HitmanPro.ALERT Support and Discussion Thread

Discussion in 'other anti-malware software' started by erikloman, May 25, 2012.

  1. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    HMP.Alert is exactly that for me. If I am alerted to an attack, I plan to use that as a signal to do a full restore of my PC with an image made prior to the attack, and that has been kept offline.

    I also run a standard AV solution as well as several 2nd opinion malware scanners to ensure that I stay clean. But I don't trust anything to clean my system after it has been compromised. There's no telling what got in there if it got past my layered security defenses. Images are actually my #1 security plan.
     
  2. GrDukeMalden

    GrDukeMalden Registered Member

    Joined:
    Jun 16, 2016
    Posts:
    491
    Location:
    VPN city
    Yes. I've seen it block other kinds of attacks on my own system. I'm not sure what those attacks were. I was browsing...certain kinds of websites when HMPA popped up. But most ransomware is able to do its damage no problem with a system protected by HMPA.

    I use HMPA to beef up Sandboxie, mostly.
     
  3. GrDukeMalden

    GrDukeMalden Registered Member

    Joined:
    Jun 16, 2016
    Posts:
    491
    Location:
    VPN city
    That's why I contain everything in sandboxie.
     
  4. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    Screenshots and logs, or it did not happen.
     
  5. GrDukeMalden

    GrDukeMalden Registered Member

    Joined:
    Jun 16, 2016
    Posts:
    491
    Location:
    VPN city
    I already posted links to videos where HMPA failed against ransomware.
     
  6. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    Those links appear to be broken...
     
  7. GrDukeMalden

    GrDukeMalden Registered Member

    Joined:
    Jun 16, 2016
    Posts:
    491
    Location:
    VPN city
    Here's the un-shortened URLs then

    https://www.youtube.com/watch?v=wVBPjxkhCHI
    The PC security Channel. This test killed the ransomware, but allowed other things. Namely a backdoor. He did a different test where it didn't stop any of the ransomware.

    https://www.youtube.com/watch?v=r5LVmnm5cmc
    MalwareGeek. This test showed that HMPA's cryptoguard doesn't work very well.

    https://www.youtube.com/watch?v=P2h2zsrd9e8
    Computer Solutions, they said it passed, but it actually failed according to their own video. One sample was known to HMP and the other sample ran free with no restrictions.

    And yes, I know these videos are from a long time ago. But this is what I was talking about when I say HMPA isn't advertised as what it actually is.

    If the ransomware in two of these videos came from an exploit, then HMPA would stop it. But since the payload is already there in these tests it can't stop it.
     
  8. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    Screenshots and logs, of your own complains, or it did not happen.
     
  9. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    Dated stuff, with the payload magically there...
     
  10. GrDukeMalden

    GrDukeMalden Registered Member

    Joined:
    Jun 16, 2016
    Posts:
    491
    Location:
    VPN city
    I know. I already said that. The point I was making is that when most people see HMPA, they think it's just a standard supplementary product, not an anti-exploit application.

    What do you expect me to do exactly? I don't have the resources to upload a video like that.

    And again, I'm not saying HMPA is a bad product, it's good at protecting against what it's meant to protect against. I'm simply saying that a lot of people have a misconception of what it actually does.
     
  11. Izettso

    Izettso Registered Member

    Joined:
    Oct 1, 2007
    Posts:
    91
    I'm following this discussion and admittedly I don't understand its substance. Maybe it's because nobody answered or could answer my query at https://www.wilderssecurity.com/thr...iscussion-thread.324841/page-645#post-2948774. Some documentation for HMPA users would be very useful.
     
  12. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Yep, same. Creating Macrium Boot Menu.

    The application has accessed and encrypted multiple productivity files (documents, photos and similar file types). This is indicative of a crypto-ransomware attack. The manipulated files were restored to their original state.

