[01-11-19 11:19:46.334] [fbc:5] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( ProtectionTypeByConfidence: ) [01-11-19 11:19:48.459] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( policyFromServer: 1.0 GB false 5 GB false 1 GB true false false false false true Low Low Low Low Low Low Low Never Low Never Never Never Never Never Never Never Never Never Never Never Never Never Never Never Never Never Never Never Never Never Never true true true true true true Never Never Never Never true false true Ignore Ignore Ignore Ignore Ignore Ignore true false %ProgramData%\CheckPoint\Endpoint Security\Remediation\InfectionsFarm\ 2048 90 %ProgramData%\CheckPoint\Endpoint Security\Remediation\Quarantine\ true true false 1024 60 2880 60 doc png jpg bmp docx gif rtf txt dot docm dotx dotm docb xls xlt xlm xlsx xlsb xlsm xltx xltm ppt pot pps pptx pptm potx ppsx sldx ps eps prn emf rle dib wpd csv tif jpeg jfif tiff dibl ppm pgm pbm pnm webp hdr heif bpg pdf html htm avi mp4 mp3 flv mov m4v mpeg mpg swf wmv asf 3gp ram wav aif aiff mpa m4a wma oef true off 4 60 WINWORD.EXE EXCEL.EXE ONENOTE.EXE POWERPNT.EXE MSPUB.EXE WINWORD.EXE EXCEL.EXE ONENOTE.EXE POWERPNT.EXE MSPUB.EXE AcroRd32.exe MSACCESS.EXE VISIO.EXE WSCRIPT.EXE CMD.EXE CSCRIPT.EXE POWERSHELL.EXE MSHTA.EXE 50 100 10 8 FileTypeExtenssions[doc,docx,xls,xlsx,pdf,png,rtf,zip,svg,wmv,mp3,rar,bmp,7z,gif,docm,dotm,xlm,xlsm,xlam,ppt,pptx,pptm,ppom,ppam,ppsm,contact,jpeg,txt] 30 3 Music\00CpSystemFolderDonotRemove\mp4 Music\00CpSystemFolderDonotRemove\mp4 Music\00CpSystemFolderDonotRemove\avi Documents\00CpSystemFolderDonotRemove\docx Documents\00CpSystemFolderDonotRemove\doc Documents\00CpSystemFolderDonotRemove\xlsx Documents\00CpSystemFolderDonotRemove\xls Documents\00CpSystemFolderDonotRemove\pptx Documents\00CpSystemFolderDonotRemove\pdf Documents\00CpSystemFolderDonotRemove\txt Videos\00CpSystemFolderDonotRemove\wmv Videos\00CpSystemFolderDonotRemove\wmv Videos\00CpSystemFolderDonotRemove\mp4 Videos\00CpSystemFolderDonotRemove\avi Pictures\00CpSystemFolderDonotRemove\jpg Pictures\00CpSystemFolderDonotRemove\png Pictures\00CpSystemFolderDonotRemove\gif 100 RankingRange[0-9:1,10-14:7,15-19:8,20-24:9,25-2147483647:10] 30 0.5 8 FileTypeExtenssions[doc,docx,xls,xlsx,pdf,png,rtf,zip,svg,wmv,mp3,rar,bmp,7z,gif,docm,dotm,xlm,xlsm,xlam,ppt,pptx,pptm,ppom,ppam,ppsm,contact,jpeg,txt] RankingRange[1-1:3,2-2:4,3-3:5,4-4:11,5-5:12,6-6:13,7-2147483647:14] RankingGroups[Desktop:13,Documents:13,Downloads:8,Pictures:8,Videos:8,Others:1] ) [01-11-19 11:19:48.491] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( policyViaExclusions: false false Silent Silent Silent ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: c:\windows\explorer.exe FileName: MD5: Signer: ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: symantec corporation ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: trend micro ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: mcafee ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: mcafee epo development (spc) ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: c:\windows\explorer.exe FileName: MD5: Signer: ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: symantec corporation ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: trend micro ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: mcafee ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: mcafee epo development (spc) ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.EDR.FeedHandler) message: ( Data streaming Stop called ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.EDR.FeedHandler) message: ( Stop was already done, will not call stop again ) [01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Seting enforcement for ExperimentalSignatures: False MachineLearningValidation: False High: Silent Medium:Silent Low: Silent ) [01-11-19 11:19:48.569] [fbc:1] [Info] source: (NGAV.Connectors.AntiRansomware.AntiRansomwareConnector) message: ( Anti-Ransomware policy applied ) [01-11-19 11:19:48.569] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( NGAVPolicy initialized ) [01-11-19 11:19:48.569] [fbc:1] [Info] source: (NGAV.Core.Engine) message: ( ##### Engine started #### ) [01-11-19 11:19:48.569] [fbc:1] [Info] source: (NGAV.Core.Engine) message: ( Telemetry initialized ) [01-11-19 11:19:48.772] [fbc:1] [Info] source: (NGAV.Connectors.AntiRansomware.AntiRansomwareConnector) message: ( Anti-Ransomware started ) [01-11-19 11:19:48.788] [fbc:1] [Error] source: (NGAV.Connectors.UserInterface.UserInterfaceBridge) message: ( System.TypeInitializationException: Se produjo una excepción en el inicializador de tipo de 'EPNetUtils.EndpointUI.ZdxUiNegotiator'. ---> System.IO.FileNotFoundException: The path to ZDxNet.dll cannot be located: no registry key en EPNetUtils.EndpointUI.ZdxUiNegotiator..cctor() --- Fin del seguimiento de la pila de la excepción interna --- en EPNetUtils.EndpointUI.ZdxUiNegotiator..ctor() en