A giudicare dal log, l'operazione sembra conclusa correttamente.
Stopped On 08-31-2023 19:03:41 (Exit Code = 0x0)
Questo browser non è più supportato.
Esegui l'aggiornamento a Microsoft Edge per sfruttare i vantaggi di funzionalità più recenti, aggiornamenti della sicurezza e supporto tecnico.
Buonasera, vorrei sapere quali dovrebbero essere i proprietari e i permessi di default delle cartelle di sistema come Windows. Controllando l'accesso valido per me, noto che è assente il controllo completo, anche per administrators.
Domanda bloccata. Questa domanda è stata eseguita dalla community del supporto tecnico Microsoft. È possibile votare se è utile, ma non è possibile aggiungere commenti o risposte o seguire la domanda.
A giudicare dal log, l'operazione sembra conclusa correttamente.
Stopped On 08-31-2023 19:03:41 (Exit Code = 0x0)
Trovato:
Microsoft Antimalware (F7F4CD20-7371-4319-B1DB-6FCFC68573EC) Service Log
Started On 08-31-2023 18:59:23
************************************************************
OS install time not retrieved: hr = 0x8007000d
Current time: 08/31/2023 18:59:23.892370400 UTC (11796 ms since boot)
2023-08-31T18:59:23.888Z ProductId: 4, ProductFeature: 0, LaunchedProtected: 0, IsWcos: 0, IsContainerOs: 0
2023-08-31T18:59:23.888Z [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: WdoWppTracing-20230831-185923-00000003-ffffffff.bin ...
2023-08-31T18:59:23.888Z [WPP] Trace session started - WdoWppTracing-20230831-185923-00000003-ffffffff.bin
2023-08-31T18:59:23.888Z OS Build/Branch info: 19041.1.amd64fre.vb_release.191206-1406
2023-08-31T18:59:23.888Z [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Offline Scanner
2023-08-31T18:59:23.888Z Service is asked to be reenabled.
2023-08-31T18:59:23.888Z Task(-EnableService) launched
2023-08-31T18:59:23.935Z Loaded module#0 MpComServer.
2023-08-31T18:59:23.935Z Loading engine...
2023-08-31T18:59:24.560Z UpdateEngine start: Source: 3, szUpdateDirectory: C:\Windows\Microsoft Antimalware\Definition Updates{2BCCDFF2-C33D-4B08-848D-97DE9DAF08B4}
2023-08-31T18:59:25.169Z Verifying engine and signature files (source: 0) ...
2023-08-31T18:59:25.309Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates{09F7CAD7-BC5C-4502-8C31-A06349EEC325}\mpengine.dll]
2023-08-31T18:59:25.840Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates{09F7CAD7-BC5C-4502-8C31-A06349EEC325}\mpasbase.vdm]
2023-08-31T18:59:25.855Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates{09F7CAD7-BC5C-4502-8C31-A06349EEC325}\mpasdlta.vdm]
2023-08-31T18:59:26.121Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates{09F7CAD7-BC5C-4502-8C31-A06349EEC325}\mpavbase.vdm]
2023-08-31T18:59:26.121Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates{09F7CAD7-BC5C-4502-8C31-A06349EEC325}\mpavdlta.vdm]
Database:
2023-08-31T18:59:26.308Z Can't find offline cache cache (C:\Windows\Microsoft Antimalware\Scans\mpcache-C6D6A097A855E62FF640BF872BB1CBD563F9B64C.bin): 0x00000002IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007bIDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000dIDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d
2023-08-31T18:59:32.151Z [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=144000000000, scope=0x380)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Aplha Test for ASR in Audit Mode", State=5, Action=1, Type=1, Duplicates(Interval=0, scope=0x0)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Aplha Test for ASR in Block Mode", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)
Engine-HIPS:
2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)
2023-08-31T18:59:32.182Z CSignatureStatus: back to good
2023-08-31T18:59:32.182Z [Engine] Loaded C:\Windows\Microsoft Antimalware\Definition Updates{09F7CAD7-BC5C-4502-8C31-A06349EEC325}
2023-08-31T18:59:32.182Z [Engine] Removing C:\Windows\Microsoft Antimalware\Definition Updates{2BCCDFF2-C33D-4B08-848D-97DE9DAF08B4} ...
2023-08-31T18:59:32.182Z MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0x0
Signature updated via XCopy on 08-31-2023 18:59:32
Product Version: 4.18.1907.16384
Service Version: 4.18.1909.6
Engine Version: 1.1.23080.2005
AS Signature Version: 1.397.101.0
AV Signature Version: 1.397.101.0
************************************************************
2023-08-31T18:59:32.198Z UpdateEngine finished with 0x0: Source: 3, szUpdateDirectory: C:\Windows\Microsoft Antimalware\Definition Updates{2BCCDFF2-C33D-4B08-848D-97DE9DAF08B4}
2023-08-31T18:59:32.213Z Engine loaded!
2023-08-31T18:59:32.213Z Verifying license file...
