontainer.exe.log, EstimatedImpact: 40%

2025-11-30T20:28:02.416 ProcessImageName: taskhostw.exe, Pid: 8684, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-30T20:28:02.416 ProcessImageName: wallpaper32.exe, Pid: 14656, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 41%

2025-11-30T20:28:02.416 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 16%

2025-11-30T20:28:02.416 ProcessImageName: PhoneExperienceHost.exe, Pid: 1316, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Desktop\desktop.ini->(UTF-16LE), EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: tzsync.exe, Pid: 29608, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Globalization\Time Zone\timezones.xml->(UTF-8), EstimatedImpact: 3%

2025-11-30T20:28:02.416 ProcessImageName: NVIDIA Overlay.exe, Pid: 18040, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 7%

2025-11-30T20:28:02.416 ProcessImageName: taskhostw.exe, Pid: 29820, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 17%

2025-11-30T20:28:02.416 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 20%

2025-11-30T20:28:02.416 ProcessImageName: ngentask.exe, Pid: 21860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 28%

2025-11-30T20:28:02.416 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: NVIDIA Overlay.exe, Pid: 12148, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 13%

2025-11-30T20:28:02.416 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: powershell.exe, Pid: 26000, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Prefetch\POWERSHELL.EXE-022A1004.pf, EstimatedImpact: 3%

2025-11-30T20:28:02.416 ProcessImageName: taskhostw.exe, Pid: 27120, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-30T20:28:02.416 ProcessImageName: nvngx_update.exe, Pid: 22732, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 2%

2025-11-30T20:28:02.416 ProcessImageName: updater.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\35583fa7-6de8-4d40-890b-637e3d445738.tmp, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 4%

2025-11-30T20:28:02.416 ProcessImageName: dllhost.exe, Pid: 18876, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: powershell.exe, Pid: 34288, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\__PSScriptPolicyTest_hmgncxrg.yzl.ps1, EstimatedImpact: 0%

2025-11-30T20:28:02.416 ProcessImageName: powershell.exe, Pid: 6100, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\__PSScriptPolicyTest_rf531tas.stx.psm1, EstimatedImpact: 0%

2025-11-30T20:28:02.417 ProcessImageName: nvngx_update.exe, Pid: 29152, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-30T20:28:02.417 ProcessImageName: updater.exe, Pid: 2212, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\0f165b58-4606-4b01-a765-9e423175d087.tmp, EstimatedImpact: 0%

2025-11-30T20:39:20.576 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T20:40:47.657 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #478688, FileId: 0x20000000974d2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T20:51:44.893 Bm signature throttled:0x00002db31bed458f

2025-11-30T20:52:07.107 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #481878, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T20:52:07.118 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #481879, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T20:54:25.576 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T20:54:38.020 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T21:09:30.572 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T21:24:35.562 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T21:31:10.598 Bm signature throttled:0x00002db31bed458f

2025-11-30T21:33:26.492 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T21:39:40.558 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T21:41:42.210 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\MLB 511 512 522 523 m�leresultat.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #487546, FileId: 0x200000001fad5, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T21:52:06.505 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #487665, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T21:54:45.552 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T22:09:50.548 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T22:19:20.777 [RTP] [Mini-filter] Unsuccessful scan status(#130): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Elektroteknikk\20230904_104627.jpg. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #488919, FileId: 0x117000000019a17, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T22:24:55.547 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T22:28:02.393 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 67195, Count: 6301, MaxTime: 1375, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Mozilla Firefox\updated\xul.dll, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4090, Count: 320, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\b07e42fc-1469-488c-8828-bc63ffde08a4.tmp, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3871, Count: 393, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\1736ea23-1215-4886-89d8-581503f36dde.tmp, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: SrTasks.exe, Pid: 19504, TotalTime: 3019, Count: 857, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{2e2e64e3-2827-42b9-90f3-f869793f41d9}_OnDiskSnapshotProp, EstimatedImpact: 10%

2025-11-30T22:28:02.393 ProcessImageName: NVIDIA Overlay.exe, Pid: 30592, TotalTime: 2039, Count: 208, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\osc\main.497d57969ef1c036.js, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: NVIDIA Overlay.exe, Pid: 26688, TotalTime: 1603, Count: 139, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\8ad7e701-76a3-4654-9380-724c52b0ea83.tmp, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1535, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 85%

2025-11-30T22:28:02.393 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1215, Count: 197, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 976, Count: 158, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Media\Filmer\2160p\Mufasa.The.Lion.King.2024.2160p.4K.WEB.x265.10bit.AAC5.1-[YTS.MX].mkv, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 33524, TotalTime: 774, Count: 26, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2509.19002.0_x64__8wekyb3d8bbwe\MicrosoftSecurityApp\Microsoft.Unified.Telemetry.dll, EstimatedImpact: 2%

2025-11-30T22:28:02.393 ProcessImageName: FileZilla_Server_1.12.0_win64-setup.exe, Pid: 32268, TotalTime: 739, Count: 37, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\nsdFF0B.tmp\Uninstall.exe, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: RuntimeBroker.exe, Pid: 28720, TotalTime: 540, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-30T22:28:02.393 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 465, Count: 71, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 435, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 421, Count: 49, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: taskhostw.exe, Pid: 6500, TotalTime: 420, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 24%

2025-11-30T22:28:02.393 ProcessImageName: explorer.exe, Pid: 8868, TotalTime: 420, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Fonts\SegoeIcons.ttf, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: filezilla-server.exe, Pid: 26760, TotalTime: 417, Count: 15, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\libstdc++-6.dll, EstimatedImpact: 100%

2025-11-30T22:28:02.393 ProcessImageName: filezilla-server-gui.exe, Pid: 21940, TotalTime: 374, Count: 4, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\wxmsw32u_core_gcc_custom.dll, EstimatedImpact: 100%

2025-11-30T22:28:02.393 ProcessImageName: powershell.exe, Pid: 29536, TotalTime: 320, Count: 38, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\4acfdbda9fe7d2c227cd2d57ea292ba9\System.Management.Automation.ni.dll, EstimatedImpact: 29%

2025-11-30T22:28:02.393 ProcessImageName: WmiPrvSE.exe, Pid: 19664, TotalTime: 315, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\INF\wstorvsp.inf->(UTF-16LE), EstimatedImpact: 26%

2025-11-30T22:28:02.393 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 315, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: WmiPrvSE.exe, Pid: 3456, TotalTime: 307, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\smbdirect.sys, EstimatedImpact: 84%

2025-11-30T22:28:02.393 ProcessImageName: NVIDIA Overlay.exe, Pid: 20108, TotalTime: 285, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\886aa96a-282a-4a0a-bb27-0df7e5a0f78b.tmp, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 256, Count: 50, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\AdoptionHeartbeat$, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 255, Count: 46, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_GE0MT4T09OKVDI8S\e_C2GK9UTC67FSUCG3\Accounts\r_PHM3PP4J9R6J6TVI.bin, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: nvcontainer.exe, Pid: 12680, TotalTime: 242, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\UXD\Log.nvcontainer.exe.log, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: php-cgi.exe, Pid: 15844, TotalTime: 212, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\xampp\php\ext\php_bz2.dll, EstimatedImpact: 85%

2025-11-30T22:28:02.393 ProcessImageName: filezilla-server-gui.exe, Pid: 30560, TotalTime: 168, Count: 16, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume4\Program Files\FileZilla Server\libstdc++-6.dll, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: nvcontainer.exe, Pid: 21216, TotalTime: 136, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\UXD\Log.nvcontainer.exe.log, EstimatedImpact: 6%

2025-11-30T22:28:02.393 ProcessImageName: ngentask.exe, Pid: 28420, TotalTime: 135, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 13%

2025-11-30T22:28:02.393 ProcessImageName: ngentask.exe, Pid: 8312, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 13%

2025-11-30T22:28:02.393 ProcessImageName: ngentask.exe, Pid: 19836, TotalTime: 135, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 26%

2025-11-30T22:28:02.393 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 108, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-11-30T22:28:02.393 ProcessImageName: WmiPrvSE.exe, Pid: 22576, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\pacer.sys, EstimatedImpact: 100%

2025-11-30T22:28:02.393 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 105, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping11060_1301338752\manifest.json, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: backgroundTaskHost.exe, Pid: 19988, TotalTime: 105, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1735914446, EstimatedImpact: 23%

2025-11-30T22:28:02.394 ProcessImageName: OneDrive.exe, Pid: 12020, TotalTime: 105, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\ID\r_74DB6FURNR2TGPBK\c_6HM880EG8H6C0PCE.bin, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: ngentask.exe, Pid: 6228, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 15%

2025-11-30T22:28:02.394 ProcessImageName: taskhostw.exe, Pid: 14168, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\USBHUB3.SYS, EstimatedImpact: 3%

2025-11-30T22:28:02.394 ProcessImageName: ffdetect.exe, Pid: 34384, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 14%

2025-11-30T22:28:02.394 ProcessImageName: wallpaper32.exe, Pid: 32536, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 19%

2025-11-30T22:28:02.394 ProcessImageName: nvcontainer.exe, Pid: 9892, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: ngentask.exe, Pid: 29596, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log->(UTF-8), EstimatedImpact: 31%

2025-11-30T22:28:02.394 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 45, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: ngentask.exe, Pid: 22056, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 28%

2025-11-30T22:28:02.394 ProcessImageName: ffdetect.exe, Pid: 34552, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 8%

2025-11-30T22:28:02.394 ProcessImageName: StoreDesktopExtension.exe, Pid: 29536, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: nvcontainer.exe, Pid: 32644, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\NVIDIA app\UXD\Log.nvcontainer.exe.log, EstimatedImpact: 40%

2025-11-30T22:28:02.394 ProcessImageName: taskhostw.exe, Pid: 8684, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 2%

2025-11-30T22:28:02.394 ProcessImageName: wallpaper32.exe, Pid: 14656, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 41%

2025-11-30T22:28:02.394 ProcessImageName: RuntimeBroker.exe, Pid: 10784, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 16%

2025-11-30T22:28:02.394 ProcessImageName: PhoneExperienceHost.exe, Pid: 1316, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\Desktop\desktop.ini->(UTF-16LE), EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: tzsync.exe, Pid: 29608, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Globalization\Time Zone\timezones.xml->(UTF-8), EstimatedImpact: 3%

2025-11-30T22:28:02.394 ProcessImageName: NVIDIA Overlay.exe, Pid: 18040, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps->(UTF-16LE), EstimatedImpact: 7%

2025-11-30T22:28:02.394 ProcessImageName: NVDisplay.Container.exe, Pid: 3928, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nv_dispi.PNF, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: steamwebhelper.exe, Pid: 15868, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamui\css\library.css, EstimatedImpact: 20%

2025-11-30T22:28:02.394 ProcessImageName: ngentask.exe, Pid: 21860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 28%

2025-11-30T22:28:02.394 ProcessImageName: taskhostw.exe, Pid: 29820, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 17%

2025-11-30T22:28:02.394 ProcessImageName: NVIDIA Overlay.exe, Pid: 12148, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Drs\nvAppTimestamps, EstimatedImpact: 13%

2025-11-30T22:28:02.394 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 32068, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\.ses, EstimatedImpact: 2%

2025-11-30T22:28:02.394 ProcessImageName: ProductAgentService.exe, Pid: 20516, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Bitdefender Agent\27.1.1.23\storage\user_context, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: powershell.exe, Pid: 26000, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\Prefetch\POWERSHELL.EXE-022A1004.pf, EstimatedImpact: 3%

2025-11-30T22:28:02.394 ProcessImageName: taskhostw.exe, Pid: 27120, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 8%

2025-11-30T22:28:02.394 ProcessImageName: taskhostw.exe, Pid: 30468, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-11-30T22:28:02.394 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 6584, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 4%

2025-11-30T22:28:02.394 ProcessImageName: nvngx_update.exe, Pid: 22732, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 2%

2025-11-30T22:28:02.394 ProcessImageName: updater.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\35583fa7-6de8-4d40-890b-637e3d445738.tmp, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: dllhost.exe, Pid: 18876, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: powershell.exe, Pid: 34288, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\__PSScriptPolicyTest_hmgncxrg.yzl.ps1, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: powershell.exe, Pid: 6100, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\__PSScriptPolicyTest_rf531tas.stx.psm1, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: updater.exe, Pid: 24360, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\5285f6c9-f4c4-44e2-9317-eefc14a9a59f.tmp, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: updater.exe, Pid: 2212, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\0f165b58-4606-4b01-a765-9e423175d087.tmp, EstimatedImpact: 0%

2025-11-30T22:28:02.394 ProcessImageName: nvngx_update.exe, Pid: 29152, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\config\versions\2\files\nvngx_server_config.txt, EstimatedImpact: 0%

2025-11-30T22:29:37.313 UpdateEngine start: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\B439570B-4819-41CB-B5E7-AFB8EA3CAD167c1c.1dc6248ce919f8c

2025-11-30T22:29:37.344 Verifying engine and signature files (source: 0) ...

2025-11-30T22:29:37.344 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5211EFEE-5E08-4D7E-B831-D58723FAD9D4}\mpengine.dll] due to PPL.

2025-11-30T22:29:37.345 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5211EFEE-5E08-4D7E-B831-D58723FAD9D4}\mpasbase.vdm] (file in cache)

2025-11-30T22:29:37.345 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5211EFEE-5E08-4D7E-B831-D58723FAD9D4}\mpasdlta.vdm]. File not in cache (0x1)

2025-11-30T22:29:37.355 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5211EFEE-5E08-4D7E-B831-D58723FAD9D4}\mpasdlta.vdm]

2025-11-30T22:29:37.355 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5211EFEE-5E08-4D7E-B831-D58723FAD9D4}\mpavbase.vdm] (file in cache)

2025-11-30T22:29:37.355 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5211EFEE-5E08-4D7E-B831-D58723FAD9D4}\mpavdlta.vdm]. File not in cache (0x1)

2025-11-30T22:29:37.366 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5211EFEE-5E08-4D7E-B831-D58723FAD9D4}\mpavdlta.vdm]

2025-11-30T22:29:37.443 [Engine] IsHybridMode: 0

2025-11-30T22:29:37.444 [KSL]KSL(1.1.25080.5) Is available via CAMP. KslDevice : KslD, TDTDevice : TDT

2025-11-30T22:29:37.456 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3F846862EA38BD6725E933D76F89C8CBB6C7EF39.bin): 0x00000002

2025-11-30T22:29:37.457 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3F846862EA38BD6725E933D76F89C8CBB6C7EF39.bin)

2025-11-30T22:29:37.457 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0

2025-11-30T22:29:37.457 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0

2025-11-30T22:29:37.457 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0

2025-11-30T22:29:37.457 Database:kLCID:1044, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, fTdtCapable:1, fTdtUVE:0, dwTDTSiloType:0, kOOsVersion:655360, kOsSP:0, kOsBld:26200, dwPvpRing=0xffffffff

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-30T22:29:42.714 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx

2025-11-30T22:29:42.715 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

2025-11-30T22:29:42.722 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE7225A660, lRefCount: 5, hr=0

2025-11-30T22:29:42.722 [Engine] New active engine 00007FFE73B0A660 replacing engine 00007FFE7225A660. Number of active engines: 2

2025-11-30T22:29:42.729 EngineInit:Global ASOC is enabled

2025-11-30T22:29:42.729 EngineInit:ASOO is enabled for developer volumes

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.760 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

2025-11-30T22:29:42.763 MpWriteUupSignatureVersion 1.441.617.0, hr = 0

2025-11-30T22:29:42.765 ForceSyncMoacInsertion config from engine is 0, hr = 0x0

2025-11-30T22:29:42.777 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit

2025-11-30T22:29:42.778 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0

2025-11-30T22:29:42.778 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)!

2025-11-30T22:29:42.778 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)!

2025-11-30T22:29:42.778 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-11-30T22:29:42.792 MpUpdateUpdateResiliencyConfiguration updated to 0

2025-11-30T22:29:42.793 [Plugin] Initializing RTP plugin state...

2025-11-30T22:29:42.793 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off.