    MITRE ATT&CK

    Data Destruction - ID: T1485, Tactic: Impact
    Data Encrypted for Impact - ID: T1486, Tactic: Impact


    Code:
    Mitigation   CryptoGuard
    Timestamp    2020-09-22T14:03:54
    
    Platform     10.0.19041/x64 v875 06_8e
    PID          14204
    Application  C:\Windows\System32\Dism.exe
    Created      2020-09-11T07:36:19
    Description  Dism Image Servicing Utility 10
    
    Filename     C:\Windows\System32\Dism.exe
    
    Detection    Generic.Ransom.C
    
     1*C:\Users\pauld\AppData\Local\Temp\37fb705b-c3fa-4d6b-8d9b-1d449172ead6
       Overwritten L0, Read T8704 H4232|^231, Write T8704 H4232|^231 #1,2
    
     2*C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Multimedia-MFCore-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
       Opened L9068, Read T9216|100% H9068 #2,1
    
     3 C:\Users\pauld\AppData\Local\Temp\c2e56a21-1e01-4247-9845-47eb7cbcb400
       Overwritten L0, Read T8704 H4124|^264, Write T8704 H4124|^264 #3
    
     4 C:\Users\pauld\AppData\Local\Temp\b1b08542-29ef-4161-b37d-4f782693b3b9
       Overwritten L0, Read T5632 H5410|^317, Write T5632 H5410|^317 #4
    
     5*C:\Users\pauld\AppData\Local\Temp\db1039e0-5b32-42aa-9367-55a8465688db
       Overwritten L0, Read T8704 H4186|^258, Write T8704 H4186|^258 #5,6
    
     6*C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Multimedia-MFCore-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
       Opened L8743, Read T9216|100% H8743 #6,5
    
     7 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Multimedia-MFCore-WCOSMinusHeadless-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.508.cat
       Opened L18999, Read T19456|100% H18999 #7
    
     8*C:\Users\pauld\AppData\Local\Temp\8d1d3e53-b6cd-4689-80b7-0c3008f698bf
       Overwritten L0, Read T8704 H8348|^240, Write T8704 H8348|^240 #8,23
    
     9*C:\Users\pauld\AppData\Local\Temp\371e96de-3515-4279-80e3-36ff285270d1
       Overwritten L0, Read T8704 H8346|^256, Write T8704 H8346|^256 #9,18
    
    10 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Multimedia-MFCore-WCOSMinusHeadless-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
       Opened L19165, Read T19456|100% H19165 #10
    
    11 C:\Users\pauld\AppData\Local\Temp\cbe9591e-eed5-49b3-baa6-eb3006269df8
       Overwritten L0, Read T6144 H5696|^293, Write T6144 H5696|^293 #11
    
    12*C:\Users\pauld\AppData\Local\Temp\cf7b982d-3663-4e7c-b49b-c826556115d1
       Overwritten L0, Read T8704 H8266|^260, Write T8704 H8266|^260 #12,13
    
    13*C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Multimedia-MFCore-WCOSMinusHeadless-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
       Opened L8932, Read T9216|100% H8932|^15327 #13,12
    
    14 C:\Users\pauld\AppData\Local\Temp\b1b08542-29ef-4161-b37d-4f782693b3b9
       Overwritten L0, Read T5632 H5400|^271, Write T5632 H5400|^271 #14
    
    15 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Multimedia-MFCore-WCOSMinusHeadless-Package~31bf3856ad364e35~amd64~~10.0.19041.508.cat
       Opened L19158, Read T19456|100% H19158 #15
    
    16 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Multimedia-MFCore-WCOSMinusHeadless-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
       Opened L19131, Read T19456|100% H19131|^96045 #16
    
    18*C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Multimedia-MFCore-WCOSMinusHeadless-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
       Opened L9700, Read T9728|100% H9700|^17140 #18,9
    
    23*C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Multimedia-MFCore-WCOSHeadless-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
       Opened L8932, Read T9216|100% H8932|^15324 #23,8
    
    
    
