[01-11-19 11:19:46.334] [fbc:5] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( ProtectionTypeByConfidence:
)
[01-11-19 11:19:48.459] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( policyFromServer:
1.0
GB
false
5
GB
false
1
GB
true
false
false
false
false
true
Low
Low
Low
Low
Low
Low
Low
Never
Low
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
Never
true
true
true
true
true
true
Never
Never
Never
Never
true
false
true
Ignore
Ignore
Ignore
Ignore
Ignore
Ignore
true
false
%ProgramData%\CheckPoint\Endpoint Security\Remediation\InfectionsFarm\
2048
90
%ProgramData%\CheckPoint\Endpoint Security\Remediation\Quarantine\
true
true
false
1024
60
2880
60
doc
png
jpg
bmp
docx
gif
rtf
txt
dot
docm
dotx
dotm
docb
xls
xlt
xlm
xlsx
xlsb
xlsm
xltx
xltm
ppt
pot
pps
pptx
pptm
potx
ppsx
sldx
ps
eps
prn
emf
rle
dib
wpd
csv
tif
jpeg
jfif
tiff
dibl
ppm
pgm
pbm
pnm
webp
hdr
heif
bpg
pdf
html
htm
avi
mp4
mp3
flv
mov
m4v
mpeg
mpg
swf
wmv
asf
3gp
ram
wav
aif
aiff
mpa
m4a
wma
oef
true
off
4
60
WINWORD.EXE
EXCEL.EXE
ONENOTE.EXE
POWERPNT.EXE
MSPUB.EXE
WINWORD.EXE
EXCEL.EXE
ONENOTE.EXE
POWERPNT.EXE
MSPUB.EXE
AcroRd32.exe
MSACCESS.EXE
VISIO.EXE
WSCRIPT.EXE
CMD.EXE
CSCRIPT.EXE
POWERSHELL.EXE
MSHTA.EXE
50
100
10
8
FileTypeExtenssions[doc,docx,xls,xlsx,pdf,png,rtf,zip,svg,wmv,mp3,rar,bmp,7z,gif,docm,dotm,xlm,xlsm,xlam,ppt,pptx,pptm,ppom,ppam,ppsm,contact,jpeg,txt]
30
3
Music\00CpSystemFolderDonotRemove\mp4
Music\00CpSystemFolderDonotRemove\mp4
Music\00CpSystemFolderDonotRemove\avi
Documents\00CpSystemFolderDonotRemove\docx
Documents\00CpSystemFolderDonotRemove\doc
Documents\00CpSystemFolderDonotRemove\xlsx
Documents\00CpSystemFolderDonotRemove\xls
Documents\00CpSystemFolderDonotRemove\pptx
Documents\00CpSystemFolderDonotRemove\pdf
Documents\00CpSystemFolderDonotRemove\txt
Videos\00CpSystemFolderDonotRemove\wmv
Videos\00CpSystemFolderDonotRemove\wmv
Videos\00CpSystemFolderDonotRemove\mp4
Videos\00CpSystemFolderDonotRemove\avi
Pictures\00CpSystemFolderDonotRemove\jpg
Pictures\00CpSystemFolderDonotRemove\png
Pictures\00CpSystemFolderDonotRemove\gif
100
RankingRange[0-9:1,10-14:7,15-19:8,20-24:9,25-2147483647:10]
30
0.5
8
FileTypeExtenssions[doc,docx,xls,xlsx,pdf,png,rtf,zip,svg,wmv,mp3,rar,bmp,7z,gif,docm,dotm,xlm,xlsm,xlam,ppt,pptx,pptm,ppom,ppam,ppsm,contact,jpeg,txt]
RankingRange[1-1:3,2-2:4,3-3:5,4-4:11,5-5:12,6-6:13,7-2147483647:14]
RankingGroups[Desktop:13,Documents:13,Downloads:8,Pictures:8,Videos:8,Others:1]
)
[01-11-19 11:19:48.491] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( policyViaExclusions: false false Silent Silent Silent )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: c:\windows\explorer.exe FileName: MD5: Signer: )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: symantec corporation )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: trend micro )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: mcafee )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: mcafee epo development (spc) )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: c:\windows\explorer.exe FileName: MD5: Signer: )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: symantec corporation )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: trend micro )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: mcafee )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Adding process exclusion: Path: FileName: MD5: Signer: mcafee epo development (spc) )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.EDR.FeedHandler) message: ( Data streaming Stop called )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.EDR.FeedHandler) message: ( Stop was already done, will not call stop again )
[01-11-19 11:19:48.506] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Seting enforcement for ExperimentalSignatures: False MachineLearningValidation: False High: Silent Medium:Silent Low: Silent )
[01-11-19 11:19:48.569] [fbc:1] [Info] source: (NGAV.Connectors.AntiRansomware.AntiRansomwareConnector) message: ( Anti-Ransomware policy applied )
[01-11-19 11:19:48.569] [fbc:1] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( NGAVPolicy initialized )
[01-11-19 11:19:48.569] [fbc:1] [Info] source: (NGAV.Core.Engine) message: ( ##### Engine started #### )
[01-11-19 11:19:48.569] [fbc:1] [Info] source: (NGAV.Core.Engine) message: ( Telemetry initialized )
[01-11-19 11:19:48.772] [fbc:1] [Info] source: (NGAV.Connectors.AntiRansomware.AntiRansomwareConnector) message: ( Anti-Ransomware started )
[01-11-19 11:19:48.788] [fbc:1] [Error] source: (NGAV.Connectors.UserInterface.UserInterfaceBridge) message: ( System.TypeInitializationException: Se produjo una excepción en el inicializador de tipo de 'EPNetUtils.EndpointUI.ZdxUiNegotiator'. ---> System.IO.FileNotFoundException: The path to ZDxNet.dll cannot be located: no registry key
en EPNetUtils.EndpointUI.ZdxUiNegotiator..cctor()
--- Fin del seguimiento de la pila de la excepción interna ---
en EPNetUtils.EndpointUI.ZdxUiNegotiator..ctor()