2025-11-30T22:29:42.793 [RTP] 

****************************RTP Perf Log***************************

RTP Start: 11 - 30 - 2025 11:28:02

Last Perf: 11 - 30 - 2025 11:28:02

First RTP Scan: 11 - 30 - 2025 11:28:03

Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1

Process Exclusions:

Path Exclusions:

Ext Exclusions:

Temp Exclusions:

Worker Threads:

  AM:50

  Async:4

Cache Flushes:

  RTP:1

System File Cache:

  Hits:11901

  Misses:15998

BM Queue:0,117,0

  Proc:0,110,0

  File:0,61,0

Plugin Queue:0,1,0

  Threat:0,0,0

  Susp:0,1,0

  Unknown:0,0,0

  Error:0,0,0

Request Queue:1,3,0

  SetEngine:1,1,0

  SetState:0,1,0

  SetUser:0,0,0

  Config:0,2,0

  ProcExcl:0,1,0

  FilterReload:0,0,0

  FilterUnload:0,0,0

MpFilter:

  Scans:489256

  Pending:0

  RegSize:306586

  AsyncQNotif:0

  AsyncQMissed:0

  AsyncQTotalSent:-1014638132

  AsyncQCurrent:0

  BMFlags:56543

  ServiceMaj:0

  ServiceMin:0

  NumInstance:21

  TotalStreamCon:15907

  NTFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:2973224

   TotalHits:4056792

   InstanceCacheInserts:171745

   InstanceCacheUpdates:0

   InstanceCacheDeletes:134363

   InstanceCacheHits:6244

   InstanceCacheMisses:707506

   InstanceCacheOverflows:11511

  CSVFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  REFS Cache Statistics (Instance Cache Type:GenericTable):

   TotalMisses:0

   TotalHits:0

   InstanceCacheInserts:0

   InstanceCacheUpdates:0

   InstanceCacheDeletes:0

   InstanceCacheHits:0

   InstanceCacheMisses:0

   InstanceCacheOverflows:0

  SyncProcessCreateDuration:0ms (1256/1616)

   Success: 1616, failures: 0 (last code: 0x0), timeouts: 0,  baddata: 0

 

**************************END RTP Perf Log*************************



 

 



2025-11-30T22:29:42.793 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5211EFEE-5E08-4D7E-B831-D58723FAD9D4}

2025-11-30T22:29:42.793 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79DD1250-8DFF-48A3-8A4E-9E0E40788266}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79DD1250-8DFF-48A3-8A4E-9E0E40788266}\mpasbase.vdm in use, hr=0x80070020

2025-11-30T22:29:42.793 [SCC][CID=1227014468_28548] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"}

2025-11-30T22:29:42.794 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-30T22:29:42.794 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-30T22:29:42.794 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-30T22:29:42.795 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-30T22:29:42.795 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-30T22:29:42.795 MdCoreSvc is supported in this platform and OS

Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:131074

Start time:11-30-2025 22:29:42

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:11-30-2025 22:29:42

2025-11-30T22:29:42.798 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-30T22:29:42.798 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

BmLoggingDisabled:MpDisableBmLogging not set.

2025-11-30T22:29:42.799 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0

2025-11-30T22:29:42.799 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0



BEGIN TDT(U) telemetry 

Instance:0

Config:User Choice to Enable TDT : 0, TDT DC MpDisableBmTdt : 1, TDT DC MpDisableBmTdtOnServer : 1

Timestamp:11-30-2025 22:29:42

END TDT(U) telemetry



2025-11-30T22:29:42.801 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T22:29:42.802 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f

2025-11-30T22:29:42.802 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f

2025-11-30T22:29:42.802 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f

2025-11-30T22:29:42.802 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f

2025-11-30T22:29:42.802 MdCoreSvc is supported in this platform and OS

Signature updated on 11-30-2025 22:29:42

Product Version: 4.18.25100.9008

Service Version: 4.18.25100.9008

Engine Version: 1.1.25100.9002

AS Signature Version: 1.441.617.0

AV Signature Version: 1.441.617.0

************************************************************

2025-11-30T22:29:42.803 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0

2025-11-30T22:29:42.803 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\WINDOWS\Temp\B439570B-4819-41CB-B5E7-AFB8EA3CAD167c1c.1dc6248ce919f8c

2025-11-30T22:29:42.811 Process scan (postsignatureupdatescan) started.

2025-11-30T22:29:42.845 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True

2025-11-30T22:29:42.846 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0

2025-11-30T22:29:42.979 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-30T22:29:42.979 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-30T22:29:42.979 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-30T22:29:42.979 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-30T22:29:42.979 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-30T22:29:42.982 [Engine] Engine 00007FFE7225A660 no longer in use. Number of active engines: 1

2025-11-30T22:29:42.982 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-30T22:29:42.982 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0).

2025-11-30T22:29:43.120 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 67392, Count: 6314, MaxTime: 1375, MaxTimeFile: \Device\HarddiskVolume4\Program Files\Mozilla Firefox\updated\xul.dll, EstimatedImpact: 0%

2025-11-30T22:29:43.121 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 4105, Count: 321, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\b07e42fc-1469-488c-8828-bc63ffde08a4.tmp, EstimatedImpact: 0%

2025-11-30T22:29:43.121 ProcessImageName: NVIDIA Overlay.exe, Pid: 21776, TotalTime: 3871, Count: 393, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\1736ea23-1215-4886-89d8-581503f36dde.tmp, EstimatedImpact: 0%

2025-11-30T22:29:43.121 ProcessImageName: SrTasks.exe, Pid: 19504, TotalTime: 3019, Count: 857, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume4\System Volume Information\SPP\OnlineMetadataCache\{2e2e64e3-2827-42b9-90f3-f869793f41d9}_OnDiskSnapshotProp, EstimatedImpact: 10%

2025-11-30T22:29:43.121 ProcessImageName: NVIDIA Overlay.exe, Pid: 30592, TotalTime: 2039, Count: 208, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\osc\main.497d57969ef1c036.js, EstimatedImpact: 0%

2025-11-30T22:29:43.121 ProcessImageName: NVIDIA Overlay.exe, Pid: 26688, TotalTime: 1634, Count: 140, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\8ad7e701-76a3-4654-9380-724c52b0ea83.tmp, EstimatedImpact: 0%

2025-11-30T22:29:43.121 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1535, Count: 82, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\acpi.sys, EstimatedImpact: 85%

2025-11-30T22:29:43.121 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 1215, Count: 197, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-11-30T22:29:43.121 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 976, Count: 158, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Media\Filmer\2160p\Mufasa.The.Lion.King.2024.2160p.4K.WEB.x265.10bit.AAC5.1-[YTS.MX].mkv, EstimatedImpact: 0%

2025-11-30T22:29:43.121 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 33524, TotalTime: 774, Count: 26, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2509.19002.0_x64__8wekyb3d8bbwe\MicrosoftSecurityApp\Microsoft.Unified.Telemetry.dll, EstimatedImpact: 2%

2025-11-30T22:29:43.121 ProcessImageName: FileZilla_Server_1.12.0_win64-setup.exe, Pid: 32268, TotalTime: 739, Count: 37, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\nsdFF0B.tmp\Uninstall.exe, EstimatedImpact: 0%

2025-11-30T22:29:43.121 ProcessImageName: RuntimeBroker.exe, Pid: 28720, TotalTime: 540, Count: 21, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 35%

2025-11-30T22:29:43.121 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 495, Count: 76, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-11-30T22:29:43.121 ProcessImageName: NVDisplay.Container.exe, Pid: 2848, TotalTime: 435, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\nvtopps\nct\nvlog.nvlgstg, EstimatedImpact: 0%

2025-11-30T22:29:43.121 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 421, Count: 49, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-11-30T22:29:43.121 ProcessImageName: taskhostw.exe, Pid: 6500, TotalTime: 420, Count: 82, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 24%

2025-11-30T22:29:43.144 [Engine] RSIG_UNLOADENGINE, 00007FFE7225A660, err=0x0

2025-11-30T22:29:43.163 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{79DD1250-8DFF-48A3-8A4E-9E0E40788266} removed

2025-11-30T22:29:43.285 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b

IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b

IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b

IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b

IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d

IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b

IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b

2025-11-30T22:29:43.292 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-30T22:29:43.292 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-30T22:29:43.292 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-30T22:29:43.292 [KSL] Entering CKSLEngine::EnableKSL. State: [3]

2025-11-30T22:29:43.292 [KSL] CKSLEngine::EnableKSL feature is already enabled.

2025-11-30T22:29:43.292 [KSL] Leaving CKSLEngine::EnableKsl(0).

2025-11-30T22:29:43.295 [RTP] [RtpConfig] Config change detected, type: 32

2025-11-30T22:29:43.295 [RTP] Duplicating the current plugin configuration object...

2025-11-30T22:29:43.295 [RTP] [RtpConfig] Config change detected, type: 2

2025-11-30T22:29:43.295 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-30T22:29:43.295 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-11-30T22:29:43.295 [RTP] [RtpConfig] Config change detected, type: 4

2025-11-30T22:29:43.295 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-11-30T22:29:43.295 [RTP] No config change detected. Not updating plugin configuration.

2025-11-30T22:29:43.295 [RTP] No config changes found. No configuration switch.

2025-11-30T22:29:43.295 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-11-30T22:29:43.295 [RTP] [RtpConfig] Config change detected, type: 8

2025-11-30T22:29:43.295 [RTP] [RtpConfig] Config change detected, type: 1024

2025-11-30T22:29:43.295 [RTP] [RtpConfig] Config change detected, type: 2048

2025-11-30T22:29:43.295 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-11-30T22:29:43.295 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-11-30T22:29:43.296 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-11-30T22:29:43.296 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-11-30T22:29:43.296 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-11-30T22:29:43.296 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-11-30T22:29:43.296 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-11-30T22:29:43.296 [RTP] PreventPagingFileAbuseKillbit[0].

2025-11-30T22:29:43.296 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-11-30T22:29:43.296 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-11-30T22:29:43.296 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-11-30T22:29:43.296 [RTP] [RtpConfig] Config change detected, type: 64

2025-11-30T22:29:43.296 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T22:29:43.298 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T22:29:43.299 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T22:29:43.301 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T22:29:43.303 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T22:29:43.305 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 19394888(ms) from now at 04:52 (03:52 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-11-30T22:29:44.819 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-30T22:29:44.822 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-11-30T22:29:44.823 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-11-30T22:29:45.849 [RTP] Duplicating the current plugin configuration object...

2025-11-30T22:29:45.849 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-11-30T22:29:45.849 [RTP] Updating plugin configuration due to recent config changes (0x40e) ...

2025-11-30T22:29:45.849 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-11-30T22:29:45.849 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x40e, Changed: 0x218

Internal signature match:subtype=Lowfi, sigseq=0x0000157E383D71D1, sigsha=faefb663cf1224109c940c4e15d9a4bc812e4775, cached=false, source=0, resourceid=0x36d4ed77

2025-11-30T22:29:47.890 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-11-30T22:29:47.890 [Cloud] Start of cloud request. Passive mode: 0

2025-11-30T22:29:47.890 [Cloud] Queued cloud request.

2025-11-30T22:29:47.890 [Cloud] MpEngineCloudRequest(). hr = 0

2025-11-30T22:29:47.891 [Cloud] Dequeued cloud request.

2025-11-30T22:29:47.891 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-11-30T22:29:48.226 [Cloud] End of cloud request.

2025-11-30T22:29:48.745 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-11-30T22:29:56.663 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x192d5e587ffffffe

2025-11-30T22:29:56.663 Process scan (postsignatureupdatescan) completed.

2025-11-30T22:34:42.764 [RbM] Setting Last known good engine candidate. hr = 0

2025-11-30T22:40:00.554 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T22:40:52.207 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #489932, FileId: 0x700000009792b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T22:51:17.591 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Hovedprosjekt\Roadmap.xlsx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #490768, FileId: 0x660000000024ab, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T22:51:19.078 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Hovedprosjekt\ProblemstillingPresentasjon.pptx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #490779, FileId: 0x130000000b845e, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T22:52:06.525 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #490883, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T22:52:06.534 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #490884, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T22:52:16.534 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #490891, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T22:52:16.539 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #490892, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T22:55:05.538 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T22:55:12.007 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\M�leteknikk\Innlevering Varme.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491134, FileId: 0x3a00000000b907, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T22:55:53.517 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #491143, FileId: 0x80000000979be, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T22:56:03.133 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Elektroteknikk\Samling 1\SI enheter.jpg. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491146, FileId: 0x300000001d138, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T22:57:12.137 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\ELN3A Gruppe 5\diverse\Logg1.docx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491149, FileId: 0x3f00000000a98c, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T22:57:16.100 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\ELN3A Gruppe 5\diverse\logg.docx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491150, FileId: 0x12f000000010e00, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T22:57:21.086 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\ELN3A Gruppe 5\diverse\Fremdriftsplan.xlsx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491151, FileId: 0x171000000001f16, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T22:59:41.372 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Elektroteknikk\trekantene\20230427_154618.jpg. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491185, FileId: 0x7900000000f8b8, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T22:59:46.064 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Elektroteknikk\trekantene\20230427_154552.jpg. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491187, FileId: 0x6f000000019117, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T22:59:51.081 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Elektroteknikk\trekantene\20230427_160021.jpg. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491188, FileId: 0xda00000000f787, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T22:59:56.079 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Elektroteknikk\trekantene\20230427_154607.jpg. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491193, FileId: 0xd5000000019de5, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:01:20.128 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Norsk\Samling 1\Oppg1.docx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491220, FileId: 0x600000001f7d4, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:03:00.634 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\PLS\Pr�ve i automatiserte anlegg 04.04.2025.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491243, FileId: 0x29000000003b4e, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:03:10.342 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\PLS\Pr�ve 04.04-olafu-OLAF-SKULEPC.opt. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491244, FileId: 0x600000001c048, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:03:15.336 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\PLS\Pr�ve 04.04.project. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491245, FileId: 0x800000001c045, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:03:20.350 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\PLS\Pr�ve 04.04-AllUsers.opt. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491246, FileId: 0x600000001c042, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:03:25.344 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\PLS\Pr�ve 04.precompilecache. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #491247, FileId: 0x700000001c02d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:10:10.544 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T23:10:53.822 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #491732, FileId: 0x4000000097065, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T23:25:15.540 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T23:25:54.079 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #492131, FileId: 0x7000000097adb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T23:33:28.535 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T23:34:51.898 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Elektroteknikk\Innleveringer\Innlevering 4.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #492376, FileId: 0x1800000000b385, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:34:52.041 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Elektroteknikk\Innleveringer\Innlevering 6.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #492377, FileId: 0x4500000000fcd6, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:34:52.084 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Elektroteknikk\Innleveringer\Innlevering 7.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #492378, FileId: 0xad0000000084b0, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:34:52.122 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Elektroteknikk\Innleveringer\Innlevering 3.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #492379, FileId: 0x4f0000000102c4, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:34:52.184 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Elektroteknikk\Innleveringer\Innlevering 5.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #492380, FileId: 0x980000000153dc, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:34:53.949 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\setup\logs\Install_2025-11-29_223250_28808-18100.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #492438, FileId: 0xd000000090579, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T23:34:54.022 Bm signature throttled:0x0000fab3228bcd4d

2025-11-30T23:39:05.198 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Norsk\Innleveringer\Innlevering 1.docx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #492800, FileId: 0x600000001f851, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:39:05.337 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Norsk\Samling 3\Pr�ve\Referat.docx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #492801, FileId: 0x3000000020d3f, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:39:05.361 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Norsk\Samling 3\Pr�ve\S�knad.docx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #492802, FileId: 0x4000000020d40, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-11-30T23:40:20.525 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T23:40:54.342 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #493292, FileId: 0x7000000097b3d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T23:52:05.576 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #496126, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T23:52:05.579 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #496127, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T23:52:15.588 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #496210, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T23:52:15.591 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #496211, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-11-30T23:55:25.522 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-11-30T23:55:55.799 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #496318, FileId: 0x7000000097bcf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T00:04:14.547 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Engelsk\Work Report.docx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #496453, FileId: 0x6000000000fcf4, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T00:10:30.521 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T00:10:56.194 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #496775, FileId: 0x7000000097c5a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T00:17:05.514 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3

2025-12-01T00:17:05.525 Job Notification: New process added to job (29156)

2025-12-01T00:17:05.532 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched

2025-12-01T00:17:05.533 Aggressive catchup quick scan threshold: 5134402693793 / 25920000000000

2025-12-01T00:17:05.540 Job Notification: New process added to job (27880)

2025-12-01T00:17:05.549 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:29156] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:27880]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-12-01T00:17:05.594 Job Notification: New process added to job (26200)

2025-12-01T00:17:05.596 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched

2025-12-01T00:17:05.598 Job Notification: New process added to job (30736)

2025-12-01T00:17:05.604 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0\MpCmdRun.exe][Pid:26200] from process [\Device\HarddiskVolume4\Windows\System32\conhost.exe][Pid:30736]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4]

2025-12-01T00:17:05.628 Job Notification: New process added to job (18204)

2025-12-01T00:17:05.630 Task(GetDeviceTicket -AccessKey 1203A93C-C759-0B6A-28CB-A97D07076F4C ) launched as network service

2025-12-01T00:17:06.047 [RTP] [RtpConfig] Config change detected, type: 32

2025-12-01T00:17:06.047 [RTP] Duplicating the current plugin configuration object...

2025-12-01T00:17:06.047 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-12-01T00:17:06.047 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-12-01T00:17:06.047 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-12-01T00:17:06.047 [RTP] No config change detected. Not updating plugin configuration.

2025-12-01T00:17:06.047 [RTP] No config changes found. No configuration switch.

2025-12-01T00:17:06.047 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-12-01T00:17:06.092 Job Notification: Process exited from job (18204)

2025-12-01T00:17:06.299 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-12-01T00:17:06.300 [Cloud] Start of cloud request. Passive mode: 0

2025-12-01T00:17:06.300 [Cloud] Queued cloud request.

2025-12-01T00:17:06.300 [Cloud] MpEngineCloudRequest(). hr = 0

2025-12-01T00:17:06.300 [Cloud] Dequeued cloud request.

2025-12-01T00:17:06.300 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-12-01T00:17:06.300 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0

2025-12-01T00:17:06.300 [Cloud] Start of cloud request. Passive mode: 0

2025-12-01T00:17:06.300 [Cloud] Queued cloud request.

2025-12-01T00:17:06.300 [Cloud] Dequeued cloud request.