    Loaded Modules (50)
    -----------------------------------------------------------------------------
    00007FF706430000-00007FF706478000 dism.exe (Microsoft Corporation),
                                      Version: 10.0.19041.329
    00007FF828250000-00007FF828445000 ntdll.dll (Microsoft Corporation),
                                      Version: 10.0.19041.488
    00007FF826C30000-00007FF826CED000 KERNEL32.dll (Microsoft Corporation),
                                      Version: 10.0.19041.292
    00007FF825620000-00007FF825731000 hmpalert.dll (SurfRight B.V.),
                                      Version: 3.8.6.875
    00007FF825D80000-00007FF826047000 KERNELBASE.dll (Microsoft Corporation),
                                      Version: 10.0.19041.488
    00007FF827540000-00007FF8275DE000 msvcrt.dll (Microsoft Corporation),
                                      Version: 7.0.19041.1
    00007FF826B10000-00007FF826BBA000 ADVAPI32.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FF826700000-00007FF82679B000 sechost.dll (Microsoft Corporation),
                                      Version: 10.0.19041.388
    00007FF8277E0000-00007FF827904000 RPCRT4.dll (Microsoft Corporation),
                                      Version: 10.0.19041.508
    00007FF827910000-00007FF827A39000 OLE32.dll (Microsoft Corporation),
                                      Version: 10.0.19041.84
    00007FF825AA0000-00007FF825BA0000 ucrtbase.dll (Microsoft Corporation),
                                      Version: 10.0.19041.488
    00007FF8267A0000-00007FF826AF5000 combase.dll (Microsoft Corporation),
                                      Version: 10.0.19041.508
    00007FF8276C0000-00007FF8276EA000 GDI32.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FF826050000-00007FF826072000 win32u.dll (Microsoft Corporation),
                                      Version: 10.0.19041.508
    00007FF825990000-00007FF825A99000 gdi32full.dll (Microsoft Corporation),
                                      Version: 10.0.19041.508
    00007FF826080000-00007FF82611D000 msvcp_win.dll (Microsoft Corporation),
                                      Version: 10.0.19041.488
    00007FF826560000-00007FF826700000 USER32.dll (Microsoft Corporation),
                                      Version: 10.0.19041.488
    00007FF8275F0000-00007FF8276BD000 OLEAUT32.dll (Microsoft Corporation),
                                      Version: 10.0.19041.388
    00007FF81A760000-00007FF81A76A000 VERSION.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FF8276F0000-00007FF827720000 IMM32.DLL (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FFFF4370000-00007FFFF441F000 a2hooks64.dll (Emsisoft Ltd),
                                      Version: 2019.2.0.1903
    00007FF827A40000-00007FF828181000 SHELL32.dll (Microsoft Corporation),
                                      Version: 10.0.19041.488
    00007FF8245C0000-00007FF8245F3000 ntmarta.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FF820B70000-00007FF821303000 windows.storage.dll (Microsoft Corporation),
                                      Version: 10.0.19041.508
    00007FF8252E0000-00007FF82530C000 Wldp.dll (Microsoft Corporation),
                                      Version: 10.0.19041.423
    00007FF8264B0000-00007FF82655E000 SHCORE.dll (Microsoft Corporation),
                                      Version: 10.0.19041.488
    00007FF827720000-00007FF827775000 shlwapi.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FF8258C0000-00007FF8258E6000 profapi.dll (Microsoft Corporation),
                                      Version: 10.0.19041.488
    00007FF8241B0000-00007FF8241C3000 kernel.appcore.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FF825D00000-00007FF825D7F000 bcryptPrimitives.dll (Microsoft Corporation),
                                      Version: 10.0.19041.264
    00007FF80CE60000-00007FF80CEC6000 DismCore.dll (Microsoft Corporation),
                                      Version: 10.0.19041.329
    00007FF80C540000-00007FF80C571000 DismCorePS.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FF8271F0000-00007FF827298000 clbcatq.dll (Microsoft Corporation),
                                      Version: 2001.12.10941.16384
    00007FF820660000-00007FF820844000 dbghelp.dll (Microsoft Corporation),
                                      Version: 10.0.19041.488
    00007FF812B30000-00007FF812B5C000 dbgcore.DLL (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FFFFD090000-00007FFFFD0D1000 dismprov.dll (Microsoft Corporation),
                                      Version: 10.0.19041.329
    00007FF80C520000-00007FF80C535000 LogProvider.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FFFFBE70000-00007FFFFBEB3000 WDSCORE.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FFFFBE10000-00007FFFFBE22000 FolderProvider.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FFFD5910000-00007FFFD59AF000 FfuProvider.dll (Microsoft Corporation),
                                      Version: 10.0.19041.423
    00007FF826180000-00007FF8261A7000 bcrypt.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FFFD2700000-00007FFFD2796000 WimProvider.dll (Microsoft Corporation),
                                      Version: 10.0.19041.423
    00007FF81DF70000-00007FF81DFA6000 XmlLite.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FFFEF010000-00007FFFEF0CD000 WIMGAPI.DLL (Microsoft Corporation),
                                      Version: 10.0.19041.423
    00007FFFD57F0000-00007FFFD587E000 VHDProvider.dll (Microsoft Corporation),
                                      Version: 10.0.19041.423
    00007FFFEFAD0000-00007FFFEFB08000 ImagingProvider.dll (Microsoft Corporation),
                                      Version: 10.0.19041.423
    00007FF825840000-00007FF82587C000 sspicli.dll (Microsoft Corporation),
                                      Version: 10.0.19041.488
    00007FF824F60000-00007FF824FEA000 msv1_0.DLL (Microsoft Corporation),
                                      Version: 10.0.19041.450
    00007FF824F40000-00007FF824F53000 NtlmShared.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    00007FF825080000-00007FF825095000 cryptdll.dll (Microsoft Corporation),
                                      Version: 10.0.19041.1
    