2023-08-31T18:59:32.213Z Verified [C:\ProgramData\Microsoft\Windows Defender\Offline Scanner\msmplics.dll]
2023-08-31T18:59:32.213Z MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0x0
Product Version: 4.18.1907.16384
Service Version: 4.18.1909.6
Engine Version: 1.1.23080.2005
AS Signature Version: 1.397.101.0
AV Signature Version: 1.397.101.0
************************************************************
2023-08-31T18:59:32.995Z MpManagerEnable: setting DisableAS to 0 ...
2023-08-31T18:59:32.995Z MpManagerEnable: setting DisableAV to 0 ...
2023-08-31T18:59:32.995Z Scheduled scan configured CPU priority: normal (LowCpuPriority: 0)
Internal signature match:subtype=Lowfi, sigseq=0x0000157EECC7829F, sigsha=988df01ffc332e9c60addbbe1c74b85f43b49817, cached=false, source=0, resourceid=0x0179b885
Internal signature match:subtype=Lowfi, sigseq=0x00001080CF3DC54A, sigsha=dc7a9ea95ab1830307a97c696dec431373c25910, cached=false, source=0, resourceid=0x1e17b347
Internal signature match:subtype=Lowfi, sigseq=0x0000157E98961FA8, sigsha=29727b199c33e2ba7beb863c494f3a822d8e7975, cached=false, source=0, resourceid=0x1e17b347
Internal signature match:subtype=Lowfi, sigseq=0x0000157E7DA74CE2, sigsha=be4b045066adb117662addadfa72dfb59bf95f4a, cached=false, source=0, resourceid=0xebbb5019
Internal signature match:subtype=Lowfi, sigseq=0x0000157EA88D91A9, sigsha=7b236713674a60036db07f5aacf97713795f971b, cached=false, source=0, resourceid=0xebbb5019
Internal signature match:subtype=Lowfi, sigseq=0x0000157E3BAEFC7E, sigsha=b0a8beb1665493c99b94ee6937bbfd9cde0e115d, cached=false, source=0, resourceid=0xebbb5019
Internal signature match:subtype=Lowfi, sigseq=0x0000157E90C02BA5, sigsha=2b4fbfe1f738b340a4d45f1eb904b0db2cec9e80, cached=false, source=0, resourceid=0x3105a5dd
Internal signature match:subtype=Lowfi, sigseq=0x0000157EF20D1A7C, sigsha=aa5b9372f0ec225d6342e12ffb9db40b90cfd590, cached=false, source=0, resourceid=0x399405b1
Internal signature match:subtype=Lowfi, sigseq=0x0000157EE45A0D42, sigsha=73f044c8433b867a62860948a23e8ab3d134e025, cached=false, source=0, resourceid=0x5b9dc1be
Internal signature match:subtype=Lowfi, sigseq=0x0000157EFE404EE0, sigsha=d305323f56f3cf14dec20fcc80a8b76d2197d0db, cached=false, source=0, resourceid=0xbfe8f9b7
2023-08-31T18:59:40.797Z [Cloud] Engine is requesting config to do cloud query [regular network].
Engine:
2023-08-31T19:00:16.151Z Setting original file name "control.exe" for "\?\c:\windows\syswow64\fontext.dll", hr=0x0
2023-08-31T19:00:23.906Z Process scan (postsignatureupdatescan) started.
2023-08-31T19:00:24.156Z Process scan (postsignatureupdatescan) completed.
Internal signature match:subtype=Lowfi, sigseq=0x0000157E4A007D3D, sigsha=63c44c372481504bb7fb73e1489e29be34876793, cached=false, source=0, resourceid=0xa681fa81
Engine:
2023-08-31T19:00:37.063Z Setting original file name "mshta.exe" for "\?\c:\windows\syswow64\mshtml.dll", hr=0x0
Internal signature match:subtype=Lowfi, sigseq=0x0000157E54114927, sigsha=b65e7387d9262d4ec12d80df586114a94463914a, cached=false, source=0, resourceid=0xde8c842f
Internal signature match:subtype=Lowfi, sigseq=0x0000157EBA69AEFD, sigsha=572d748d4369bb207228c0910ae5a8692983d001, cached=false, source=0, resourceid=0xde8c842f
Engine:
2023-08-31T19:00:47.734Z Setting original file name "pcalua.exe" for "\?\c:\windows\syswow64\pcacli.dll", hr=0x0
Engine:
2023-08-31T19:00:47.814Z Setting original file name "pcalua.exe" for "\?\c:\windows\syswow64\pcaui.exe", hr=0x0
Engine:
2023-08-31T19:00:55.132Z Setting original file name "reg.exe" for "\?\c:\windows\syswow64\reg.exe", hr=0x0
Engine:
2023-08-31T19:00:55.398Z Setting original file name "register-cimprovider2.exe" for "\?\c:\windows\syswow64\register-cimprovider.exe", hr=0x0
Engine:
2023-08-31T19:00:57.141Z Setting original file name "rundll32.exe" for "\?\c:\windows\syswow64\rundll32.exe", hr=0x0
Engine:
2023-08-31T19:00:57.719Z Setting original file name "schtasks.exe" for "\?\c:\windows\syswow64\schtasks.exe", hr=0x0
Internal signature match:subtype=Lowfi, sigseq=0x0000157EECC7829F, sigsha=988df01ffc332e9c60addbbe1c74b85f43b49817, cached=false, source=0, resourceid=0x0179b885
Engine:
2023-08-31T19:02:17.138Z Setting original file name "pcalua.exe" for "\?\c:\windows\system32\pcacli.dll", hr=0x0