2025-12-01T00:17:06.302 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

2025-12-01T00:17:06.408 [Cloud] End of cloud request.

2025-12-01T00:17:06.454 [Cloud] MpEngineParseSpyNetResponse(). hr = 0

2025-12-01T00:17:06.456 [Cloud] End of cloud request.

2025-12-01T00:17:06.815 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-12-01T00:17:08.533 Job Notification: Process exited from job (26200)

2025-12-01T00:17:08.535 Job Notification: Process exited from job (30736)

2025-12-01T00:17:08.565 Job Notification: Process exited from job (29156)

2025-12-01T00:17:08.566 Job Notification: Process exited from job (27880)

2025-12-01T00:25:35.512 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T00:25:56.554 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #497361, FileId: 0x7000000097ced, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T00:29:42.701 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 28011, Count: 3440, MaxTime: 500, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA Corporation\Downloader\latest\NvDLISR\nvngx_dlisr.dll, EstimatedImpact: 0%

2025-12-01T00:29:42.701 ProcessImageName: NVIDIA Overlay.exe, Pid: 26688, TotalTime: 1117, Count: 86, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\717c0708-e302-4d70-a1f5-be3c68cdb8ab.tmp, EstimatedImpact: 0%

2025-12-01T00:29:42.701 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 662, Count: 54, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\dbce9e14-f3e2-4ca0-89e2-726295b6bd12.tmp, EstimatedImpact: 0%

2025-12-01T00:29:42.701 ProcessImageName: RuntimeBroker.exe, Pid: 33848, TotalTime: 416, Count: 22, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 30%

2025-12-01T00:29:42.701 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 255, Count: 56, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-12-01T00:29:42.701 ProcessImageName: taskhostw.exe, Pid: 10472, TotalTime: 195, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-12-01T00:29:42.701 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 25168, TotalTime: 150, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-12-01T00:29:42.701 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-12-01T00:29:42.701 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 30756, TotalTime: 90, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 1%

2025-12-01T00:29:42.701 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-12-01T00:29:42.701 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-12-01T00:29:42.701 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-12-01T00:29:42.701 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-12-01T00:29:42.701 ProcessImageName: svchost.exe, Pid: 20276, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT6B8F.tmp, EstimatedImpact: 13%

2025-12-01T00:29:42.701 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\cache\httpclient\0fb243ded9649ae6d18059c674a4ae00, EstimatedImpact: 0%

2025-12-01T00:29:42.701 ProcessImageName: StoreDesktopExtension.exe, Pid: 29272, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-12-01T00:29:42.701 ProcessImageName: updater.exe, Pid: 34704, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-12-01T00:39:07.757 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\ELN3A Gruppe 5\Sign\SindreSign.png. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #498150, FileId: 0x1c00000000a992, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T00:39:17.761 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\ELN3A Gruppe 5\Sign\OlafSign.png. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #498158, FileId: 0x15200000000a99b, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T00:40:22.818 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Skrivebord\Pr�ve samling 6 oppg1.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #498192, FileId: 0xcc0000000154d1, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T00:40:40.506 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T00:40:56.605 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #498227, FileId: 0x7000000097d78, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T00:47:09.439 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Matte\Innleveringer\Innlevering 7.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #498327, FileId: 0xb000000000b3e7, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T00:49:39.366 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Fysikk\Innleveringer\Innlevering 2 i fysikk.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #498364, FileId: 0x4000000020d3a, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T00:49:44.083 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Tegning\Samling 1\oppg1.dwg. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #498365, FileId: 0x300000001fac1, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T00:49:44.924 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Tegning\Samling 1\oppg2.dwg. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #498366, FileId: 0x300000001fa9d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T00:49:49.631 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Tegning\Samling 1\Polyline.dwg. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #498367, FileId: 0x300000001fa9c, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T00:52:07.264 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #498384, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T00:52:07.268 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #498385, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T00:52:17.283 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #498390, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T00:52:17.298 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #498391, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T00:55:45.507 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T00:55:58.097 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #498414, FileId: 0x7000000097e09, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T01:10:50.502 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T01:10:58.178 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #499437, FileId: 0x8000000097e8f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T01:25:55.497 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T01:25:58.833 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #499713, FileId: 0x7000000097f1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T01:35:08.528 Bm signature throttled:0x0000fab3228bcd4d

2025-12-01T01:39:46.467 [AutoPurge] Verification Routine tasks have started.

2025-12-01T01:39:46.467 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set.

2025-12-01T01:39:46.476 [AutoPurge] Routine task for Cache Maintenance has started.

2025-12-01T01:39:46.476 [AutoPurge] Cleanup Routine tasks have started.

2025-12-01T01:39:46.476 [AutoPurge] Routine task for Cache Maintenance ...

2025-12-01T01:39:46.476 [AutoPurge] Routine task for MpSFCBuild ...

2025-12-01T01:39:46.476 [AutoPurge] MpCmIsBuildCompleted() - S_OK

2025-12-01T01:39:46.476 [AutoPurge] MpSignalMaintenanceMode ...

2025-12-01T01:39:46.482 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:12997BB4-D263-40EF-99CB-3BDEEA320450, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1)

2025-12-01T01:39:46.482 Scheduled scan with Id 12997BB4-D263-40EF-99CB-3BDEEA320450 configured CPU priority: normal (LowCpuPriority: 0)

2025-12-01T01:39:46.483 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build.

2025-12-01T01:39:46.483 [SFC] System file cache build is not needed (already completed)

2025-12-01T01:39:46.484 QuickScan:ScanID:12997BB4-D263-40EF-99CB-3BDEEA320450: Quick Scan skipped since it already ran during the past 7 days

2025-12-01T01:39:46.485 QuickScan:ScanID:12997BB4-D263-40EF-99CB-3BDEEA320450: Quick scan finished with error 1223

2025-12-01T01:39:46.485 OnDemandScanWorker: Scan Cancelled! scanId:12997BB4-D263-40EF-99CB-3BDEEA320450, hr = 0x80508018

2025-12-01T01:39:46.487 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0)

2025-12-01T01:39:46.487 [AutoPurge] Purged 0 expired detection item(s) from a total of 1.

2025-12-01T01:39:46.487 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 3, expiration in 86400 seconds)

!ERROR

Begin Quick Scan

Scan ID:{12997BB4-D263-40EF-99CB-3BDEEA320450}

Scan Source:1

Start Time:12-01-2025 01:39:46

Unsuccessful Scan

Return Code:1223

************************************************************



Beginning quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Target:

Flags:65538

Start time:12-01-2025 01:39:46

Finished quarantine recovery

Quarantine ID:{00000000-0000-0000-0000-000000000000}

Result:0

End time:12-01-2025 01:39:46

2025-12-01T01:39:46.491 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ...

2025-12-01T01:39:46.491 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25100.9008-0 ...

2025-12-01T01:39:46.491 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0 ...

2025-12-01T01:39:46.491 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ...

2025-12-01T01:39:46.492 [AutoPurge] Cleanup Routine tasks have ended.

2025-12-01T01:39:46.532 Engine:Setting original file name "mstsc.exe" for "c:\windows\systemresources\mstsc.exe.mun", hr=0x0

2025-12-01T01:39:46.539 EnsureProtectedFolderAcls(), hr = 0x0

2025-12-01T01:39:46.542 [AutoPurge] MpReinforceServiceAcls: 0

2025-12-01T01:39:46.552 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0

2025-12-01T01:39:46.555 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed.

2025-12-01T01:39:46.555 [AutoPurge] Verification Routine tasks have ended.

2025-12-01T01:39:46.561 Engine:Setting original file name "WIARPC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiarpc.dll.mui_0c913b87", hr=0x0

2025-12-01T01:39:46.593 Engine:Setting original file name "nlsbres.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..ocale-nls.resources_31bf3856ad364e35_10.0.26100.4484_nb-no_339b02f7f61c146e\winnlsres.dll.mui", hr=0x0

2025-12-01T01:39:46.735 Engine:Setting original file name "x64launcher.exe" for "c:\program files (x86)\steam\bin\x86launcher.exe", hr=0x0

2025-12-01T01:39:46.905 Engine:Setting original file name "IEXPLORE.EXE" for "c:\program files (x86)\internet explorer\en-us\iexplore.exe.mui", hr=0x0

2025-12-01T01:39:46.945 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_en-us_1258b52c940aadb7_winload.efi.mui_35ee487d", hr=0x0

2025-12-01T01:39:47.394 Engine:Setting original file name "bootmgr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-b..nager-efi.resources_31bf3856ad364e35_10.0.26100.6899_lv-lv_914992ee3a69ab54\bootmgr_ex.efi.mui", hr=0x0

2025-12-01T01:39:47.532 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sr-..-rs_d1943ecc8317ab66_msimsg.dll.mui_72e8994f", hr=0x0

2025-12-01T01:39:47.665 Engine:Setting original file name " " for "c:\program files (x86)\steam\bin\cef\cef.win7x64\dxcompiler.dll", hr=0x0

2025-12-01T01:39:47.863 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\winsxs\wow64_microsoft-windows-bcp47languages_31bf3856ad364e35_10.0.26100.7019_none_40ac55a9bb1ab239\bcp47langs.dll", hr=0x0

2025-12-01T01:39:47.878 Engine:Setting original file name "MAPI32.DLL.MUI" for "c:\windows\system32\nb-no\mapistub.dll.mui", hr=0x0

2025-12-01T01:39:48.088 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-12-01T01:39:48.132 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_ar-sa_af75f4ef024a79a1_msimsg.dll.mui_72e8994f", hr=0x0

2025-12-01T01:39:48.221 Engine:Setting original file name "Apphelp" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a4bb088d5aa4193f97a4bdef0c1f8c71\apphelp.dll.mui", hr=0x0

2025-12-01T01:39:48.274 Engine:Setting original file name "F12Chooser.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-ie-iechooser.resources_31bf3856ad364e35_11.0.26100.1_nb-no_a7630c027f26ac69\iechooser.exe.mui", hr=0x0

2025-12-01T01:39:48.325 Engine:Setting original file name "THEMESERVICE.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-themeservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_5e5bf64d5b3ca824_themeservice.dll.mui_9e71f1ab", hr=0x0

2025-12-01T01:39:48.361 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_ad141a64b8fd6038_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:48.450 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\wow64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.26100.712_none_5cfec91758ee0662\windows.security.credentials.ui.credentialpicker.dll", hr=0x0

2025-12-01T01:39:48.497 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-12-01T01:39:48.500 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-12-01T01:39:48.500 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-12-01T01:39:48.519 Engine:Setting original file name "mavinject32.exe" for "c:\windows\winsxs\wow64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_592d553ad6e77100\mavinject.exe", hr=0x0

2025-12-01T01:39:48.647 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_bfcde09794ad7074_memtest.exe.mui_77b8cbcc", hr=0x0

2025-12-01T01:39:48.680 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\zh-cn\memtest.efi.mui", hr=0x0

2025-12-01T01:39:48.795 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_nb-no_022ea2e874b2cab6_winresume.efi.mui_f412814e", hr=0x0

2025-12-01T01:39:48.810 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\edge\application\142.0.3595.94\vulkan-1.dll", hr=0x0

2025-12-01T01:39:48.875 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lt-lt_11cd7cc1c62eb609_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:49.167 Engine:Setting original file name "WmiApSrv.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiapsrv.exe.mui_b1567840", hr=0x0

2025-12-01T01:39:49.228 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kk-kz_bb9a512b689c9b87_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:49.256 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_pt-br_b5793645604cae79_memtest.efi.mui_71e15c22", hr=0x0

2025-12-01T01:39:49.272 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_he-il_3abd6f82e93c03e5_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:49.282 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.26100.1_en-us_c3d82ef5c0380efa_wudfpf.sys.mui_f61e9e86", hr=0x0

2025-12-01T01:39:49.550 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaihdrx.dll", hr=0x0

2025-12-01T01:39:49.704 Engine:Setting original file name "apisetstub" for "c:\windows\system32\downlevel\api-ms-win-core-file-l1-2-0.dll", hr=0x0

2025-12-01T01:39:49.741 Engine:Setting original file name "l3codec.acm.mui" for "c:\windows\system32\nb-no\l3codeca.acm.mui", hr=0x0

2025-12-01T01:39:49.853 Engine:Setting original file name "w32topl.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_10.0.26100.1_none_cbd0eec659c2eb5c_w32topl.dll_1a0f388b", hr=0x0

2025-12-01T01:39:49.874 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ms-my_6f80e6fda2cebe8f_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:50.170 Engine:Setting original file name "NVPTXJITCOMPILER32.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvptxjitcompiler64.dll", hr=0x0

2025-12-01T01:39:50.234 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5de87d4a39ffc584310f0b06dff9fcd0\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-12-01T01:39:50.304 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_38f499759ea365c4_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:50.366 Engine:Setting original file name "ddputils.lib.mui" for "c:\windows\system32\nb-no\ddputils.dll.mui", hr=0x0

2025-12-01T01:39:50.406 Engine:Setting original file name "apisetstub" for "c:\windows\system32\downlevel\api-ms-win-crt-utility-l1-1-0.dll", hr=0x0

2025-12-01T01:39:50.495 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_kn-in_6e7a81f857a45cbe_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:50.509 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-12-01T01:39:50.512 IWscAVStatus4: 1, 1, 1. hr = 0x0

2025-12-01T01:39:50.513 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1)

2025-12-01T01:39:50.537 Engine:Setting original file name "officeimm.odf" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\office.odf", hr=0x0

2025-12-01T01:39:50.779 Engine:Setting original file name ""AcGenral.dll"" for "c:\windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_10.0.26100.7019_none_a8119654a230db44\acgenral.dll", hr=0x0

2025-12-01T01:39:50.875 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sr-..-rs_7327597d7718c882_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:50.892 Engine:Setting original file name "Hyper-V Host Compute Service Diagnostics Tool" for "c:\windows\winsxs\amd64_hyperv-compute-cont..sticstool.resources_31bf3856ad364e35_10.0.26100.1_en-us_61074b8c7d2f38cf\hcsdiag.exe.mui", hr=0x0

2025-12-01T01:39:50.911 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.32530.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-12-01T01:39:50.956 Engine:Setting original file name "davsvc.dll.mui" for "c:\windows\system32\nb-no\webclnt.dll.mui", hr=0x0

2025-12-01T01:39:50.986 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\nb-no\wsepno.dll.mui", hr=0x0

2025-12-01T01:39:51.000 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x0

2025-12-01T01:39:51.041 Engine:Setting original file name "bootstr.exe.mui" for "c:\windows\system32\nb-no\bootstr.dll.mui", hr=0x0

2025-12-01T01:39:51.069 Engine:Setting original file name "msvcp140_2_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_2_app.dll", hr=0x0

2025-12-01T01:39:51.336 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-libraryloader-l1-1-0.dll", hr=0x0

2025-12-01T01:39:51.341 Engine:Setting original file name "dvsvc.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..rationsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_5c873aff49ea76e6\dcsvc.dll.mui", hr=0x0

2025-12-01T01:39:51.374 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_qps-ploc_5c9773f9ea1ce396_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:51.377 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_cs-cz_7086b4650c9e547c_memtest.efi.mui_71e15c22", hr=0x0

2025-12-01T01:39:51.483 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa78d0db4729269ff4beb393d45ca94a\dnsapi.dll.mui", hr=0x0

2025-12-01T01:39:51.499 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hr-hr_86baa9ad7eed6d52_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:51.546 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ja-jp_ed01f249e53f7235_memtest.exe.mui_77b8cbcc", hr=0x0

2025-12-01T01:39:51.584 Engine:Setting original file name "D3DX10.dll" for "c:\windows\system32\d3dx10_43.dll", hr=0x0

2025-12-01T01:39:51.624 Engine:Setting original file name "OPCTextExtractor.dll" for "c:\windows\winsxs\amd64_windows-senseclient-service_31bf3856ad364e35_10.0.26100.6725_none_43c7c4b43f528182\opctextextractorwin.dll", hr=0x0

2025-12-01T01:39:51.696 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_da-dk_f5abc0a0339bc397_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:51.795 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-conio-l1-1-0.dll", hr=0x0

2025-12-01T01:39:51.928 Engine:Setting original file name "Auto Enrollment DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..utoenroll.resources_31bf3856ad364e35_10.0.26100.1_en-us_b82b35a9c2228d6b\pautoenr.dll.mui", hr=0x0

2025-12-01T01:39:52.041 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\windows\winsxs\amd64_microsoft-textinput-helpers.resources_31bf3856ad364e35_10.0.26100.1_nb-no_2c9a52bac4b766e3\ime_textinputhelpers.dll.mui", hr=0x0

2025-12-01T01:39:52.056 Engine:Setting original file name "Ribbons" for "c:\windows\winsxs\amd64_microsoft-windows-ribbons.resources_31bf3856ad364e35_10.0.26100.1_en-us_f85e1124efc279b5\ribbons.scr.mui", hr=0x0

2025-12-01T01:39:52.104 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\da-dk\memtest.exe.mui", hr=0x0

2025-12-01T01:39:52.169 Engine:Setting original file name "scecli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\978b70ff94ed14c641fe52c5237facec\scecli.dll.mui", hr=0x0