    Process Trace
    1  C:\Windows\System32\Dism.exe [14204] 2020-09-22T14:03:32
       "C:\WINDOWS\system32\dism.exe" /English /unmount-wim /mountdir:"c:\boot\macrium\WinREFiles\mount" /commit
    2  C:\Program Files\Macrium\Reflect\RMBuilder.exe [14604] 2020-09-22T13:51:36
       "C:\program files\macrium\reflect\rmbuilder.exe" *00000000000309C8
    3  C:\Program Files\Macrium\Reflect\ReflectBin.exe [10828] 2020-09-22T13:50:27
    4  C:\Program Files\Macrium\Reflect\Reflect.exe [11496] 2020-09-22T13:50:24
    5  C:\Windows\explorer.exe [8836] 2020-09-22T12:40:41
    6  C:\Windows\System32\userinit.exe [7012] 2020-09-22T12:40:37 27.9s
    7  C:\Windows\System32\winlogon.exe [8] 2020-09-22T12:40:30
       winlogon.exe
    8  C:\Windows\System32\smss.exe [920] 2020-09-22T12:40:30 64ms
       \SystemRoot\System32\smss.exe 000000d0 00000084
    9  C:\Windows\System32\smss.exe [560] 2020-09-22T12:40:20
       \SystemRoot\System32\smss.exe
    