NGAV.Connectors.UserInterface.UserInterfaceEP..ctor() en NGAV.Connectors.UserInterface.UserInterfaceBridge.Configure() ) [01-11-19 11:19:48.788] [fbc:1] [Info] source: (NGAV.Core.Enforcement.Remediation) message: ( Remediation initialized ) [01-11-19 11:19:48.788] [fbc:1] [Info] source: (NGAV.Helpers.HelperDirectory) message: ( Will not delete directory, Path: C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\indicators not exist ) [01-11-19 11:19:48.788] [fbc:1] [Info] source: (NGAV.Helpers.HelperDirectory) message: ( Will not delete directory, Path: C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\sentree\protections not exist ) [01-11-19 11:19:48.788] [fbc:1] [Info] source: (NGAV.Helpers.HelperDirectory) message: ( Will not delete directory, Path: C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\shared\protections not exist ) [01-11-19 11:19:51.715] [fbc:1] [Info] source: (NGAV.Core.Signatures.ParserUnsharedFormat.ParserManager) message: ( Signatures zip file extracted: C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\Signatures.zip ) [01-11-19 11:19:51.762] [fbc:1] [Info] source: (NGAV.Core.Signatures.ParserUnsharedFormat.ParserManager) message: ( mldata zip file extracted: C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\indicators\mldata.zip ) [01-11-19 11:19:53.872] [fbc:1] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Engine.DataAggregation.Records.RecordBase]) message: ( queueu started ) [01-11-19 11:19:54.872] [fbc:1] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Engine.DataAggregation.Records.RecordBase]) message: ( queueu started ) [01-11-19 11:19:54.887] [fbc:1] [Info] source: (NGAV.Core.SuspiciousEvent.SuspiciousEvents) message: ( Suspicious events initialized ) [01-11-19 11:19:54.934] [fbc:1] [Info] source: (NGAV.ML.MLMatrix) message: ( Loaded model Camouflage ) [01-11-19 11:19:54.965] [fbc:1] [Info] source: (NGAV.ML.MLMatrix) message: ( Loaded model HashCopy ) [01-11-19 11:19:54.965] [fbc:1] [Info] source: (NGAV.ML.MLMatrix) message: ( ML matrix Initialized successfuly ) [01-11-19 11:19:54.965] [fbc:1] [Info] source: (NGAV.ML.MLMatrix) message: ( Starting ML ) [01-11-19 11:19:54.965] [fbc:1] [Info] source: (NGAV.Reputation.ReputationConnector) message: ( Reputation initialized ) [01-11-19 11:19:55.965] [fbc:1] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Core.Reporting.Information.DetectedTrees]) message: ( queueu started ) [01-11-19 11:19:55.965] [fbc:1] [Info] source: (NGAV.Core.Signatures.Validation.ValidationFP) message: ( Validation FP initialized ) [01-11-19 11:19:56.200] [fbc:1b] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Ignoring Indicators for process Path: C:\Windows\Explorer.EXE MD5: 38ae1b3c38faef56fe4907922f0385ba Signer: Microsoft Windows, due to exclusion ) [01-11-19 11:19:56.965] [fbc:16] [Warn] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Enforcement type for DetectionConfidence: Low is: Silent ) [01-11-19 11:19:56.965] [fbc:16] [Warn] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Enforcement type for DetectionConfidence: Medium is: Silent ) [01-11-19 11:19:56.965] [fbc:16] [Warn] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Enforcement type for DetectionConfidence: High is: Silent ) [01-11-19 11:20:56.231] [fbc:17] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Engine.DataAggregation.Records.RecordBase]) message: ( queueu disposed ) [01-11-19 11:21:01.231] [fbc:22] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Engine.DataAggregation.Records.RecordBase]) message: ( queueu stopped ) [01-11-19 11:21:01.231] [fbc:1b] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Engine.DataAggregation.Records.RecordBase]) message: ( queueu disposed ) [01-11-19 11:21:06.231] [fbc:22] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Engine.DataAggregation.Records.RecordBase]) message: ( queueu stopped ) [01-11-19 11:21:06.231] [fbc:22] [Info] source: (NGAV.ML.MLMatrix) message: ( ML stopped ) [01-11-19 11:21:06.231] [fbc:22] [Info] source: (NGAV.Reputation.ReputationConnector) message: ( Reputation deinitialized ) [01-11-19 11:21:06.231] [fbc:19] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Core.Reporting.Information.DetectedTrees]) message: ( queueu disposed ) [01-11-19 11:21:11.231] [fbc:22] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Core.Reporting.Information.DetectedTrees]) message: ( queueu stopped ) [01-11-19 11:21:11.231] [fbc:22] [Info] source: (NGAV.Core.Signatures.Validation.ValidationFP) message: ( Validation FP deinitialized ) [01-11-19 11:21:11.231] [fbc:22] [Info] source: (NGAV.Connectors.AntiRansomware.AntiRansomwareConnector) message: ( Anti-Ransomware stopped ) [01-11-19 11:21:11.231] [fbc:22] [Info] source: (NGAV.Core.Enforcement.Remediation) message: ( Remediation deinitialized ) [01-11-19 11:21:11.231] [fbc:22] [Info] source: (NGAV.Core.Engine) message: ( ##### Engine stopped ##### )