2025-12-01T01:39:52.196 Engine:Setting original file name "mpsdrv.sys.mui" for "c:\windows\winsxs\backup\amd64_networking-mpssvc-drv.resources_31bf3856ad364e35_10.0.26100.1_nb-no_05849dc2762f9d2d_mpsdrv.sys.mui_b2aea3b6", hr=0x0

2025-12-01T01:39:52.221 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-tw_21b451d70c8c2957_memtest.exe.mui_77b8cbcc", hr=0x0

2025-12-01T01:39:52.405 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_2b309b875a6f3e1e_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:52.483 Engine:Setting original file name "Vulkan Runtime" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\vulkan-1.dll", hr=0x0

2025-12-01T01:39:52.529 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-p..i-ntprint.resources_31bf3856ad364e35_10.0.26100.1_en-us_6ff199c21e8ad886\ntprint.dll.mui", hr=0x0

2025-12-01T01:39:52.610 Engine:Setting original file name "bootstr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..environment-strings_31bf3856ad364e35_10.0.26100.1_none_f575b80d757af501\bootstr.dll", hr=0x0

2025-12-01T01:39:52.643 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_zh-cn_fd81e6b68df3d1a9_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:52.819 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-12-01T01:39:52.939 Engine:Setting original file name "liblzma.dll" for "c:\program files\windowsapps\microsoft.6365217ce6eb4_102.2509.19002.0_x64__8wekyb3d8bbwe\lzma.dll", hr=0x0

2025-12-01T01:39:53.079 Engine:Setting original file name "wuapi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\uus\x86\nb-no\c120e79170c204b0e5f1ece795e86e83\wuapicore.dll.mui", hr=0x0

2025-12-01T01:39:53.083 Engine:Setting original file name "apisetstub" for "c:\windows\syswow64\downlevel\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x0

2025-12-01T01:39:53.123 Engine:Setting original file name "apisetstub" for "c:\windows\winsxs\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_10.0.26100.1_none_c4588310e9a6e860\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x0

2025-12-01T01:39:53.161 Engine:Setting original file name "Ontology.dll" for "c:\users\serverpc\appdata\local\nvidia corporation\nvidia app\nvbackend\applicationontology\ontology64.dll", hr=0x0

2025-12-01T01:39:53.324 Engine:Setting original file name "VpnSohDesktop.dll" for "c:\windows\system32\windows.perception.stub.dll", hr=0x0

2025-12-01T01:39:53.416 Engine:Setting original file name "kernel32" for "c:\windows\syswow64\kernel32.dll", hr=0x0

2025-12-01T01:39:53.462 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.549981c3f5f10_4.2308.1005.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-12-01T01:39:53.707 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_b38289243d899c4c_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:53.780 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_82eb3d34cd19fa50_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:53.918 Engine:Setting original file name "Steamclient.dll" for "c:\program files (x86)\steam\steamclient64.dll", hr=0x0

2025-12-01T01:39:54.001 Engine:Setting original file name "VrdUmde.dll" for "c:\windows\winsxs\amd64_gpuvirtualizationumed_31bf3856ad364e35_10.0.26100.1150_none_17421023ba072774\vrdumed.dll", hr=0x0

2025-12-01T01:39:54.016 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.efi.mui", hr=0x0

2025-12-01T01:39:54.235 Engine:Setting original file name "ScreenMagnifier.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-magnify.resources_31bf3856ad364e35_10.0.26100.4202_en-us_916458009c99b6c6\magnify.exe.mui", hr=0x0

2025-12-01T01:39:54.282 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.winmd", hr=0x0

2025-12-01T01:39:54.614 Engine:Setting original file name "bootmgr.exe.mui" for "c:\windows\boot\efi_ex\de-de\bootmgr_ex.efi.mui", hr=0x0

2025-12-01T01:39:54.654 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_lt-lt_ba1ae95b692b9594_msimsg.dll.mui_72e8994f", hr=0x0

2025-12-01T01:39:54.695 Engine:Setting original file name "apisetstub" for "c:\windows\winsxs\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_10.0.26100.1_none_3886c015fe3eadee\api-ms-win-eventlog-legacy-l1-1-0.dll", hr=0x0

2025-12-01T01:39:54.775 Engine:Setting original file name "windows.ui.xaml.resources.win81.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ctui-resourceswin81_31bf3856ad364e35_10.0.26100.1301_none_b7b52abe3d381205_windows.ui.xaml.resources.win81.dll_d426e245", hr=0x0

2025-12-01T01:39:54.898 Engine:Setting original file name "FixSfp.exe" for "c:\program files\bitdefender agent\27.1.1.23\x64\fixsfp64.exe", hr=0x0

2025-12-01T01:39:54.926 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-timezone-l1-1-0.dll", hr=0x0

2025-12-01T01:39:55.020 Engine:Setting original file name "jscript9.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\c3275836e276aea69afa458336037853\jscript9legacy.dll.mui", hr=0x0

2025-12-01T01:39:55.183 Engine:Setting original file name "wdc.dll" for "c:\windows\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.26100.7019_none_37f71bc250da2cd9\wdc.dll.mun", hr=0x0

2025-12-01T01:39:55.256 Engine:Setting original file name "bootmgr.exe.mui" for "c:\windows\boot\efi\en-us\bootmgfw.efi.mui", hr=0x0

2025-12-01T01:39:55.471 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x0

2025-12-01T01:39:55.534 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-profile-l1-1-0.dll", hr=0x0

2025-12-01T01:39:55.780 Engine:Setting original file name "Windows.FileExplorer.Common.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\84c8a2171c12d91e854ffb6a27b39453\windows.fileexplorer.common.dll.mui", hr=0x0

2025-12-01T01:39:55.815 Engine:Setting original file name "connect.dll" for "c:\windows\winsxs\amd64_microsoft-windows-getconnectedwizards_31bf3856ad364e35_10.0.26100.5074_none_01025b56469ad413\connect.dll.mun", hr=0x0

2025-12-01T01:39:56.006 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\system32\wbem\en-us\ndisimplatcim.dll.mui", hr=0x0

2025-12-01T01:39:56.056 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4_memtest.exe.mui_77b8cbcc", hr=0x0

2025-12-01T01:39:56.109 Engine:Setting original file name "apisetstub" for "c:\windows\winsxs\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_10.0.26100.1_none_3886c015fe3eadee\api-ms-win-core-string-l2-1-0.dll", hr=0x0

2025-12-01T01:39:56.159 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-core-localization-l1-2-0.dll", hr=0x0

2025-12-01T01:39:56.229 Engine:Setting original file name "Placeholder.dll" for "c:\windows\winsxs\x86_netfx4-penimc_v0400_b03f5f7f11d50a3a_4.0.15920.102_none_21046749883d249b\penimc_v0400.dll", hr=0x0

2025-12-01T01:39:56.256 Engine:Setting original file name "NvCamera.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\nvcameraallowlisting32.dll", hr=0x0

2025-12-01T01:39:56.577 Engine:Setting original file name ".NET Host Policy -" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\hostpolicy.dll", hr=0x0

2025-12-01T01:39:56.716 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_10.0.26100.7171_none_f70fffd91c8f0404\winload.efi", hr=0x0

2025-12-01T01:39:56.761 Engine:Setting original file name "bootmgr.exe.mui" for "c:\windows\boot\efi_ex\es-es\bootmgfw_ex.efi.mui", hr=0x0

2025-12-01T01:39:57.041 Engine:Setting original file name "AcPlugin.dll" for "c:\windows\apppatch\acplugindlls\pluginwowx86\acplugin_test2.dll", hr=0x0

2025-12-01T01:39:57.084 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sv-se_cac4b549037c269f_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:57.090 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d_memtest.exe.mui_77b8cbcc", hr=0x0

2025-12-01T01:39:57.124 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-12-01T01:39:57.145 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\winsxs\amd64_microsoft-windows-appx-deployment-server_31bf3856ad364e35_10.0.26100.7171_none_fd3893d466902045\applytrustoffline.exe", hr=0x0

2025-12-01T01:39:57.222 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\system32\en-us\pcaevts.dll.mui", hr=0x0

2025-12-01T01:39:57.393 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\wow64_microsoft-windows-a..on-logger.resources_31bf3856ad364e35_10.0.26100.1_en-us_a0e09b8ec526451d\aeevts.dll.mui", hr=0x0

2025-12-01T01:39:57.501 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-12-01T01:39:57.558 Engine:Setting original file name "sbscmp20_mscorwks.dll" for "c:\windows\winsxs\amd64_netfx-shared_registry_whidbey_31bf3856ad364e35_10.0.26100.4202_none_024ec116170c5905\sharedreg12.dll", hr=0x0

2025-12-01T01:39:57.712 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\4f8d3bb436c7\apex_particleschecked_x86.dll", hr=0x0

2025-12-01T01:39:57.809 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_it-it_72537c4985790e22_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:39:57.981 Engine:Setting original file name "EsclWiaDriver.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_esclwiadriver.dll.mui_d4a5b959", hr=0x0

2025-12-01T01:39:58.135 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\da-dk\msprivs.dll.mui", hr=0x0

2025-12-01T01:39:58.138 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-12-01T01:39:58.153 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_es-es_bdfd06f72820647a_memtest.exe.mui_77b8cbcc", hr=0x0

2025-12-01T01:39:58.293 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pl-pl\msprivs.dll.mui", hr=0x0

2025-12-01T01:39:58.311 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-private-l1-1-0.dll", hr=0x0

2025-12-01T01:39:58.340 Engine:Setting original file name "rmactivate.exe.mui" for "c:\windows\syswow64\en-us\rmactivate_isv.exe.mui", hr=0x0

2025-12-01T01:39:58.390 Engine:Setting original file name "Windows SDK" for "c:\windows\syswow64\winmetadata\windows.security.winmd", hr=0x0

2025-12-01T01:39:58.619 Engine:Setting original file name "apex.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\73be2921551d\apex_turbulencefschecked_x86.dll", hr=0x0

2025-12-01T01:39:58.648 Engine:Setting original file name "ScrCons" for "c:\windows\system32\wbem\en-us\scrcons.exe.mui", hr=0x0

2025-12-01T01:39:58.658 Engine:Setting original file name "PtpProv" for "c:\windows\winsxs\amd64_microsoft-windows-t..-provider.resources_31bf3856ad364e35_10.0.26100.1_en-us_eec70481b215edf0\ptpprov.dll.mui", hr=0x0

2025-12-01T01:39:58.708 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\resources\themes\aero\nb-no\aerolite.msstyles.mui", hr=0x0

2025-12-01T01:39:58.924 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_cd255b4d1be69fe9_winload.efi.mui_35ee487d", hr=0x0

2025-12-01T01:39:58.959 Engine:Setting original file name "pegi.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_en-us_58f534214187451c\pegi.rs.mui", hr=0x0

2025-12-01T01:39:58.966 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\syswow64\en-us\wextract.exe.mui", hr=0x0

2025-12-01T01:39:59.492 Engine:Setting original file name "updater.exe" for "c:\program files (x86)\google\update\googleupdate.exe", hr=0x0

2025-12-01T01:39:59.694 Engine:Setting original file name "ServicingBase.dll" for "c:\windows\system32\servicingcommon.dll", hr=0x0

2025-12-01T01:39:59.725 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\en-us\winload.exe.mui", hr=0x0

2025-12-01T01:39:59.815 Engine:Setting original file name "apisetstub" for "c:\windows\winsxs\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_10.0.26100.1_none_c4588310e9a6e860\api-ms-win-core-wow64-l1-1-0.dll", hr=0x0

2025-12-01T01:39:59.843 Engine:Setting original file name "apisetstub" for "c:\windows\system32\downlevel\api-ms-win-crt-math-l1-1-0.dll", hr=0x0

2025-12-01T01:39:59.956 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ai.winmd", hr=0x0

2025-12-01T01:39:59.997 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsmediaplayermedialibrary\nb-no\diagpackage.dll.mui", hr=0x0

2025-12-01T01:40:00.029 Engine:Setting original file name "SyncCenter.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mobsync_31bf3856ad364e35_10.0.26100.7019_none_915d0497f94761b4\synccenter.dll.mun", hr=0x0

2025-12-01T01:40:00.079 Engine:Setting original file name "apisetstub" for "c:\windows\system32\downlevel\api-ms-win-core-memory-l1-1-1.dll", hr=0x0

2025-12-01T01:40:00.137 Engine:Setting original file name "bootmgr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-b..nager-efi.resources_31bf3856ad364e35_10.0.26100.6899_zh-tw_7df97b417d9f8ed3\bootmgfw_ex.efi.mui", hr=0x0

2025-12-01T01:40:00.169 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\system32\wbem\en-us\netadaptercim.dll.mui", hr=0x0

2025-12-01T01:40:00.205 Engine:Setting original file name "WEXTRACT.EXE            .MUI" for "c:\windows\syswow64\nb-no\wextract.exe.mui", hr=0x0

2025-12-01T01:40:00.323 Engine:Setting original file name "NvTelemetry.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvinstallerutil.dll", hr=0x0

2025-12-01T01:40:00.372 Engine:Setting original file name "NvMessageBusBroadcast.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\localsystem\_nvmsgbusbroadcast.dll", hr=0x0

2025-12-01T01:40:00.583 Engine:Setting original file name "NVOPENCL.DLL" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvopencl64.dll", hr=0x0

2025-12-01T01:40:00.593 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x0

2025-12-01T01:40:00.669 Engine:Setting original file name "Ribbons" for "c:\windows\system32\nb-no\ribbons.scr.mui", hr=0x0

2025-12-01T01:40:00.878 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_de-de_bb6100e4729f7310\msprivs.dll.mui", hr=0x0

2025-12-01T01:40:01.061 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_en-gb_943f70b729277031_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:01.098 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570\dnsapi.dll.mui", hr=0x0

2025-12-01T01:40:01.102 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x0

2025-12-01T01:40:01.203 Engine:Setting original file name "expediteupdater" for "c:\program files\microsoft update health tools\expediteupdater.exe", hr=0x0

2025-12-01T01:40:01.262 Engine:Setting original file name "dnsapi" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\5fc58c6fab06ca1651cc2f24f6b3294e\dnsapi.dll.mui", hr=0x0

2025-12-01T01:40:01.387 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-12-01T01:40:01.432 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.skypeapp_15.150.3125.0_x64__kzf8qxf38zg5c\skype\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-12-01T01:40:01.512 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\pt-br\msprivs.dll.mui", hr=0x0

2025-12-01T01:40:01.572 Engine:Setting original file name "vcomp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x0

2025-12-01T01:40:01.630 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_pt-br_45b1cef334010120_msimsg.dll.mui_72e8994f", hr=0x0

2025-12-01T01:40:01.682 Engine:Setting original file name "DismProvPS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-d..ing-management-core_31bf3856ad364e35_10.0.26100.7019_none_c721839bdaa557fd\dismcoreps.dll", hr=0x0

2025-12-01T01:40:01.825 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x0

2025-12-01T01:40:01.864 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\system32\boot\winresume.efi", hr=0x0

2025-12-01T01:40:01.868 Engine:Setting original file name "ProfSvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-profsvc.resources_31bf3856ad364e35_10.0.26100.1_en-us_63afbc426d007f3f_profsvc.dll.mui_32482e9e", hr=0x0

2025-12-01T01:40:01.987 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2cfe4c864d785675f415b7e6aa962e4\msinfo32.exe.mui", hr=0x0

2025-12-01T01:40:02.235 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\6dfad87d7e49db84e1a96c1c1b32fef6\msidntld.dll.mui", hr=0x0

2025-12-01T01:40:02.251 Engine:Setting original file name "colorui.dll" for "c:\windows\winsxs\amd64_microsoft-windows-icm-ui_31bf3856ad364e35_10.0.26100.6725_none_d5fbbf1150ed1caa\colorui.dll.mun", hr=0x0

2025-12-01T01:40:02.266 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7\memtest.exe.mui", hr=0x0

2025-12-01T01:40:02.384 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pa-in_9c6b14ad918eaffd_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:02.405 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ar-sa_51090f9ff64b96bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:02.462 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.26100.1_en-us_c94c280205b42295\bubbles.scr.mui", hr=0x0

2025-12-01T01:40:02.751 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\nb-no\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x0

2025-12-01T01:40:02.776 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-console-l1-2-0.dll", hr=0x0

2025-12-01T01:40:02.793 Engine:Setting original file name "SETUP.EXE.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-wow64-legacy.resources_31bf3856ad364e35_10.0.26100.1_nb-no_735ab890ce560efa\setup16.exe.mui", hr=0x0

2025-12-01T01:40:02.947 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x0

2025-12-01T01:40:02.985 Engine:Setting original file name "RarExt.dll" for "c:\program files\winrar\rarext32.dll", hr=0x0

2025-12-01T01:40:03.029 Engine:Setting original file name "pcw.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-pcw_31bf3856ad364e35_10.0.26100.1150_none_4bf8e6d5066a4f9f_pcw.sys_dbeb0bbd", hr=0x0

2025-12-01T01:40:03.123 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\syswow64\nb-no\ieadvpack.dll.mui", hr=0x0

2025-12-01T01:40:03.165 Engine:Setting original file name "EmbyServer.dll" for "c:\users\serverpc\appdata\roaming\emby-server\system\embyserver.exe", hr=0x0

2025-12-01T01:40:03.272 Engine:Setting original file name "apisetstub" for "c:\windows\syswow64\downlevel\api-ms-win-security-sddl-l1-1-0.dll", hr=0x0