    Dropped Files
    1  C:\Users\pauld\AppData\Local\Temp\cf7b982d-3663-4e7c-b49b-c826556115d1
         Dropped by \Device\HarddiskVolume5\Windows\System32\Dism.exe [14204]
    2  C:\Users\pauld\AppData\Local\Temp\cbe9591e-eed5-49b3-baa6-eb3006269df8
         Dropped by \Device\HarddiskVolume5\Windows\System32\Dism.exe [14204]
            Read by \Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.9-0\MsMpEng.exe [4976]
    3  C:\Users\pauld\AppData\Local\Temp\8d1d3e53-b6cd-4689-80b7-0c3008f698bf
         Dropped by \Device\HarddiskVolume5\Windows\System32\Dism.exe [14204]
            Read by \Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.9-0\MsMpEng.exe [4976]
    4  C:\Users\pauld\AppData\Local\Temp\c2e56a21-1e01-4247-9845-47eb7cbcb400
         Dropped by \Device\HarddiskVolume5\Windows\System32\Dism.exe [14204]
    5  C:\Users\pauld\AppData\Local\Temp\371e96de-3515-4279-80e3-36ff285270d1
         Dropped by \Device\HarddiskVolume5\Windows\System32\Dism.exe [14204]
            Read by \Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.9-0\MsMpEng.exe [4976]
    6  C:\Users\pauld\AppData\Local\Temp\db1039e0-5b32-42aa-9367-55a8465688db
         Dropped by \Device\HarddiskVolume5\Windows\System32\Dism.exe [14204]
    7  C:\Users\pauld\AppData\Local\Temp\37fb705b-c3fa-4d6b-8d9b-1d449172ead6
         Dropped by \Device\HarddiskVolume5\Windows\System32\Dism.exe [14204]
    8  C:\Users\pauld\AppData\Local\Temp\8987fece-3d8f-4588-8df2-9d58b4be85b3
         Dropped by \Device\HarddiskVolume5\Windows\System32\Dism.exe [14204]
    9  C:\Users\pauld\AppData\Local\Temp\b1b08542-29ef-4161-b37d-4f782693b3b9
         Dropped by \Device\HarddiskVolume5\Windows\System32\Dism.exe [14204]
    1  C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem85.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    2  C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem86.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    3  C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem87.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    4  C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem88.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    5  C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem9.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    6  C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\openssh-client-package-Wrapper~31bf3856ad364e35~amd64~~10.0.19041.488.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    7  C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\OpenSSH-Client-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    8  C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\OpenSSH-Client-Package~31bf3856ad364e35~amd64~~10.0.19041.488.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    9  C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_10_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    10 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_11_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    11 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_12_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    12 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_13_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    13 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_14_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    14 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_15_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    15 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_16_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    16 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_17_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    17 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_18_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    18 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_19_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    19 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1_for_KB4561600~31bf3856ad364e35~amd64~~10.0.1.0.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    20 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1_for_KB4576478~31bf3856ad364e35~amd64~~10.0.4240.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    21 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    22 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_20_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    23 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_21_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    24 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_22_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    25 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB4561600~31bf3856ad364e35~amd64~~10.0.1.0.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    26 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB4576478~31bf3856ad364e35~amd64~~10.0.4240.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    27 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    28 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB4576478~31bf3856ad364e35~amd64~~10.0.4240.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    29 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    30 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_4_for_KB4576478~31bf3856ad364e35~amd64~~10.0.4240.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    31 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_4_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    32 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_5_for_KB4576478~31bf3856ad364e35~amd64~~10.0.4240.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    33 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_5_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    34 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_6_for_KB4576478~31bf3856ad364e35~amd64~~10.0.4240.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    35 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_6_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    36 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_7_for_KB4576478~31bf3856ad364e35~amd64~~10.0.4240.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    37 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_7_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    38 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_8_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    39 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_9_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    40 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_for_DotNetRollup~31bf3856ad364e35~amd64~~10.0.4240.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    41 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_for_KB4561600~31bf3856ad364e35~amd64~~10.0.1.0.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    42 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_for_KB4577266~31bf3856ad364e35~amd64~~19041.504.1.2.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    43 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.508.1.9.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    44 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnge001.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    45 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnms002.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    46 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnms003.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    47 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnms004.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    48 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnms005.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    49 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnms007.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    50 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnms008.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    51 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnms010.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    52 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnms011.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    53 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnms012.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    54 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnms014.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    55 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\RemoteDesktopServices-Base-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    56 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\RemoteDesktopServices-Base-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    57 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\RemoteDesktopServices-Base-Package~31bf3856ad364e35~amd64~~10.0.19041.84.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    58 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Server-Help-Package.ClientEnterprise~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    59 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Server-Help-Package.ClientEnterprise~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    60 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-AppLayer-Group-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    61 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-AppLayer-Group-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    62 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-ApplicationGuard-Inbox-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    63 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-ApplicationGuard-Inbox-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    64 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-ApplicationGuard-Inbox-Package~31bf3856ad364e35~amd64~~10.0.19041.488.