en NGAV.Connectors.UserInterface.UserInterfaceEP..ctor()
en NGAV.Connectors.UserInterface.UserInterfaceBridge.Configure() )
[01-11-19 11:19:48.788] [fbc:1] [Info] source: (NGAV.Core.Enforcement.Remediation) message: ( Remediation initialized )
[01-11-19 11:19:48.788] [fbc:1] [Info] source: (NGAV.Helpers.HelperDirectory) message: ( Will not delete directory, Path: C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\indicators not exist )
[01-11-19 11:19:48.788] [fbc:1] [Info] source: (NGAV.Helpers.HelperDirectory) message: ( Will not delete directory, Path: C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\sentree\protections not exist )
[01-11-19 11:19:48.788] [fbc:1] [Info] source: (NGAV.Helpers.HelperDirectory) message: ( Will not delete directory, Path: C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\shared\protections not exist )
[01-11-19 11:19:51.715] [fbc:1] [Info] source: (NGAV.Core.Signatures.ParserUnsharedFormat.ParserManager) message: ( Signatures zip file extracted: C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\Signatures.zip )
[01-11-19 11:19:51.762] [fbc:1] [Info] source: (NGAV.Core.Signatures.ParserUnsharedFormat.ParserManager) message: ( mldata zip file extracted: C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\indicators\mldata.zip )
[01-11-19 11:19:53.872] [fbc:1] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Engine.DataAggregation.Records.RecordBase]) message: ( queueu started )
[01-11-19 11:19:54.872] [fbc:1] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Engine.DataAggregation.Records.RecordBase]) message: ( queueu started )
[01-11-19 11:19:54.887] [fbc:1] [Info] source: (NGAV.Core.SuspiciousEvent.SuspiciousEvents) message: ( Suspicious events initialized )
[01-11-19 11:19:54.934] [fbc:1] [Info] source: (NGAV.ML.MLMatrix) message: ( Loaded model Camouflage )
[01-11-19 11:19:54.965] [fbc:1] [Info] source: (NGAV.ML.MLMatrix) message: ( Loaded model HashCopy )
[01-11-19 11:19:54.965] [fbc:1] [Info] source: (NGAV.ML.MLMatrix) message: ( ML matrix Initialized successfuly )
[01-11-19 11:19:54.965] [fbc:1] [Info] source: (NGAV.ML.MLMatrix) message: ( Starting ML )
[01-11-19 11:19:54.965] [fbc:1] [Info] source: (NGAV.Reputation.ReputationConnector) message: ( Reputation initialized )
[01-11-19 11:19:55.965] [fbc:1] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Core.Reporting.Information.DetectedTrees]) message: ( queueu started )
[01-11-19 11:19:55.965] [fbc:1] [Info] source: (NGAV.Core.Signatures.Validation.ValidationFP) message: ( Validation FP initialized )
[01-11-19 11:19:56.200] [fbc:1b] [Info] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Ignoring Indicators for process Path: C:\Windows\Explorer.EXE MD5: 38ae1b3c38faef56fe4907922f0385ba Signer: Microsoft Windows, due to exclusion )
[01-11-19 11:19:56.965] [fbc:16] [Warn] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Enforcement type for DetectionConfidence: Low is: Silent )
[01-11-19 11:19:56.965] [fbc:16] [Warn] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Enforcement type for DetectionConfidence: Medium is: Silent )
[01-11-19 11:19:56.965] [fbc:16] [Warn] source: (NGAV.Core.Configuration.NGAVPolicy) message: ( Enforcement type for DetectionConfidence: High is: Silent )
[01-11-19 11:20:56.231] [fbc:17] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Engine.DataAggregation.Records.RecordBase]) message: ( queueu disposed )
[01-11-19 11:21:01.231] [fbc:22] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Engine.DataAggregation.Records.RecordBase]) message: ( queueu stopped )
[01-11-19 11:21:01.231] [fbc:1b] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Engine.DataAggregation.Records.RecordBase]) message: ( queueu disposed )
[01-11-19 11:21:06.231] [fbc:22] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Engine.DataAggregation.Records.RecordBase]) message: ( queueu stopped )
[01-11-19 11:21:06.231] [fbc:22] [Info] source: (NGAV.ML.MLMatrix) message: ( ML stopped )
[01-11-19 11:21:06.231] [fbc:22] [Info] source: (NGAV.Reputation.ReputationConnector) message: ( Reputation deinitialized )
[01-11-19 11:21:06.231] [fbc:19] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Core.Reporting.Information.DetectedTrees]) message: ( queueu disposed )
[01-11-19 11:21:11.231] [fbc:22] [Info] source: (NGAV.FeedManager.RecordsBlockingQueue`1[NGAV.Core.Reporting.Information.DetectedTrees]) message: ( queueu stopped )
[01-11-19 11:21:11.231] [fbc:22] [Info] source: (NGAV.Core.Signatures.Validation.ValidationFP) message: ( Validation FP deinitialized )
[01-11-19 11:21:11.231] [fbc:22] [Info] source: (NGAV.Connectors.AntiRansomware.AntiRansomwareConnector) message: ( Anti-Ransomware stopped )
[01-11-19 11:21:11.231] [fbc:22] [Info] source: (NGAV.Core.Enforcement.Remediation) message: ( Remediation deinitialized )
[01-11-19 11:21:11.231] [fbc:22] [Info] source: (NGAV.Core.Engine) message: ( ##### Engine stopped ##### )