2025-12-01T01:40:03.288 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-environment-l1-1-0.dll", hr=0x0

2025-12-01T01:40:03.452 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2535f07be6867822893c0bd7f299affd\dwmcore.dll.mui", hr=0x0

2025-12-01T01:40:03.475 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_am-et_12002fbedc3ad139_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:03.520 Engine:Setting original file name "mavinject64.exe" for "c:\windows\winsxs\amd64_microsoft-windows-appmanagement-appvwow_31bf3856ad364e35_10.0.26100.6899_none_4ed8aae8a286af05\mavinject.exe", hr=0x0

2025-12-01T01:40:03.685 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_b1cb38b404e84204\seclogon.dll.mui", hr=0x0

2025-12-01T01:40:03.747 Engine:Setting original file name "AuditPolicyGP.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\1e37baae98dce76981781b53776e70b9\auditpolicygpinterop.dll.mui", hr=0x0

2025-12-01T01:40:03.834 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9c4e95300400790b8d8a05d9bf7e1f5c\winnlsres.dll.mui", hr=0x0

2025-12-01T01:40:03.848 Engine:Setting original file name "Windows.UI.FileExplorer.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e981bfd75ae177a858ec5c78a5cfda25\windows.ui.fileexplorer.dll.mui", hr=0x0

2025-12-01T01:40:03.909 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-12-01T01:40:04.125 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ru-ru_e71c93fcf7d6f33e_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:04.189 Engine:Setting original file name "qualityupdateassistant" for "c:\windows\system32\qualityupdateassistant.dll", hr=0x0

2025-12-01T01:40:04.202 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ro-ro_2c617f480dd85974_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:04.205 Engine:Setting original file name "apisetstub" for "c:\windows\winsxs\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_10.0.26100.1_none_c4588310e9a6e860\api-ms-win-crt-string-l1-1-0.dll", hr=0x0

2025-12-01T01:40:04.316 Engine:Setting original file name "wersvc" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d2f884580919ab799dbe1ecd0f275799\wersvc.dll.mui", hr=0x0

2025-12-01T01:40:04.411 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_fa-ir_f7555235024374d9_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:04.444 Engine:Setting original file name "ClrCompression" for "c:\program files\windowsapps\microsoft.net.native.runtime.1.7_1.7.25531.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-12-01T01:40:04.484 Engine:Setting original file name "WIASERVC.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_nb-no_9117e2dfaa8e9b03_wiaservc.dll.mui_54051b53", hr=0x0

2025-12-01T01:40:04.553 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-12-01T01:40:04.589 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_ru-ru_0752c1c778fe6e7c_memtest.exe.mui_77b8cbcc", hr=0x0

2025-12-01T01:40:04.680 Engine:Setting original file name "AM_Delta_Patch_1.441.578.0.exe" for "c:\windows\softwaredistribution\download\f3fd9dcab4ecbaa79ad3abebb78717c90ab90d86", hr=0x0

2025-12-01T01:40:04.722 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-12-01T01:40:05.200 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_id-id_6be80829898706a2_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:05.206 Engine:Setting original file name "STI.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_10.0.26100.1_en-us_d64b3cbf22b2a8d1_sti.dll.mui_00a4f15b", hr=0x0

2025-12-01T01:40:05.220 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\9035fe481934c33719e75dea902d1698\bcastdvruserservice.dll.mui", hr=0x0

2025-12-01T01:40:05.259 Engine:Setting original file name "NVIDIA Debug Dump" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvdebugdump.exe", hr=0x0

2025-12-01T01:40:05.279 Engine:Setting original file name "acpiex.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-acpiex_31bf3856ad364e35_10.0.26100.1150_none_d0b1f61a88e2f0e9_acpiex.sys_6a8b9aed", hr=0x0

2025-12-01T01:40:05.302 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_60b47cf61af27adc_memtest.exe.mui_77b8cbcc", hr=0x0

2025-12-01T01:40:05.319 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x0

2025-12-01T01:40:05.469 Engine:Setting original file name "bootmgr.exe" for "c:\windows\boot\efi_ex\bootmgr_ex.efi", hr=0x0

2025-12-01T01:40:05.547 Engine:Setting original file name "msimsg.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-i..er-engine.resources_31bf3856ad364e35_10.0.26100.1_sv-se_29319a980f7b0983_msimsg.dll.mui_72e8994f", hr=0x0

2025-12-01T01:40:05.549 Engine:Setting original file name "XInput1_3.dll" for "c:\program files (x86)\steam\bin\xpad.dll", hr=0x0

2025-12-01T01:40:05.656 Engine:Setting original file name "pshed.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-pshed_31bf3856ad364e35_10.0.26100.1_none_633b3602ca01eb94_pshed.dll_f6ac239e", hr=0x0

2025-12-01T01:40:05.729 Engine:Setting original file name "ClipSVC.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-client-li..m-service.resources_31bf3856ad364e35_10.0.26100.1_en-us_3f436cbd520195fd_clipsvc.dll.mui_18823613", hr=0x0

2025-12-01T01:40:05.754 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_cy-gb_976c80cbdb5c65c1_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:06.071 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_uk-ua_c5d15aec526b5235_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:06.086 Engine:Setting original file name "CertCredprovider.dll" for "c:\windows\systemresources\certcredprovider.dll.mun", hr=0x0

2025-12-01T01:40:06.198 Engine:Setting original file name "msfltr32.acm" for "c:\windows\winsxs\wow64_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_10.0.26100.1_none_e82ddbd17df6cb5b\msacm32.dll", hr=0x0

2025-12-01T01:40:06.258 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-12-01T01:40:06.274 Engine:Setting original file name "DeviceDisplayStatus.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\fa2036b29172ddc1e3381516f95b7428\devicedisplaystatusmanager.dll.mui", hr=0x0

2025-12-01T01:40:06.329 Engine:Setting original file name "dnsapi" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_nb-no_6dcfa7c5391fe7a2_dnsapi.dll.mui_97465f8a", hr=0x0

2025-12-01T01:40:06.470 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_3cda2262e7ef70ab_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:06.602 Engine:Setting original file name "osloader.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_10.0.26100.7171_none_f70fffd91c8f0404\winload.exe", hr=0x0

2025-12-01T01:40:06.769 Engine:Setting original file name "bootmgr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-b..nager-efi.resources_31bf3856ad364e35_10.0.26100.6899_sk-sk_02b2efdedf2bc622\bootmgfw_ex.efi.mui", hr=0x0

2025-12-01T01:40:06.783 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_et-ee_9786a4bcaafec5cb_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:07.054 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files\mozilla firefox\dxcompiler.dll", hr=0x0

2025-12-01T01:40:07.124 Engine:Setting original file name "Device_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\device\nb-no\edb83efa185c0a23d97fafe6a71cd608\diagpackage.dll.mui", hr=0x0

2025-12-01T01:40:07.150 Engine:Setting original file name "rtutils.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasrtutils_31bf3856ad364e35_10.0.26100.3037_none_a90518339a5ed736_rtutils.dll_243724ab", hr=0x0

2025-12-01T01:40:07.209 Engine:Setting original file name "mycomput.dll" for "c:\windows\systemresources\mycomput.dll.mun", hr=0x0

2025-12-01T01:40:07.277 Engine:Setting original file name "udiapi.dll" for "c:\windows\system32\udiapiclient.dll", hr=0x0

2025-12-01T01:40:07.296 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-12-01T01:40:07.359 Engine:Setting original file name "nvDLPP.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvaidvc.dll", hr=0x0

2025-12-01T01:40:07.364 Engine:Setting original file name "DWrite" for "c:\windows\winsxs\amd64_microsoft-windows-directwrite.resources_31bf3856ad364e35_10.0.26100.1_en-us_8e75f00536c95f8c\dwrite.dll.mui", hr=0x0

2025-12-01T01:40:07.375 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\windows\syswow64\nb-no\mfc40u.dll.mui", hr=0x0

2025-12-01T01:40:07.464 Engine:Setting original file name "bootmgr.exe.mui" for "c:\windows\boot\efi_ex\es-mx\bootmgfw_ex.efi.mui", hr=0x0

2025-12-01T01:40:07.491 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.26100.1_en-us_12a038f1fa40c367_wlrmdr.exe.mui_ee563c83", hr=0x0

2025-12-01T01:40:07.594 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.xaml.winmd", hr=0x0

2025-12-01T01:40:07.596 Engine:Setting original file name "apisetstub" for "c:\windows\syswow64\downlevel\api-ms-win-core-delayload-l1-1-0.dll", hr=0x0

2025-12-01T01:40:07.705 Engine:Setting original file name "raspptp.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-rasbase-raspptp_31bf3856ad364e35_10.0.26100.1882_none_358d932997f7087d_raspptp.sys_25e89db1", hr=0x0

2025-12-01T01:40:07.811 Engine:Setting original file name "l3codec.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\17e7113a56f3171dc40844c9d3ee9e47\l3codeca.acm.mui", hr=0x0

2025-12-01T01:40:07.847 Engine:Setting original file name "bridgeres.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-networkbridge_31bf3856ad364e35_10.0.26100.2454_none_a3b07853b6183928_bridgeres.dll_55e40455", hr=0x0

2025-12-01T01:40:08.104 Engine:Setting original file name "TWINUI.APPCORE.dll" for "c:\windows\systemresources\twinui.appcore.dll.mun", hr=0x0

2025-12-01T01:40:08.107 Engine:Setting original file name "mf.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..oundation.resources_31bf3856ad364e35_10.0.26100.1_en-us_8b9cc1ab2476fea1\mfpmp.exe.mui", hr=0x0

2025-12-01T01:40:08.218 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-processthreads-l1-1-1.dll", hr=0x0

2025-12-01T01:40:08.289 Engine:Setting original file name "FreeImage.dll" for "c:\program files (x86)\steam\steamapps\common\wallpaper_engine\bin\freeimage64.dll", hr=0x0

2025-12-01T01:40:08.295 Engine:Setting original file name "tier0_s.dll" for "c:\program files (x86)\steam\tier0_s64.dll", hr=0x0

2025-12-01T01:40:08.313 Engine:Setting original file name "nvaudcap.dll" for "c:\windows\syswow64\nvaudcap32v.dll", hr=0x0

2025-12-01T01:40:08.326 Engine:Setting original file name "gameoverlayui.exe" for "c:\program files (x86)\steam\gameoverlayui64.exe", hr=0x0

2025-12-01T01:40:08.358 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mi-nz_b80bad72b6b0ee53_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:08.391 Engine:Setting original file name "CertCli" for "c:\windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_10.0.26100.1_en-us_61b2ff4b086153b8\certcli.dll.mui", hr=0x0

2025-12-01T01:40:08.396 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\en-us\wsepno.dll.mui", hr=0x0

2025-12-01T01:40:08.436 Engine:Setting original file name "ConfigurationRemotingServer.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\configurationremotingserver.exe", hr=0x0

2025-12-01T01:40:08.447 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_sr-..-rs_e67ffd847af5d250_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:08.451 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\power\en-us\diagpackage.dll.mui", hr=0x0

2025-12-01T01:40:08.478 Engine:Setting original file name "dplayx.dll" for "c:\windows\winsxs\x86_microsoft-windows-d..directplay8-payload_31bf3856ad364e35_1.0.26100.4202_none_bb7ce817a226517c\dpnaddr.dll", hr=0x0

2025-12-01T01:40:08.748 Engine:Setting original file name "msfltr32.acm.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8836c193640d589410b5cc3dbe67e146\msacm32.dll.mui", hr=0x0

2025-12-01T01:40:08.877 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\amd64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_6a24110114ad15ad_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-12-01T01:40:08.901 Engine:Setting original file name "usk.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\7c8e526d244ad657f882f8bbba0149ec\usk.rs.mui", hr=0x0

2025-12-01T01:40:08.914 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-12-01T01:40:08.938 Engine:Setting original file name "dplayx.dll" for "c:\windows\syswow64\dpmodemx.dll", hr=0x0

2025-12-01T01:40:09.129 Engine:Setting original file name "Register-CimProvider2.exe.mui" for "c:\windows\syswow64\en-us\register-cimprovider.exe.mui", hr=0x0

2025-12-01T01:40:09.197 Engine:Setting original file name "apisetstub" for "c:\windows\syswow64\downlevel\api-ms-win-core-datetime-l1-1-0.dll", hr=0x0

2025-12-01T01:40:09.250 Engine:Setting original file name "metabase.dll.mui" for "c:\windows\winsxs\wow64_microsoft-windows-iis-metabase.resources_31bf3856ad364e35_10.0.26100.1_en-us_8ff50fedc8451a7b\metadata.dll.mui", hr=0x0

2025-12-01T01:40:09.255 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x0

2025-12-01T01:40:09.339 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_de-de_ab2a1f0520f5ef2b_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:09.422 Engine:Setting original file name "wiashext.dll" for "c:\windows\winsxs\amd64_microsoft-windows-w..sition-uicomponents_31bf3856ad364e35_10.0.26100.5074_none_6ae84cc4352bf074\wiashext.dll.mun", hr=0x0

2025-12-01T01:40:09.432 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_6fced6fbf4c0e3e0_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:09.583 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\en-us\diagpackage.dll.mui", hr=0x0

2025-12-01T01:40:09.606 Engine:Setting original file name "windows.ui.xaml.inkcontrols.dll" for "c:\windows\winsxs\backup\wow64_microsoft-windows-ui-xaml-inkcontrols_31bf3856ad364e35_10.0.26100.3323_none_7478bb53490dd7a8_windows.ui.xaml.inkcontrols.dll_523c865d", hr=0x0

2025-12-01T01:40:09.661 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\windows\system32\nb-no\msidntld.dll.mui", hr=0x0

2025-12-01T01:40:09.667 Engine:Setting original file name "glu32" for "c:\windows\winsxs\amd64_microsoft-windows-opengl.resources_31bf3856ad364e35_10.0.26100.1_en-us_9c3b296d3d668ac3\glu32.dll.mui", hr=0x0

2025-12-01T01:40:09.691 Engine:Setting original file name "mf.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mediafoundation_31bf3856ad364e35_10.0.26100.7171_none_384874e2bca9ce3f\mfpmp.exe", hr=0x0

2025-12-01T01:40:09.733 Engine:Setting original file name "scesrv" for "c:\windows\system32\nb-no\scesrv.dll.mui", hr=0x0

2025-12-01T01:40:09.749 Engine:Setting original file name "DWWIN" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ae2b7dc24859d1fa2a509d5b642451b4\dwwin.exe.mui", hr=0x0

2025-12-01T01:40:09.766 Engine:Setting original file name "iscsicpl.exe" for "c:\windows\systemresources\iscsicpl.exe.mun", hr=0x0

2025-12-01T01:40:09.901 Engine:Setting original file name "nvcuvid.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcuvid64.dll", hr=0x0

2025-12-01T01:40:09.936 Engine:Setting original file name "AppHostNameRegistrationVerifier.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\baf91a75f57ca8730dd9a6f926a58dd0\apphostregistrationverifier.exe.mui", hr=0x0

2025-12-01T01:40:09.947 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_en-gb_9672c12aaba943d2_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:10.089 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-rtlsupport-l1-1-0.dll", hr=0x0

2025-12-01T01:40:10.111 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x0

2025-12-01T01:40:10.140 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_gu-in_97d53b15f69aaeca_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:10.188 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hr-hr_84875939fc6b99b1_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:10.208 Engine:Setting original file name "ServDeps.exe.mui" for "c:\windows\syswow64\wbem\nb-no\servdeps.dll.mui", hr=0x0

2025-12-01T01:40:10.244 Engine:Setting original file name "schtasks.exe" for "c:\windows\winsxs\amd64_microsoft-windows-sctasks_31bf3856ad364e35_10.0.26100.6725_none_25e27f3a6574108c\schtasks.exe", hr=0x0

2025-12-01T01:40:10.255 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_tt-ru_e38364b045f31518_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:10.310 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_el-gr_b382575af3d00da3_memtest.efi.mui_71e15c22", hr=0x0

2025-12-01T01:40:10.483 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.26100.1_en-us_0e875971ea5fda56\ieadvpack.dll.mui", hr=0x0

2025-12-01T01:40:10.527 Engine:Setting original file name "apisetstub" for "c:\windows\syswow64\downlevel\api-ms-win-security-cryptoapi-l1-1-0.dll", hr=0x0

2025-12-01T01:40:10.531 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-core-datetime-l1-1-0.dll", hr=0x0

2025-12-01T01:40:10.557 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-12-01T01:40:10.590 Engine:Setting original file name "apisetstub" for "c:\windows\system32\downlevel\api-ms-win-service-winsvc-l1-1-0.dll", hr=0x0

2025-12-01T01:40:10.602 Engine:Setting original file name "user32" for "c:\windows\system32\user32.dll", hr=0x0

2025-12-01T01:40:10.644 Engine:Setting original file name "PowerCPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-powercpl_31bf3856ad364e35_10.0.26100.3624_none_fd8edba4244dccd3\powercpl.dll.mun", hr=0x0

2025-12-01T01:40:10.688 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.642.119.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-12-01T01:40:10.700 Engine:Setting original file name "shutdownui" for "c:\windows\winsxs\amd64_microsoft-windows-shutdownext.resources_31bf3856ad364e35_10.0.26100.1_en-us_9bd0f22e3578c871\shutdownext.dll.mui", hr=0x0