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    65 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-ApplicationGuard-Inbox-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    66 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-ApplicationGuard-Inbox-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    67 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-ApplicationGuard-Inbox-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.488.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    68 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Client-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    69 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Client-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    70 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Client-Package~31bf3856ad364e35~amd64~~10.0.19041.329.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    71 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Core-Group-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    72 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Core-Group-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    73 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Core-Group-Package~31bf3856ad364e35~amd64~~10.0.19041.329.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    74 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Group-Policy-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    75 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Group-Policy-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    76 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Management-Group-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    77 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Management-Group-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    78 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Management-MDM-Group-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    79 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Management-MDM-Group-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    80 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Management-Powershell-Group-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    81 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Management-Powershell-Group-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    82 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Nis-Group-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    83 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Nis-Group-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    84 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WindowsSearchEngineSKU-Group-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    85 C:\boot\macrium\WinREFiles\mount\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WindowsSearchEngineSKU-Group-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    86 C:\boot\macrium\WinREFiles\media\bootmgfw.efi
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    87 C:\boot\macrium\WinREFiles\media\boot\bcdedit.exe
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    88 C:\ProgramData\Macrium\RMBuilder\BuildDevices.log
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    89 C:\boot\macrium\WinREFiles\media\Drivers\Macrium.oem
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    90 C:\boot\macrium\WinREFiles\media\Drivers\Wifi\VEN_8086_DEV_02F0\IntelIHVRouter08.dll
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
            Read by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    91 C:\boot\macrium\WinREFiles\media\Drivers\Wifi\VEN_8086_DEV_02F0\netvwifibus.inf
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
            Read by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    92 C:\boot\macrium\WinREFiles\media\Drivers\Wifi\VEN_8086_DEV_02F0\Netwfw08.dat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
            Read by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    93 C:\boot\macrium\WinREFiles\media\Drivers\Wifi\VEN_8086_DEV_02F0\Netwfw10.dat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
            Read by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    94 C:\boot\macrium\WinREFiles\media\Drivers\Wifi\VEN_8086_DEV_02F0\Netwtw08.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
            Read by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    95 C:\boot\macrium\WinREFiles\media\Drivers\Wifi\VEN_8086_DEV_02F0\netwtw08.inf
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
            Read by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    96 C:\boot\macrium\WinREFiles\media\Drivers\Wifi\VEN_8086_DEV_02F0\netwtw08.PNF
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
            Read by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    97 C:\boot\macrium\WinREFiles\media\Drivers\Wifi\VEN_8086_DEV_02F0\Netwtw08.sys
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
            Read by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    98 C:\boot\macrium\WinREFiles\media\Drivers\Wifi\VEN_8086_DEV_02F0\Netwtw10.inf
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
            Read by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    99 C:\boot\macrium\WinREFiles\media\Drivers\Wifi\VEN_8086_DEV_02F0\Netwtw10.sys
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
            Read by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    100 C:\boot\macrium\WinREFiles\mount\Drivers\Macrium.oem
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    101 C:\boot\macrium\WinREFiles\mount\Drivers\Wifi\VEN_8086_DEV_02F0\IntelIHVRouter08.dll
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    102 C:\boot\macrium\WinREFiles\mount\Drivers\Wifi\VEN_8086_DEV_02F0\netvwifibus.inf
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    103 C:\boot\macrium\WinREFiles\mount\Drivers\Wifi\VEN_8086_DEV_02F0\Netwfw08.dat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    104 C:\boot\macrium\WinREFiles\mount\Drivers\Wifi\VEN_8086_DEV_02F0\Netwfw10.dat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    105 C:\boot\macrium\WinREFiles\mount\Drivers\Wifi\VEN_8086_DEV_02F0\Netwtw08.cat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    106 C:\boot\macrium\WinREFiles\mount\Drivers\Wifi\VEN_8086_DEV_02F0\netwtw08.inf
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    107 C:\boot\macrium\WinREFiles\mount\Drivers\Wifi\VEN_8086_DEV_02F0\netwtw08.PNF
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    108 C:\boot\macrium\WinREFiles\mount\Drivers\Wifi\VEN_8086_DEV_02F0\Netwtw08.sys
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    109 C:\boot\macrium\WinREFiles\mount\Drivers\Wifi\VEN_8086_DEV_02F0\Netwtw10.inf
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    110 C:\boot\macrium\WinREFiles\mount\Drivers\Wifi\VEN_8086_DEV_02F0\Netwtw10.sys
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    111 C:\boot\macrium\WinREFiles\mount\Drivers\SearchPaths.txt
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    112 C:\boot\macrium\WinREFiles\mount\boot\reflect.cfg
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    113 C:\boot\macrium\WinREFiles\DriversHash.bin
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    114 C:\boot\macrium\WinREFiles\media\Version
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    115 C:\boot\macrium\WinREFiles\media\PEVersion
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    116 C:\boot\macrium\WinREFiles\media\x64
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\RMBuilder.exe [14604]
    1  C:\ProgramData\Macrium\Reflect\OK.bmp
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    2  C:\ProgramData\Macrium\Reflect\OK16.bmp
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    3  C:\ProgramData\Macrium\Reflect\Delete.bmp
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    4  C:\ProgramData\Macrium\Reflect\Delete16.bmp
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    5  C:\ProgramData\Macrium\Reflect\Cancel.bmp
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    6  C:\ProgramData\Macrium\Reflect\Cancel16.bmp
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    7  C:\ProgramData\Macrium\Reflect\Wrning.bmp
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    8  C:\ProgramData\Macrium\Reflect\Wrning16.bmp
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    9  C:\ProgramData\Macrium\Reflect\bmp.tmp
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    10 C:\ProgramData\Macrium\Reflect\XMLFiles.dat
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    11 C:\Users\pauld\AppData\Local\Microsoft\Windows\INetCache\IE\MDLVEO95\patch[1].htm
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    12 \\?\Volume{fb7120cf-6b5a-4439-ae24-54e4d49f09ee}\is_protected.mrimg
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    13 C:\is_protected.mrimg
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    14 D:\is_protected.mrimg
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    15 \\?\Volume{727be1a9-2a39-41b8-b556-84fe402c1d74}\is_protected.mrimg
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    16 E:\is_protected.mrimg
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    17 C:\Users\pauld\AppData\Local\Temp\~DFF6DB7B5AFCED46E2.TMP
         Dropped by \Device\HarddiskVolume5\Program Files\Macrium\Reflect\ReflectBin.exe [10828]
    1  C:\Users\pauld\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
         Dropped by \Device\HarddiskVolume5\Windows\explorer.exe [8836]
            Read by \Device\HarddiskVolume5\Windows\explorer.exe [8836]
    2  C:\Users\pauld\AppData\Roaming\Microsoft\Windows\Themes\CachedFiles\CachedImage_1920_1080_POS1.jpg
         Dropped by \Device\HarddiskVolume5\Windows\explorer.exe [8836]
    
