| Time & API |
Arguments |
Status |
Return |
Repeated |
1619861122.212822
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x00000000
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
failed
|
3221225525 |
0
|
1619861122.212822
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x00000000
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Crypto
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Crypto
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
failed
|
3221225525 |
0
|
1619861122.212822
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x00000000
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Crypto\RSA
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Crypto\RSA
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
failed
|
3221225525 |
0
|
1619861122.212822
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x00000000
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3154413779-3303930873-3537499701-500
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3154413779-3303930873-3537499701-500
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
failed
|
3221225525 |
0
|
1619861122.259822
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x00000000
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
failed
|
3221225525 |
0
|
1619861122.259822
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x00000000
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Crypto
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Crypto
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
failed
|
3221225525 |
0
|
1619861122.259822
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x00000000
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Crypto\RSA
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Crypto\RSA
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
failed
|
3221225525 |
0
|
1619861122.259822
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x00000000
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3154413779-3303930873-3537499701-500
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3154413779-3303930873-3537499701-500
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
failed
|
3221225525 |
0
|