2025-12-01T01:40:10.874 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_fi-fi_5d180ba41d3a56a4\memtest.exe.mui", hr=0x0

2025-12-01T01:40:10.968 Engine:Setting original file name ".NET Host Resolver - 8.0.20" for "c:\users\serverpc\appdata\local\temp\emby-server-updater\hostfxr.dll", hr=0x0

2025-12-01T01:40:10.987 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_bs-..-ba_3017f7e2648d7e73_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:11.082 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_quz-pe_0266e81632046792_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:11.203 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lb-lu_cb546bb0b0d79a98_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:11.240 Engine:Setting original file name "Microsoft� Windows� Operating System" for "c:\windows\winsxs\amd64_microsoft-windows-a..perience-ait-static_31bf3856ad364e35_10.0.26100.7019_none_ccd1f49f5e2b3b28\aitstatic.exe", hr=0x0

2025-12-01T01:40:11.332 Engine:Setting original file name "UNPShared.dll" for "c:\windows\winsxs\amd64_microsoft-windows-update-upshared_31bf3856ad364e35_10.0.26100.5074_none_29764f36135e6d4c\upshared.dll", hr=0x0

2025-12-01T01:40:11.413 Engine:Setting original file name "messagin.dll" for "c:\program files\bitdefender agent\27.1.1.23\messaging.dll", hr=0x0

2025-12-01T01:40:11.419 Engine:Setting original file name "bootmgr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-b..nager-efi.resources_31bf3856ad364e35_10.0.26100.6899_zh-cn_79fd3deb802eb263\bootmgr_ex.efi.mui", hr=0x0

2025-12-01T01:40:11.516 Engine:Setting original file name "WindowsCodecs" for "c:\windows\syswow64\windowscodecs.dll", hr=0x0

2025-12-01T01:40:11.555 Engine:Setting original file name "WerMgr" for "c:\windows\system32\wermgr.exe", hr=0x0

2025-12-01T01:40:11.607 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps..ocm_172acf79d122d81d\memtest.exe.mui", hr=0x0

2025-12-01T01:40:11.610 Engine:Setting original file name "imapi.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bd7c223153b9576fe4c4e66ebf1c6ece\imapi.dll.mui", hr=0x0

2025-12-01T01:40:11.623 Engine:Setting original file name "bootmgr.exe.mui" for "c:\windows\boot\efi_ex\et-ee\bootmgr_ex.efi.mui", hr=0x0

2025-12-01T01:40:11.829 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_hi-in_8555c5797fc8795e_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:11.909 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.26100.1_nb-no_13c1da41c963374e\esrb.rs.mui", hr=0x0

2025-12-01T01:40:11.923 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\updated\nmhproxy.exe", hr=0x0

2025-12-01T01:40:12.006 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x0

2025-12-01T01:40:12.032 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_zh-tw_ff4ad39908e2da78_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:12.036 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-12-01T01:40:12.088 Engine:Setting original file name "microsoftedgedevtools.exe" for "c:\windows\system32\microsoftedgecp.exe", hr=0x0

2025-12-01T01:40:12.111 Engine:Setting original file name "la57setup.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ec428185df2994f7d7954c1efe1b2738\la57setup.exe.mui", hr=0x0

2025-12-01T01:40:12.118 Engine:Setting original file name "wuapi.dll" for "c:\windows\uus\x86\wuapicore.dll", hr=0x0

2025-12-01T01:40:12.193 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\system32\en-us\dsprop.dll.mui", hr=0x0

2025-12-01T01:40:12.465 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-12-01T01:40:12.490 Engine:Setting original file name "etweseproviderresources.dll" for "c:\windows\winsxs\backup\amd64_microsoft-etw-ese_31bf3856ad364e35_10.0.26100.1_none_cc4e7afeeee8d3b1_etweseproviderresources.dll_f21e8ea7", hr=0x0

2025-12-01T01:40:12.564 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_th-th_2821a024e044bada_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:12.566 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x0

2025-12-01T01:40:12.607 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\bf8ce2a53903d9e6d302aee07de95dd9\mfc40u.dll.mui", hr=0x0

2025-12-01T01:40:12.621 Engine:Setting original file name "TAPISRV.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-tapiservice.resources_31bf3856ad364e35_10.0.26100.1_en-us_83c985f74a352be9\tapisrv.dll.mui", hr=0x0

2025-12-01T01:40:12.849 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_lo-la_099683f3cb70d44f_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:12.852 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\msteams_24295.605.3225.8804_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x0

2025-12-01T01:40:12.950 Engine:Setting original file name "wininet.dll" for "c:\windows\systemresources\wininet.dll.mun", hr=0x0

2025-12-01T01:40:12.982 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\nb-no\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x0

2025-12-01T01:40:13.001 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_hu-hu_9dd052ebcaf187fd_memtest.efi.mui_71e15c22", hr=0x0

2025-12-01T01:40:13.004 Engine:Setting original file name "PrintBrmEng.exe.mui" for "c:\windows\system32\spool\tools\en-us\printbrmengine.exe.mui", hr=0x0

2025-12-01T01:40:13.006 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_it-it_4087c8eabdc39e5f_memtest.efi.mui_71e15c22", hr=0x0

2025-12-01T01:40:13.046 Engine:Setting original file name "audioadg.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\f411807b0749e7d602e77baf3c1c4e60\audiodg.exe.mui", hr=0x0

2025-12-01T01:40:13.126 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x0

2025-12-01T01:40:13.208 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-t..iprovider.resources_31bf3856ad364e35_10.0.26100.1_en-us_41b711b4f2db4fe7\rdpsign.exe.mui", hr=0x0

2025-12-01T01:40:13.222 Engine:Setting original file name "apisetstub" for "c:\windows\syswow64\downlevel\api-ms-win-security-lsapolicy-l1-1-0.dll", hr=0x0

2025-12-01T01:40:13.354 Engine:Setting original file name "Video_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\video\nb-no\2ca5a0690699da595bd35a22420a1c04\diagpackage.dll.mui", hr=0x0

2025-12-01T01:40:13.363 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x64__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-12-01T01:40:13.384 Engine:Setting original file name "FvSDKTestClientPublic" for "c:\program files\nvidia corporation\frameviewsdk\sdk\fvsdktestclient_public.exe", hr=0x0

2025-12-01T01:40:13.501 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\qps-ploc\msprivs.dll.mui", hr=0x0

2025-12-01T01:40:13.507 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x0

2025-12-01T01:40:13.657 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\windows\system32\nb-no\pnpclean.dll.mui", hr=0x0

2025-12-01T01:40:13.660 Engine:Setting original file name "ImagingDevices.cpl" for "c:\program files (x86)\windows photo viewer\imagingdevices.exe", hr=0x0

2025-12-01T01:40:13.672 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_or-in_f89501f89f876dc5_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:13.714 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.26100.7171_none_4ad020869b677502\taskmgr.exe.mun", hr=0x0

2025-12-01T01:40:13.764 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_ja-jp_ca98740be1962356_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:13.823 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x0

2025-12-01T01:40:13.856 Engine:Setting original file name "apisetstub" for "c:\windows\syswow64\downlevel\api-ms-win-core-wow64-l1-1-0.dll", hr=0x0

2025-12-01T01:40:13.880 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_it-it_f0fca0072ba86c5a\msprivs.dll.mui", hr=0x0

2025-12-01T01:40:13.922 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_qps-ploc_7ccda1c46b445ed4\memtest.exe.mui", hr=0x0

2025-12-01T01:40:13.942 Engine:Setting original file name "NETBIOS.SYS" for "c:\windows\winsxs\backup\amd64_microsoft-windows-netbios_31bf3856ad364e35_10.0.26100.1_none_56d5608ad3abe945_netbios.sys_6f23c4df", hr=0x0

2025-12-01T01:40:14.008 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-process-l1-1-0.dll", hr=0x0

2025-12-01T01:40:14.161 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\systemresources\etwcoreuicomponentsresources.dll.mun", hr=0x0

2025-12-01T01:40:14.173 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_pt-br_55b72b827c87f88f_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:14.293 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_da-dk_0dc0948c02e4507b_memtest.efi.mui_71e15c22", hr=0x0

2025-12-01T01:40:14.310 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_mt-mt_b4ebaa02b8bfece3_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:14.349 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.devices.winmd", hr=0x0

2025-12-01T01:40:14.386 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_576ce8a1070e9744_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:14.400 Engine:Setting original file name "FileInfo.sys" for "c:\windows\winsxs\backup\amd64_microsoft-windows-fileinfominifilter_31bf3856ad364e35_10.0.26100.1150_none_729c4b9be137bb96_fileinfo.sys_9be2dfcd", hr=0x0

2025-12-01T01:40:14.492 Engine:Setting original file name "aclui.dll" for "c:\windows\winsxs\amd64_microsoft-windows-aclui_31bf3856ad364e35_10.0.26100.7019_none_f0f7bbb4638cf785\aclui.dll.mun", hr=0x0

2025-12-01T01:40:14.497 Engine:Setting original file name "apex.dll" for "c:\program files\nvidia corporation\installer2\display.physx.{abbd86a2-7095-46ec-95a1-488ad5329a26}\files\engine\73be2921551d\apex_fieldsamplerchecked_x86.dll", hr=0x0

2025-12-01T01:40:14.563 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.777.2143.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x0

2025-12-01T01:40:14.632 Engine:Setting original file name "qualityupdateassistant" for "c:\program files\microsoft update health tools\qualityupdateassistant.dll", hr=0x0

2025-12-01T01:40:14.664 Engine:Setting original file name "NVPPE.dll" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvppex.dll", hr=0x0

2025-12-01T01:40:14.748 Engine:Setting original file name "VCOMP140.DLL" for "c:\windows\systemapps\microsoftwindows.client.fileexp_cw5n1h2txyewy\vcomp140_app.dll", hr=0x0

2025-12-01T01:40:14.750 Engine:Setting original file name "hiberrsm.exe" for "c:\windows\winsxs\backup\amd64_microsoft-windows-b..os-resume.resources_31bf3856ad364e35_10.0.26100.1_en-us_4761fcc7ecd6d884_winresume.efi.mui_f412814e", hr=0x0

2025-12-01T01:40:14.953 Engine:Setting original file name "NVPrxy.dll" for "c:\program files\nvidia corporation\installer2\installercore\nvprxy32.dll", hr=0x0

2025-12-01T01:40:15.071 Engine:Setting original file name "Mystify" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\589bec7339e102473dc7566c3b9b0f45\mystify.scr.mui", hr=0x0

2025-12-01T01:40:15.098 Engine:Setting original file name "volmgrx.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..memanager.resources_31bf3856ad364e35_10.0.26100.1_en-us_a18734abf077f9b4_volmgrx.sys.mui_b0c205d7", hr=0x0

2025-12-01T01:40:15.141 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x0

2025-12-01T01:40:15.234 Engine:Setting original file name "libcrypto" for "c:\program files\windowsapps\microsoft.windows.photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\libcrypto-3-x64.dll", hr=0x0

2025-12-01T01:40:15.270 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-string-l1-1-0.dll", hr=0x0

2025-12-01T01:40:15.302 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_hi-in_83227505fd46a5bd_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:15.352 Engine:Setting original file name "CertCa" for "c:\windows\winsxs\amd64_microsoft-windows-c..ertca-dll.resources_31bf3856ad364e35_10.0.26100.1_nb-no_25e015431023bb9b\certca.dll.mui", hr=0x0

2025-12-01T01:40:15.463 Engine:Setting original file name "PCW_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_ddc581f4a364804b\diagpackage.dll.mui", hr=0x0

2025-12-01T01:40:15.552 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..subsystem.resources_31bf3856ad364e35_10.0.26100.1_nb-no_ab8620bc0ed41a36\scardsvr.dll.mui", hr=0x0

2025-12-01T01:40:15.571 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_6.0.3624.51421.dll", hr=0x0

2025-12-01T01:40:15.660 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-12-01T01:40:15.699 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.26100.1_fr-fr_06d4a9c0547686dc\msprivs.dll.mui", hr=0x0

2025-12-01T01:40:15.869 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mapi_31bf3856ad364e35_10.0.26100.7019_none_473a9ee5c9a5ebee\mapistub.dll", hr=0x0

2025-12-01T01:40:16.023 Engine:Setting original file name "mofcomp.exe.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_nb-no_8c87dcbbb8114be3_mofcomp.exe.mui_35badf56", hr=0x0

2025-12-01T01:40:16.028 Engine:Setting original file name "MspsProv.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..oning-wmi.resources_31bf3856ad364e35_10.0.26100.1_nb-no_bd6de3cbb42de1cb\mspsprov.dll.mui", hr=0x0

2025-12-01T01:40:16.076 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x0

2025-12-01T01:40:16.197 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.26100.7019_none_4a484d6501b73a17\wwanapi.dll", hr=0x0

2025-12-01T01:40:16.270 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ne-np_591939d32e7d4223_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:16.359 Engine:Setting original file name "Microsoft� .NET Framework" for "c:\program files\windowsapps\microsoft.xboxidentityprovider_12.130.16001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x0

2025-12-01T01:40:16.527 Engine:Setting original file name "Operativsystemet Microsoft� Windows�" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\e2a170892be5347a116ae0806fb5309d\pcalua.exe.mui", hr=0x0

2025-12-01T01:40:16.645 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x0

2025-12-01T01:40:16.662 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x0

2025-12-01T01:40:16.962 Engine:Setting original file name "imageres.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-imageres_31bf3856ad364e35_10.0.26100.1_none_d9b14b936072a0bc\imageres.dll.mun", hr=0x0

2025-12-01T01:40:17.179 Engine:Setting original file name "vcruntime140.dll" for "c:\config.msi\1c742.rbf", hr=0x0

2025-12-01T01:40:17.232 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-12-01T01:40:17.276 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_kk-kz_71b9c9e0d19e9ee0_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:17.475 Engine:Setting original file name "Windows SDK" for "c:\windows\winsxs\wow64_microsoft-windows-runtime-metadata_31bf3856ad364e35_10.0.26100.7019_none_d7344336ec20e48a\windows.media.winmd", hr=0x0

2025-12-01T01:40:17.493 Engine:Setting original file name "Apps_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\apps\nb-no\d2a92c7cfed83dc547a21508b5b0ea0f\diagpackage.dll.mui", hr=0x0

2025-12-01T01:40:17.513 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32.dll", hr=0x0

2025-12-01T01:40:17.577 Engine:Setting original file name "CertPKICmdlet" for "c:\windows\system32\en-us\certpkicmdlet.dll.mui", hr=0x0

2025-12-01T01:40:17.592 Engine:Setting original file name "rasgcw.dll" for "c:\windows\winsxs\amd64_microsoft-windows-rasgetconnectedwizard_31bf3856ad364e35_10.0.26100.7171_none_d5fd24377c2039d4\rasgcw.dll.mun", hr=0x0

2025-12-01T01:40:17.650 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\ed4232cecc06e9efb72d2a7c142b63b4\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x0

2025-12-01T01:40:17.661 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.424.1611.0_x64__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-12-01T01:40:17.729 Engine:Setting original file name "WindowsMediaPlayerMediaLibrary_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_en-us_0cb2119581e88ce0\diagpackage.dll.mui", hr=0x0

2025-12-01T01:40:17.907 Engine:Setting original file name "BCP47Lang.dll" for "c:\windows\system32\bcp47langs.dll", hr=0x0

2025-12-01T01:40:17.984 Engine:Setting original file name "gpapi.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-g..licy-base.resources_31bf3856ad364e35_10.0.26100.1_en-us_be2843fbd972ca37_gpapi.dll.mui_ef0a9748", hr=0x0

2025-12-01T01:40:18.006 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-crt-math-l1-1-0.dll", hr=0x0

2025-12-01T01:40:18.066 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x0

2025-12-01T01:40:18.077 Engine:Setting original file name "aero.msstyles.mui" for "c:\windows\winsxs\amd64_microsoft-windows-aerolite.resources_31bf3856ad364e35_10.0.26100.1_en-us_bc993ceae8fc48bf\aerolite.msstyles.mui", hr=0x0

2025-12-01T01:40:18.360 Engine:Setting original file name "audioepb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-a..audiocore.resources_31bf3856ad364e35_10.0.26100.1_en-us_21823bda82ea31ac\audioendpointbuilder.dll.mui", hr=0x0

2025-12-01T01:40:18.362 Engine:Setting original file name "apisetstub" for "c:\windows\winsxs\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_10.0.26100.1_none_c4588310e9a6e860\api-ms-win-core-registry-l1-1-0.dll", hr=0x0

2025-12-01T01:40:18.400 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\en-us\utilman.exe.mui", hr=0x0

2025-12-01T01:40:18.543 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x0

2025-12-01T01:40:18.601 Engine:Setting original file name "apisetstub" for "c:\windows\syswow64\downlevel\api-ms-win-core-libraryloader-l1-1-1.dll", hr=0x0

2025-12-01T01:40:18.618 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x0

2025-12-01T01:40:18.627 Engine:Setting original file name "sqlite3" for "c:\program files\windowsapps\microsoftteams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\sqlite3.dll", hr=0x0