    Thumbprints
    1234cb96f13b12fb8569b71710a0903b73466391fe298e0fd06bba3c0e6bcba8
    
     
  13. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    And on what exactly do you base this conclusion? I already said that tools like HMPA will never be able to provide 100% protection against ransomware, but if AV fails to block ransomware via signature/heuristics, then tools like HMPA might be able to help via behaviorial blocking.

    It should also block malware from performing process hollowing and APC code injection, again if AV fails to do so. I don't see any false advertising on the HMPA site, but perhaps it should become more clear that it should always be used alongside an AV.
     
  14. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    I restarted my computer and HMPA 3.7 build 797 started a scan. I never saw this before. I don't see any setting to stop it.
     
  15. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,239
    Location:
    Among the gum trees
    Have you got HMP installed? If so, it will scan on system start by default.
     
  16. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    Thanks i do also have HMP. I had W10 installed yesterday, so i did a new install of my Apps. I did not look at the settings of HMP this time and don't ever remember it having a scheduled scan. Why would HMPA start scanning after boot instead of HMP. Under HMP Scan setting it shows why HMPA was scanning.
     
  17. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,239
    Location:
    Among the gum trees
    Alert doesn't actually scan. It gets HMP to do the scan. If you don't have HMP installed I believe HMP.A will download HMP for the scan.

    You can change HMP's schedule to daily, or pick a day and time.
     
  18. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
  19. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,239
    Location:
    Among the gum trees
  20. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    Look on the bright side. It might get better.
     
  21. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,243
  22. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I'm not confident. :doubt:

    Erik was the lead developer of these tools.
    And for Sophos I'm sure HMP and HmP.A are only of value as components of their business offerings, not as standalone consumer tools.

    The Lomans made their money, there is no real motivation to endure corporate culture.

    Hope I'm wrong though, HmP.A is a stalwart on my machines.
     
  23. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    I may be wrong, but I though that, at least when SurfRight was still small, Mark was the lead developer and Erik handled the business side of things.
     
  24. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    This ^^^
     
  25. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    I was thinking the same...
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.