Engine:
2023-08-31T19:02:17.169Z Setting original file name "pcalua.exe" for "\?\c:\windows\system32\pcadm.dll", hr=0x0
Engine:
2023-08-31T19:02:23.177Z Setting original file name "reg.exe" for "\?\c:\windows\system32\reg.exe", hr=0x0
Engine:
2023-08-31T19:02:23.318Z Setting original file name "register-cimprovider2.exe" for "\?\c:\windows\system32\register-cimprovider.exe", hr=0x0
Engine:
2023-08-31T19:02:25.488Z Setting original file name "rundll32.exe" for "\?\c:\windows\system32\rundll32.exe", hr=0x0
Engine:
2023-08-31T19:02:26.025Z Setting original file name "schtasks.exe" for "\?\c:\windows\system32\schtasks.exe", hr=0x0
Internal signature match:subtype=Lowfi, sigseq=0x0000157EF20D1A7C, sigsha=aa5b9372f0ec225d6342e12ffb9db40b90cfd590, cached=false, source=0, resourceid=0x399405b1
Engine:
2023-08-31T19:02:41.303Z Setting original file name "vssadmin.exe" for "\?\c:\windows\system32\vssadmin.exe", hr=0x0
Engine:
2023-08-31T19:03:00.386Z Triggered AR EMS scan
Engine:
2023-08-31T19:03:00.386Z EMS scan for process: lsass pid: 668, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2023-08-31T19:03:00.511Z EMS scan for process: svchost pid: 796, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2023-08-31T19:03:00.594Z EMS scan for process: svchost pid: 892, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2023-08-31T19:03:00.625Z EMS scan for process: svchost pid: 976, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2023-08-31T19:03:00.747Z EMS scan for process: svchost pid: 1016, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2023-08-31T19:03:00.832Z EMS scan for process: svchost pid: 428, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2023-08-31T19:03:00.879Z EMS scan for process: svchost pid: 448, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2023-08-31T19:03:00.973Z EMS scan for process: svchost pid: 1328, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2023-08-31T19:03:01.051Z EMS scan for process: svchost pid: 1424, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2023-08-31T19:03:01.098Z EMS scan for process: svchost pid: 1572, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2023-08-31T19:03:01.145Z EMS scan for process: svchost pid: 1636, sigseq: 0x0, sendMemoryScanReport: 0, source: 2
Engine:
2023-08-31T19:03:02.922Z Setting original file name "powershell.exe" for "\?\c:\windows\system32\windowspowershell\v1.0\powershell.exe", hr=0x0
Engine:
2023-08-31T19:03:02.969Z Setting original file name "powershell.exe" for "\?\c:\windows\syswow64\windowspowershell\v1.0\powershell.exe", hr=0x0
Internal signature match:subtype=Lowfi, sigseq=0x0000157E4A007D3D, sigsha=63c44c372481504bb7fb73e1489e29be34876793, cached=true, source=0, resourceid=0xa681fa81
Internal signature match:subtype=Lowfi, sigseq=0x0000157EFE404EE0, sigsha=d305323f56f3cf14dec20fcc80a8b76d2197d0db, cached=false, source=0, resourceid=0xbfe8f9b7
2023-08-31T19:03:27.246Z [Cloud] Engine is requesting config to do cloud query [regular network].
Internal signature match:subtype=Lowfi, sigseq=0x0000157EECC7829F, sigsha=988df01ffc332e9c60addbbe1c74b85f43b49817, cached=true, source=0, resourceid=0x0179b885
Internal signature match:subtype=Lowfi, sigseq=0x00005BE7D967BD5A, sigsha=5a4d1a98d2a4cf463a562f95fc9eb8bb83207c6f, cached=false, source=0, resourceid=0x3c04fe46
2023-08-31T19:03:41.423Z [Cloud] Engine is requesting config to do cloud query [regular network].
2023-08-31T19:03:41.423Z Service stop requested (ServiceError: 0x0). Calling CleanupMpService ...
2023-08-31T19:03:41.663Z Unloaded module#0 MpComServer.
Microsoft Antimalware (F7F4CD20-7371-4319-B1DB-6FCFC68573EC) Log
Stopped On 08-31-2023 19:03:41 (Exit Code = 0x0)
************************************************************
crashata al 91% con 47000 file scansionati circa, dove trovo il log?
Windows Defender si è bloccato così
Effettua una scansione offline e vedi se la porta a termine.
Vabbè...comunque per essere più sicuro con l'EFI/CompuTrace.A voglio cambiare scheda madre.
Nessun virus sopravvive a una reinstallazione pulita, con eliminazione delle partizioni.
Nello specifico, si tratta solo di un'applicazione potenzialmente indesiderata, nulla di veramente pericoloso.