2025-12-01T01:40:18.693 Engine:Setting original file name "apisetstub" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.32612.0_x64__8wekyb3d8bbwe\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x0

2025-12-01T01:40:18.747 Engine:Setting original file name "w32time.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-time-tool.resources_31bf3856ad364e35_10.0.26100.1_en-us_7b897a2738f484fc\w32tm.exe.mui", hr=0x0

2025-12-01T01:40:18.751 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\printer\nb-no\diagpackage.dll.mui", hr=0x0

2025-12-01T01:40:18.784 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_fr-ca_80a1d04cb31f8eca_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:18.788 Engine:Setting original file name "ERC" for "c:\windows\system32\nb-no\wercplsupport.dll.mui", hr=0x0

2025-12-01T01:40:18.830 Engine:Setting original file name "vdsutil.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-v..skservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_59d12af3dce743c1_vdsutil.dll.mui_0caf9b0e", hr=0x0

2025-12-01T01:40:18.918 Engine:Setting original file name "AppLockerCSP.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appidcore.resources_31bf3856ad364e35_10.0.26100.1_en-us_564c6ad9b132641f_applockercsp.dll.mui_d2a0df70", hr=0x0

2025-12-01T01:40:19.004 Engine:Setting original file name "dnsrslvr.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..ient-core.resources_31bf3856ad364e35_10.0.26100.1591_en-us_b30301a4b143f570_dnsrslvr.dll.mui_1e1a1ed1", hr=0x0

2025-12-01T01:40:19.088 Engine:Setting original file name "PSAPI" for "c:\windows\winsxs\backup\wow64_microsoft-windows-basedependencies_31bf3856ad364e35_10.0.26100.1_none_09ea4476c5bcc4c0_psapi.dll_e8b5b4d1", hr=0x0

2025-12-01T01:40:19.114 Engine:Setting original file name "AcPlugin.dll" for "c:\program files\windowsapps\microsoft.applicationcompatibilityenhancements_1.2511.9.0_x64__8wekyb3d8bbwe\amd64\acplugin_test.dll", hr=0x0

2025-12-01T01:40:19.126 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_22621.112.358.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\426c2b1101abec586136a4bbd67a716e\narrator.exe.mui", hr=0x0

2025-12-01T01:40:19.144 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..tiator_ui.resources_31bf3856ad364e35_10.0.26100.1_en-us_7967a83a130d426e\iscsicpl.dll.mui", hr=0x0

2025-12-01T01:40:19.220 Engine:Setting original file name "WindowsMediaPlayerPlayDVD_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-w..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_nb-no_587c1f8aa98a4a71\diagpackage.dll.mui", hr=0x0

2025-12-01T01:40:19.430 Engine:Setting original file name "scecli" for "c:\windows\system32\nb-no\scecli.dll.mui", hr=0x0

2025-12-01T01:40:19.451 Engine:Setting original file name "scesrv" for "c:\windows\winsxs\amd64_microsoft-windows-s..ionengine.resources_31bf3856ad364e35_10.0.26100.1_en-us_e63bd45b831a32e3\scesrv.dll.mui", hr=0x0

2025-12-01T01:40:19.466 Engine:Setting original file name "apisetstub" for "c:\windows\system32\downlevel\api-ms-win-core-registry-l2-1-0.dll", hr=0x0

2025-12-01T01:40:19.486 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_bg-bg_af9bba51d24fbf0e_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:19.553 Engine:Setting original file name "nvhda.sys" for "c:\windows\system32\driverstore\filerepository\nvhda.inf_amd64_c32d8360d192a82e\nvhda64v.sys", hr=0x0

2025-12-01T01:40:19.565 Engine:Setting original file name "wmiutils.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-wmi-core.resources_31bf3856ad364e35_10.0.26100.1_en-us_d1bb369b303559b1_wmiutils.dll.mui_42583eaf", hr=0x0

2025-12-01T01:40:19.605 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_te-in_e10bae4a47776b9f_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:19.635 Engine:Setting original file name "BdncProxy.dll" for "c:\program files\bitdefender agent\27.1.1.23\crash_handler\bdnc.dll", hr=0x0

2025-12-01T01:40:19.710 Engine:Setting original file name "apisetstub" for "c:\windows\syswow64\downlevel\api-ms-win-core-threadpool-l1-2-0.dll", hr=0x0

2025-12-01T01:40:19.717 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.26100.1_nb-no_e175a2f7bf27ee8d_ws2ifsl.sys.mui_b672c7b4", hr=0x0

2025-12-01T01:40:19.787 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_eu-es_e55e702bbb854a24_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:19.825 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-msinfo32-exe.resources_31bf3856ad364e35_10.0.26100.1_en-us_53ae64398a08feba\msinfo32.exe.mui", hr=0x0

2025-12-01T01:40:19.868 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.676.1651.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-12-01T01:40:20.334 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.0_4.528.1755.0_x86__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-12-01T01:40:20.363 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x0

2025-12-01T01:40:20.471 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x0

2025-12-01T01:40:20.480 Engine:Setting original file name "NxCooking.dll" for "c:\program files (x86)\nvidia corporation\physx\engine\v2.7.6\physxcooking.dll", hr=0x0

2025-12-01T01:40:20.511 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.275.500.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x0

2025-12-01T01:40:20.551 Engine:Setting original file name "apisetstub" for "c:\windows\system32\downlevel\api-ms-win-core-io-l1-1-1.dll", hr=0x0

2025-12-01T01:40:20.650 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x0

2025-12-01T01:40:20.736 Engine:Setting original file name "filterLib.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\4fffc8576907b0b5da815790887fb244\fltlib.dll.mui", hr=0x0

2025-12-01T01:40:20.768 Engine:Setting original file name "srpuxgp.dll" for "c:\windows\systemresources\srpuxnativesnapin.dll.mun", hr=0x0

2025-12-01T01:40:20.772 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\backup\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.26100.1_zh-cn_1db814810f1b4ce7_memtest.exe.mui_77b8cbcc", hr=0x0

2025-12-01T01:40:21.054 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_nl-nl_0d26e65c98dbf6f7_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:21.066 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_sl-si_8549ba61ed8af84b_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:21.069 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x0

2025-12-01T01:40:21.259 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_pl-pl_9d43c82914fc6152_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:21.283 Engine:Setting original file name "Windows SDK" for "c:\windows\winsxs\amd64_microsoft-windows-runtime-metadata_31bf3856ad364e35_10.0.26100.7019_none_ccdf98e4b7c0228f\windows.web.winmd", hr=0x0

2025-12-01T01:40:21.364 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.675.1142.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x0

2025-12-01T01:40:21.483 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_ca-es_584cefb2c144b7d8_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:21.494 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\winsxs\amd64_microsoft-windows-qedwipes_31bf3856ad364e35_10.0.26100.1_none_5473011012d79dc1\qedwipes.dll.mun", hr=0x0

2025-12-01T01:40:21.516 Engine:Setting original file name "bootmgr.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-b..nager-efi.resources_31bf3856ad364e35_10.0.26100.6899_uk-ua_44800294c7280690\bootmgfw_ex.efi.mui", hr=0x0

2025-12-01T01:40:21.555 Engine:Setting original file name "fx.dll" for "c:\program files\bitdefender agent\27.1.1.23\x64\critical_fixups64.dll", hr=0x0

2025-12-01T01:40:21.578 Engine:Setting original file name "ImagingDevices.cpl" for "c:\program files\windows photo viewer\imagingdevices.exe", hr=0x0

2025-12-01T01:40:21.681 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_et-ee_4da61d721400c924_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:21.726 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_mk-mk_fb2fbffb5205c552_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:21.966 Engine:Setting original file name "msinfo.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-m..xe-common.resources_31bf3856ad364e35_10.0.26100.1_en-us_58b62bf54b9ae38a\msinfo32.exe.mui", hr=0x0

2025-12-01T01:40:22.029 Engine:Setting original file name "apisetstub" for "c:\windows\winsxs\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_10.0.26100.1_none_3886c015fe3eadee\api-ms-win-security-lsalookup-l2-1-0.dll", hr=0x0

2025-12-01T01:40:22.107 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.70.1338.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x0

2025-12-01T01:40:22.112 Engine:Setting original file name "netcfgx.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-tcpip.resources_31bf3856ad364e35_10.0.26100.1_en-us_c93621b935b09922_tcpipcfg.dll.mui_a5479fc1", hr=0x0

2025-12-01T01:40:22.165 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_qps..ocm_f4c1513bcd79893e_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:22.215 Engine:Setting original file name "nvxdsync.exe" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\display.nvcontainer\plugins\session\nvxdsyncplugin.dll", hr=0x0

2025-12-01T01:40:22.357 Engine:Setting original file name "ReShade" for "c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvcamera\reshadefxc64.exe", hr=0x0

2025-12-01T01:40:22.404 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x0

2025-12-01T01:40:22.554 Engine:Setting original file name "COMCTL32.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.26100.1591_uz-..-uz_0fbfb1c9f2926e3e_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:22.589 Engine:Setting original file name "PresentMon" for "c:\programdata\nvidia corporation\downloader\latest\frameviewsdk\bin\presentmon_x64.exe", hr=0x0

2025-12-01T01:40:22.600 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\power\nb-no\2803551e72f3605cc0b181750700647e\diagpackage.dll.mui", hr=0x0

2025-12-01T01:40:22.668 Engine:Setting original file name "comctl32.DLL.MUI" for "c:\windows\winsxs\backup\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.26100.1591_th-th_25ee4fb15dc2e739_comctl32.dll.mui_0da4e682", hr=0x0

2025-12-01T01:40:22.674 Engine:Setting original file name "Umpo.DLL.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-u..erservice.resources_31bf3856ad364e35_10.0.26100.1_nb-no_a887c532823d0a08_umpo.dll.mui_cac12e54", hr=0x0

2025-12-01T01:40:22.677 Engine:Setting original file name "bootres" for "c:\windows\boot\resources\nb-no\bootres.dll.mui", hr=0x0

2025-12-01T01:40:22.704 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepacknb-no_26100.121.219.0_neutral__8wekyb3d8bbwe\windows\system32\nb-no\b74f41bc269d13282681d018820fb031\ddores.dll.mui", hr=0x0

2025-12-01T01:40:22.733 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.652.1806.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x0

2025-12-01T01:40:22.742 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.27.350.0_x64__8wekyb3d8bbwe\dotnet\mscordaccore_amd64_amd64_8.0.2125.47513.dll", hr=0x0

2025-12-01T01:40:22.775 Engine:Setting original file name "apisetstub" for "c:\xampp\mysql\bin\api-ms-win-core-namedpipe-l1-1-0.dll", hr=0x0

2025-12-01T01:40:22.775 OriginalFileName Maintenance::10298 files in Moac, 0 skipped (cached), 484 filename set

2025-12-01T01:40:22.775 [AutoPurge] Routine task for Cache Maintenance has ended.

2025-12-01T01:41:00.341 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #500500, FileId: 0x9000000097f85, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T01:41:00.498 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T01:52:08.674 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #502886, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T01:52:08.681 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #502887, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T01:52:18.677 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #502894, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T01:52:18.681 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #502895, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T01:52:18.691 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #502896, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T01:52:18.695 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #502897, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T01:56:00.670 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #503010, FileId: 0x7000000098036, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T01:56:05.496 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T02:05:56.624 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #503447, FileId: 0x95000000008e85, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T02:07:06.020 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ...

2025-12-01T02:07:06.029 [DLP] DlpEngineConfigStorage::OnConfigChange DlpDwordSettingsMap:

2025-12-01T02:07:06.029 [RTP] [RtpConfig] Config change detected, type: 32

2025-12-01T02:07:06.029 [RTP] Duplicating the current plugin configuration object...

2025-12-01T02:07:06.030 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-12-01T02:07:06.030 [RTP] Updating plugin configuration due to recent config changes (0x20) ...

2025-12-01T02:07:06.030 [RTP] [RtpConfig] Config change detected, type: 2

2025-12-01T02:07:06.030 [RTP] [RtpConfig] Config change detected, type: 2

2025-12-01T02:07:06.030 [RTP] [RtpConfig] Config change detected, type: 4

2025-12-01T02:07:06.030 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled)

2025-12-01T02:07:06.030 [RTP] No config change detected. Not updating plugin configuration.

2025-12-01T02:07:06.030 [RTP] No config changes found. No configuration switch.

2025-12-01T02:07:06.030 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0

2025-12-01T02:07:06.030 [RTP] [RtpConfig] Config change detected, type: 8

2025-12-01T02:07:06.030 [RTP] [RtpConfig] Config change detected, type: 16

2025-12-01T02:07:06.030 [RTP] [RtpConfig] Config change detected, type: 1024

2025-12-01T02:07:06.030 [RTP] [RtpConfig] Config change detected, type: 2048

2025-12-01T02:07:06.030 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0).

2025-12-01T02:07:06.030 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0).

2025-12-01T02:07:06.030 [RTP] Setting FilterExperimentMode to 0 (hr=0).

2025-12-01T02:07:06.030 [RTP] Setting DisableDriverUnload to 1 (hr=0).

2025-12-01T02:07:06.030 [RTP] Setting RegLinkHardeningMode to 1 (hr=0).

2025-12-01T02:07:06.030 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0).

2025-12-01T02:07:06.031 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-12-01T02:07:06.031 [RTP] Setting EfsHardeningFlags to 1 (hr=0).

2025-12-01T02:07:06.031 [RTP] PreventPagingFileAbuseKillbit[0].

2025-12-01T02:07:06.031 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0).

2025-12-01T02:07:06.031 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0).

2025-12-01T02:07:06.031 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration.

2025-12-01T02:07:06.031 [RTP] [RtpConfig] Config change detected, type: 64

2025-12-01T02:07:06.032 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-12-01T02:07:06.034 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-12-01T02:07:06.035 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-12-01T02:07:06.037 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-12-01T02:07:06.039 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 4460152(ms) from now at 04:21 (03:21 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes.

2025-12-01T02:07:08.581 [RTP] Duplicating the current plugin configuration object...

2025-12-01T02:07:08.581 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ...

2025-12-01T02:07:08.581 [RTP] Updating plugin configuration due to recent config changes (0x41e) ...

2025-12-01T02:07:08.582 [RTP] Calling GenerateEngineConfigStruct (0x18) ...

2025-12-01T02:07:08.590 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x218

2025-12-01T02:11:01.200 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #504030, FileId: 0x800000009781c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T02:11:10.482 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T02:26:01.217 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #505417, FileId: 0x9000000098153, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T02:26:15.486 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T02:29:42.679 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 52055, Count: 6955, MaxTime: 625, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\NVIDIA\NGX\models\dlssd\versions\20316673\files\160_E658700.bin, EstimatedImpact: 0%

2025-12-01T02:29:42.679 ProcessImageName: NVIDIA Overlay.exe, Pid: 26688, TotalTime: 2342, Count: 173, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\66da1a05-92dc-4c69-b30c-2164140094e8.tmp, EstimatedImpact: 0%

2025-12-01T02:29:42.679 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 1483, Count: 108, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\dbce9e14-f3e2-4ca0-89e2-726295b6bd12.tmp, EstimatedImpact: 0%

2025-12-01T02:29:42.679 ProcessImageName: RuntimeBroker.exe, Pid: 33848, TotalTime: 416, Count: 22, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 30%

2025-12-01T02:29:42.679 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 394, Count: 21, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 79%

2025-12-01T02:29:42.679 ProcessImageName: RuntimeBroker.exe, Pid: 29724, TotalTime: 371, Count: 22, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 25%

2025-12-01T02:29:42.679 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 255, Count: 56, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-12-01T02:29:42.679 ProcessImageName: taskhostw.exe, Pid: 30948, TotalTime: 210, Count: 78, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\config.json, EstimatedImpact: 15%

2025-12-01T02:29:42.679 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 196, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-12-01T02:29:42.679 ProcessImageName: taskhostw.exe, Pid: 10472, TotalTime: 195, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-12-01T02:29:42.679 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 25168, TotalTime: 195, Count: 36, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-12-01T02:29:42.679 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 165, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-12-01T02:29:42.679 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 150, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\66d618f2-7a02-4cce-aee7-503c76473c67.tmp, EstimatedImpact: 0%

2025-12-01T02:29:42.679 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 105, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-12-01T02:29:42.679 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 93, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-12-01T02:29:42.679 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 30756, TotalTime: 90, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 1%

2025-12-01T02:29:42.680 ProcessImageName: DeviceCensus.exe, Pid: 17624, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3, EstimatedImpact: 2%

2025-12-01T02:29:42.680 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-12-01T02:29:42.680 ProcessImageName: svchost.exe, Pid: 20276, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT6B8F.tmp, EstimatedImpact: 13%

2025-12-01T02:29:42.680 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\cache\httpclient\0fb243ded9649ae6d18059c674a4ae00, EstimatedImpact: 0%

2025-12-01T02:29:42.680 ProcessImageName: NVIDIA Overlay.exe, Pid: 30592, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\fa883ff7-d73c-4cb9-b4cc-5ee338f62eba.tmp, EstimatedImpact: 0%

2025-12-01T02:29:42.680 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_431960.acf, EstimatedImpact: 0%

2025-12-01T02:29:42.680 ProcessImageName: taskhostw.exe, Pid: 31124, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-12-01T02:29:42.680 ProcessImageName: StoreDesktopExtension.exe, Pid: 29272, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-12-01T02:29:42.680 ProcessImageName: svchost.exe, Pid: 30600, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_102122788\BITE0F1.tmp, EstimatedImpact: 1%

2025-12-01T02:29:42.680 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-12-01T02:29:42.680 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-12-01T02:29:42.680 ProcessImageName: updater.exe, Pid: 21428, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\584cb5a5-8b1a-48a1-b1b3-040dcaab2776.tmp, EstimatedImpact: 0%

2025-12-01T02:29:42.680 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-12-01T02:29:42.681 ProcessImageName: updater.exe, Pid: 34704, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-12-01T02:29:42.681 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-12-01T02:37:52.852 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Hovedprosjekt\PresentasjonJanuar.docx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #506665, FileId: 0x8000000001632f, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T02:41:01.401 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #506763, FileId: 0x70000000981e3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T02:41:20.472 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T02:52:06.368 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #507041, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T02:52:06.371 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #507042, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T02:52:16.383 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #507058, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T02:52:16.387 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #507060, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T02:53:03.951 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\ELN3A Gruppe 5\Fremdriftsplan.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #507131, FileId: 0x1f1000000007ae8, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T02:56:02.851 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #507199, FileId: 0x700000009826e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T02:56:25.476 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T02:57:49.836 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\L�M\Innlevering 7.docx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #507249, FileId: 0xb00000000b83b, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T02:57:54.819 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\L�M\L�m-oppdrag-7-FELLES-FERDIG.docx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #507250, FileId: 0x13000000055ff9, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T02:58:05.367 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Elektriske maskiner\Pr�ve 10.11.2024.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #507253, FileId: 0x93000000024739, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

Internal signature match:subtype=Lowfi, sigseq=0x0000236C3E2788A9, sigsha=dddf6b81b72cebfe73d3a40d39f6574aeb7f8d62, cached=false, source=2, resourceid=0x1c439500

2025-12-01T03:01:00.109 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1

2025-12-01T03:01:00.109 [Cloud] Start of cloud request. Passive mode: 0

2025-12-01T03:01:00.109 [Cloud] Queued cloud request.

