This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Mitigation SelfPreservation?

I'm getting the following log entry from Intercept X.  The event does not appear in Sophos Central in the Root Cause Analysis so I do not have further information on it.  I'm just wondering if this is something I should be concerned about.

11/9/17
1:23:59.000 PM
 
11/09/2017 01:23:59 PM LogName=Application SourceName=HitmanPro.Alert EventCode=911 EventType=2 Type=Error ComputerName=xxxxxxxx TaskCategory=Mitigation OpCode=Info RecordNumber=13872 Keywords=Classic Message=Mitigation SelfProtection Platform 10.0.15063/x64 v608 06_5e PID 16568 Application C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrobat.exe Description Adobe Acrobat DC 17.12 Stack Trace # Address Module Location -- -------- ------------------------ ---------------------------------------- 1 51FB4952 Scan.api 0fb7c0 MOVZX EAX, AX 8945fc MOV [EBP-0x4], EAX 6685c0 TEST AX, AX 0f8434010000 JZ 0x51fb4a95 57 PUSH EDI 8b7df4 MOV EDI, [EBP-0xc] 57 PUSH EDI ff75f0 PUSH DWORD [EBP-0x10] ff75ec PUSH DWORD [EBP-0x14] e81f090000 CALL 0x51fb5290 83c40c ADD ESP, 0xc 894608 MOV [ESI+0x8], EAX 85c0 TEST EAX, EAX 0f8412010000 JZ 0x51fb4a91 6685ff TEST DI, DI 7470 JZ 0x51fb49f4 2 51FB5BF5 Scan.api 3 775D8744 kernel32.dll BaseThreadInitThunk +0x24 4 7787582D ntdll.dll RtlGetAppContainerNamedObjectPath +0xfd 5 778757FD ntdll.dll RtlGetAppContainerNamedObjectPath +0xcd Process Trace 1 C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrobat.exe [16568] "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrobat.exe" -Embedding 2 C:\Windows\System32\svchost.exe [828] C:\WINDOWS\system32\svchost.exe -k DcomLaunch 3 C:\Windows\System32\services.exe [676] Thumbprint 59af996799dc23e4b0d70a5d857a42e1a094fb583b98829d1237cfee623ab6ff
  • host = xxxxxxxxxxxxxxx
  • linecount = 53
  • punct = //_::_\r=\r=.\r=\r=\r=\r=..\r=\r=\r=\r=\r=___\r\r\r\r_____../__\r\r
  • source = WinEventLog:Application
  • sourcetype = WinEventLog:Application


This thread was automatically locked due to age.