2025-12-01T03:01:00.109 [Cloud] MpEngineCloudRequest(). hr = 0

2025-12-01T03:01:00.109 [Cloud] Dequeued cloud request.

2025-12-01T03:01:00.109 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0

Dynamic Signature has been received

Dynamic Signature Type:Signature Update

Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\67482979d160d6f2492037fac08369534cf3fa9e

Dynamic Signature Compilation Timestamp:12-01-2025 03:01:00

Persistence Type:Duration

Time remaining:1728000000

2025-12-01T03:01:00.357 Dynamic signature received

2025-12-01T03:01:00.357 [Cloud] End of cloud request.

2025-12-01T03:01:00.358 RTSD:RTSD recieved, rescanning impacted resources

2025-12-01T03:01:00.868 [NRI] Successfully updated NIS service with platform settings for enforcement level Log

2025-12-01T03:01:10.332 Bm signature throttled:0x00002db31bed458f

2025-12-01T03:11:03.607 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #508634, FileId: 0x70000000982fd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T03:11:30.473 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T03:26:03.869 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #508870, FileId: 0x7000000098385, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T03:26:35.459 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T03:35:10.581 Bm signature throttled:0x0000fab3228bcd4d

2025-12-01T03:40:56.130 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\L�M\Organisasjon og ledelse Innlevering 4.docx. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #510087, FileId: 0x900000001b463, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T03:41:04.162 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #510125, FileId: 0x700000009840d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T03:41:40.462 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T03:42:09.953 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Tegning\Samling 6\RammeA3.dwt. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #510416, FileId: 0x440000000211fb, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T03:43:56.934 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Tegning\Samling 5\Hovedstr�m.bak. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #510898, FileId: 0x6400000002111e, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T03:52:08.066 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #512515, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T03:52:08.069 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #512516, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T03:52:18.078 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #512564, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T03:52:18.085 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #512566, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T03:56:04.361 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #512835, FileId: 0x700000009849e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T03:56:45.445 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T04:11:04.627 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #513353, FileId: 0x7000000098527, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T04:11:50.444 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T04:14:29.610 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Tegning\Pr�ve v�r 2023 for elnett.dwg. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #513409, FileId: 0xb7000000022831, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T04:26:04.679 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #513585, FileId: 0x70000000985b6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T04:26:55.447 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T04:29:42.659 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 82903, Count: 11181, MaxTime: 4187, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\safe-watch-updater\installer.exe, EstimatedImpact: 0%

2025-12-01T04:29:42.659 ProcessImageName: NVIDIA Overlay.exe, Pid: 26688, TotalTime: 3308, Count: 257, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\66da1a05-92dc-4c69-b30c-2164140094e8.tmp, EstimatedImpact: 0%

2025-12-01T04:29:42.659 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2146, Count: 161, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\dbce9e14-f3e2-4ca0-89e2-726295b6bd12.tmp, EstimatedImpact: 0%

2025-12-01T04:29:42.659 ProcessImageName: RuntimeBroker.exe, Pid: 33848, TotalTime: 416, Count: 22, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 30%

2025-12-01T04:29:42.659 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 394, Count: 21, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 79%

2025-12-01T04:29:42.659 ProcessImageName: RuntimeBroker.exe, Pid: 29724, TotalTime: 371, Count: 22, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 25%

2025-12-01T04:29:42.659 ProcessImageName: php-cgi.exe, Pid: 25388, TotalTime: 367, Count: 19, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\xampp\php\php8ts.dll, EstimatedImpact: 100%

2025-12-01T04:29:42.659 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 301, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-12-01T04:29:42.659 ProcessImageName: WmiPrvSE.exe, Pid: 18188, TotalTime: 300, Count: 73, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.LanguageExperiencePacknb-NO_26100.121.219.0_neutral__8wekyb3d8bbwe\Windows\System32\driverstore\nb-NO\wstorvsp.inf_loc, EstimatedImpact: 28%

2025-12-01T04:29:42.659 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 255, Count: 56, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-12-01T04:29:42.659 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 25168, TotalTime: 240, Count: 47, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-12-01T04:29:42.659 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 225, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-12-01T04:29:42.659 ProcessImageName: taskhostw.exe, Pid: 30948, TotalTime: 210, Count: 78, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\config.json, EstimatedImpact: 15%

2025-12-01T04:29:42.659 ProcessImageName: taskhostw.exe, Pid: 10472, TotalTime: 195, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-12-01T04:29:42.659 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 165, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\66d618f2-7a02-4cce-aee7-503c76473c67.tmp, EstimatedImpact: 0%

2025-12-01T04:29:42.659 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 150, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-12-01T04:29:42.659 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 139, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-12-01T04:29:42.659 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 30756, TotalTime: 90, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 1%

2025-12-01T04:29:42.659 ProcessImageName: DeviceCensus.exe, Pid: 17624, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3, EstimatedImpact: 2%

2025-12-01T04:29:42.660 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: svchost.exe, Pid: 20276, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT6B8F.tmp, EstimatedImpact: 13%

2025-12-01T04:29:42.660 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\cache\httpclient\0fb243ded9649ae6d18059c674a4ae00, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: NVIDIA Overlay.exe, Pid: 30592, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\fa883ff7-d73c-4cb9-b4cc-5ee338f62eba.tmp, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_431960.acf, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: StoreDesktopExtension.exe, Pid: 32808, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: taskhostw.exe, Pid: 31124, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-12-01T04:29:42.660 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 15, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: taskhostw.exe, Pid: 26496, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 1%

2025-12-01T04:29:42.660 ProcessImageName: svchost.exe, Pid: 30600, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_102122788\BITE0F1.tmp, EstimatedImpact: 1%

2025-12-01T04:29:42.660 ProcessImageName: StoreDesktopExtension.exe, Pid: 29272, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: taskhostw.exe, Pid: 23732, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: updater.exe, Pid: 21428, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\584cb5a5-8b1a-48a1-b1b3-040dcaab2776.tmp, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: updater.exe, Pid: 34704, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: updater.exe, Pid: 31428, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-12-01T04:29:42.660 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-12-01T04:41:04.922 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #513946, FileId: 0x700000009863e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T04:42:00.444 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T04:52:06.397 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #514111, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T04:52:06.400 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #514112, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T04:52:16.412 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #514121, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T04:52:16.420 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #514122, FileId: 0xaf000000000120, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T04:56:05.037 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #514195, FileId: 0x70000000986cd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T04:57:05.428 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T05:02:56.692 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\ELN3A Gruppe 5\Loggfil.pdf. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #514790, FileId: 0x1d5000000007c4b, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T05:03:18.418 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Privat\dwbqcYly1LpOs6boNQjJm.1034.mp4. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #514863, FileId: 0x59000000010ad9, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T05:05:01.757 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Tegning\Pr�ve samling 6 oppg1.dwl. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #515082, FileId: 0xd00000002428c, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T05:05:37.966 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Dokumenter\Hotell Bergen OSS.png. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #515201, FileId: 0x6500000000ec94, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T05:11:06.512 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #515488, FileId: 0x7000000098754, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T05:12:10.436 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T05:26:06.542 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #515733, FileId: 0xa00000009866c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T05:27:15.419 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T05:35:12.417 Bm signature throttled:0x0000fab3228bcd4d

2025-12-01T05:41:06.800 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #516945, FileId: 0x700000009885f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T05:42:20.418 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T05:52:07.769 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #517104, FileId: 0xe8000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000001, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T05:52:07.772 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #517105, FileId: 0xe8000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T05:52:17.777 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #517112, FileId: 0xe8000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T05:52:17.788 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\updater.log. Process: (unknown), Status: 0xc000004b, State: 0, ScanRequest #517114, FileId: 0xe8000000001369, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T05:56:06.921 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #517225, FileId: 0x80000000988eb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T05:57:25.419 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

Internal signature match:subtype=Lowfi, sigseq=0x0000108090FCF4C4, sigsha=064f0536ffb97bb72d6c274c080aa4e2ffdf1b46, cached=false, source=2, resourceid=0xe9a0dc71

2025-12-01T06:11:08.365 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #519293, FileId: 0x7000000098977, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T06:12:30.412 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T06:26:08.559 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #521725, FileId: 0x7000000098a0e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T06:27:35.405 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T06:29:42.627 ProcessImageName: httpd.exe, Pid: 26680, TotalTime: 118017, Count: 15527, MaxTime: 4187, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\safe-watch-updater\installer.exe, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: NVIDIA Overlay.exe, Pid: 26688, TotalTime: 4229, Count: 344, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\Default\Network\66da1a05-92dc-4c69-b30c-2164140094e8.tmp, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: Spotify.exe, Pid: 2012, TotalTime: 2779, Count: 215, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\Default\Network\dbce9e14-f3e2-4ca0-89e2-726295b6bd12.tmp, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: svchost.exe, Pid: 3060, TotalTime: 1834, Count: 101, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: RuntimeBroker.exe, Pid: 33848, TotalTime: 416, Count: 22, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 30%

2025-12-01T06:29:42.627 ProcessImageName: qbittorrent.exe, Pid: 23568, TotalTime: 391, Count: 34, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: RuntimeBroker.exe, Pid: 29724, TotalTime: 371, Count: 22, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume4\xampp\uninstall.exe, EstimatedImpact: 25%

2025-12-01T06:29:42.627 ProcessImageName: php-cgi.exe, Pid: 25388, TotalTime: 367, Count: 19, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume4\xampp\php\php8ts.dll, EstimatedImpact: 100%

2025-12-01T06:29:42.627 ProcessImageName: svchost.exe, Pid: 1940, TotalTime: 315, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: WmiPrvSE.exe, Pid: 18188, TotalTime: 300, Count: 73, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.LanguageExperiencePacknb-NO_26100.121.219.0_neutral__8wekyb3d8bbwe\Windows\System32\driverstore\nb-NO\wstorvsp.inf_loc, EstimatedImpact: 28%

2025-12-01T06:29:42.627 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 28808, TotalTime: 255, Count: 56, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneAuth\accounts\24567ebd456a099e, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 25168, TotalTime: 240, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\general.keystore, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: taskhostw.exe, Pid: 30948, TotalTime: 210, Count: 78, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Windows\OneSettings\config.json, EstimatedImpact: 15%

2025-12-01T06:29:42.627 ProcessImageName: AggregatorHost.exe, Pid: 4652, TotalTime: 210, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateReboot$, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: taskhostw.exe, Pid: 10472, TotalTime: 195, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Windows\UUS\uusp.json, EstimatedImpact: 14%

2025-12-01T06:29:42.627 ProcessImageName: Spotify.exe, Pid: 11060, TotalTime: 180, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Spotify\66d618f2-7a02-4cce-aee7-503c76473c67.tmp, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: svchost.exe, Pid: 2976, TotalTime: 139, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume4\Windows\System32\drivers\ntfs.sys, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: OneDriveStandaloneUpdater.exe, Pid: 30756, TotalTime: 90, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 1%

2025-12-01T06:29:42.627 ProcessImageName: DeviceCensus.exe, Pid: 17624, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3, EstimatedImpact: 2%

2025-12-01T06:29:42.627 ProcessImageName: steam.exe, Pid: 15760, TotalTime: 60, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d356105fac5527ef.customDestinations-ms, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: MicrosoftSecurityApp.exe, Pid: 15152, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\IdentityCache\1\UD\u_40LO3L2SHK2N8LHH\e_C2GK9UTC67FSUCG3\AT\r_74DB6FURNR2TGPBK\c_CQKU62E8SBMCTGDD.bin, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: taskhostw.exe, Pid: 32784, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 5%

2025-12-01T06:29:42.627 ProcessImageName: svchost.exe, Pid: 20276, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\BIT6B8F.tmp, EstimatedImpact: 13%

2025-12-01T06:29:42.627 ProcessImageName: EmbyServer.exe, Pid: 18328, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\Emby-Server\programdata\cache\httpclient\0fb243ded9649ae6d18059c674a4ae00, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: NVIDIA Overlay.exe, Pid: 30592, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\NVIDIA Corporation\NVIDIA Overlay\CefCache\fa883ff7-d73c-4cb9-b4cc-5ee338f62eba.tmp, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: svchost.exe, Pid: 5528, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\steamapps\appmanifest_431960.acf, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: StoreDesktopExtension.exe, Pid: 32808, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\globalization\icu\icudtl.dat, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: taskhostw.exe, Pid: 31124, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 9%

2025-12-01T06:29:42.627 ProcessImageName: taskhostw.exe, Pid: 26496, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres->(UTF-16LE), EstimatedImpact: 1%

2025-12-01T06:29:42.627 ProcessImageName: svchost.exe, Pid: 30600, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Temp\chrome_BITS_11060_102122788\BITE0F1.tmp, EstimatedImpact: 1%

2025-12-01T06:29:42.627 ProcessImageName: StoreDesktopExtension.exe, Pid: 29272, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume4\WINDOWS\AppPatch\01DC5041B0D8F2C6.sysmain.sdb, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: nvcontainer.exe, Pid: 11036, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NVIDIA app\www\assets\config\config.json, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: taskhostw.exe, Pid: 23732, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Microsoft\TokenBroker\Cache\01c5cb21ab1d4fd56e65159d6c36cd5db1f647e1.tbres, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: steamwebhelper.exe, Pid: 15944, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Steam\dumps\settings.dat, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: updater.exe, Pid: 34704, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: updater.exe, Pid: 31428, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\crx_cache\metadata.json, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: Spotify.exe, Pid: 12568, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Users\ServerPC\AppData\Local\Packages\SpotifyAB.SpotifyMusic_zpdnekdrzrea0\LocalCache\Local\Spotify\User Data\Crashpad\settings.dat, EstimatedImpact: 0%

2025-12-01T06:29:42.627 ProcessImageName: updater.exe, Pid: 21428, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume4\Program Files (x86)\Google\GoogleUpdater\584cb5a5-8b1a-48a1-b1b3-040dcaab2776.tmp, EstimatedImpact: 0%

2025-12-01T06:41:08.870 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume4\Users\ServerPC\AppData\Roaming\qBittorrent\qBittorrent-data.ini.lock. Process: \Device\HarddiskVolume4\Program Files\qBittorrent\qbittorrent.exe, Status: 0xc0000001, State: 0, ScanRequest #525281, FileId: 0x8000000098a97, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x4000801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0

2025-12-01T06:42:40.396 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config)

2025-12-01T06:42:43.091 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\ELN3A Gruppe 5\Sign\KristofferSign.jpg. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #525481, FileId: 0xb200000000a990, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T06:51:24.365 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Skrivebord\VLFK-Snarvegar\VLFK tenester.url. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #526578, FileId: 0x20000000770fc, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T06:51:29.125 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Skrivebord\VLFK-Snarvegar\Elevhjelp.url. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #526582, FileId: 0x2000000077102, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T06:51:30.456 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Skrivebord\VLFK-Snarvegar\E-post p� nett.url. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #526585, FileId: 0x2000000077100, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

2025-12-01T06:51:35.195 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume4\Users\ServerPC\OneDrive - Vestland fylkeskommune\Skrivebord\VLFK-Snarvegar\HR-Portalen.url. Process: \Device\HarddiskVolume4\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #526603, FileId: 0x20000000770fd, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0

Anon7 - 2021