Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- "Time of Day","Process Name","PID","Operation","Path","Result","Detail"
- "09:29:12,4797692","explorer.exe","9544","CreateFile","C:\test\.svn\entries","PATH NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "09:29:12,4799699","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:12,4800683","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:12,4801322","explorer.exe","9544","QueryNetworkOpenInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:04, LastWriteTime: 07/08/2011 09:29:04, ChangeTime: 07/08/2011 09:29:04, AllocationSize: 01/01/1601 02:00:00, EndOfFile: 01/01/1601 02:00:00, FileAttributes: D"
- "09:29:12,4801826","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:12,4802554","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:12,4810247","explorer.exe","9544","CreateFile","C:\test\.svn\entries","PATH NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "09:29:12,4812006","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:12,4812978","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:12,4813599","explorer.exe","9544","QueryNetworkOpenInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:04, LastWriteTime: 07/08/2011 09:29:04, ChangeTime: 07/08/2011 09:29:04, AllocationSize: 01/01/1601 02:00:00, EndOfFile: 01/01/1601 02:00:00, FileAttributes: D"
- "09:29:12,4814091","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:12,4814808","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:12,4816170","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:12,4817111","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:12,4817822","explorer.exe","9544","QueryNetworkOpenInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:04, LastWriteTime: 07/08/2011 09:29:04, ChangeTime: 07/08/2011 09:29:04, AllocationSize: 01/01/1601 02:00:00, EndOfFile: 01/01/1601 02:00:00, FileAttributes: D"
- "09:29:12,4818331","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:12,4819030","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:12,4820203","explorer.exe","9544","QueryOpen","C:\test\.svn","FAST IO DISALLOWED",""
- "09:29:12,4821091","explorer.exe","9544","CreateFile","C:\test\.svn","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "09:29:12,5842071","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:12,5843001","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:12,5843611","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:04, LastWriteTime: 07/08/2011 09:29:04, ChangeTime: 07/08/2011 09:29:04, FileAttributes: D"
- "09:29:12,5844073","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:12,5844760","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:12,5846152","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:12,5847064","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:12,5847656","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:04, LastWriteTime: 07/08/2011 09:29:04, ChangeTime: 07/08/2011 09:29:04, FileAttributes: D"
- "09:29:12,5848118","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:12,5848799","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:12,5849717","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:12,5850416","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:12,5850848","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:04, LastWriteTime: 07/08/2011 09:29:04, ChangeTime: 07/08/2011 09:29:04, FileAttributes: D"
- "09:29:12,5851186","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:12,5851683","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:13,8883139","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:13,8884222","explorer.exe","9544","QuerySecurityFile","C:\test","BUFFER OVERFLOW","Information: Owner, Group, DACL"
- "09:29:13,8884838","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:13,8885496","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:13,8886514","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:13,8887267","explorer.exe","9544","QuerySecurityFile","C:\test","SUCCESS","Information: Owner, Group, DACL"
- "09:29:13,8887699","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:13,8888220","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,6700645","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,6701320","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,6701901","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,6702345","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,6748771","explorer.exe","9544","QueryOpen","C:\test\Nuovo collegamento.lnk","FAST IO DISALLOWED",""
- "09:29:16,6749878","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "09:29:16,6753894","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read/Write, Write DAC, Disposition: Create, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: 0, OpenResult: Created"
- "09:29:16,6761398","explorer.exe","9544","QueryBasicInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: A"
- "09:29:16,6761990","explorer.exe","9544","QueryStandardInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","AllocationSize: 0, EndOfFile: 0, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "09:29:16,6762831","explorer.exe","9544","QueryAttributeInformationVolume","C:\test\Nuovo collegamento.lnk","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c00000, MaximumComponentNameLength: 255, FileSystemName: NTFS"
- "09:29:16,6763340","explorer.exe","9544","QueryBasicInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: A"
- "09:29:16,6764080","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,6764998","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,6828019","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,6829891","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","END OF FILE","Offset: 0, Length: 4.096, Priority: Normal"
- "09:29:16,6835209","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,6835979","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,7231422","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7233116","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","END OF FILE","Offset: 0, Length: 4.096, Priority: Normal"
- "09:29:16,7414391","explorer.exe","9544","CreateFile","C:\test\~uovo collegamento.tmp","SUCCESS","Desired Access: Generic Read/Write, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: HT, ShareMode: None, AllocationSize: 0, OpenResult: Created"
- "09:29:16,7418394","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","END OF FILE","Offset: 0, Length: 65.536, Priority: Normal"
- "09:29:16,7419123","explorer.exe","9544","SetEndOfFileInformationFile","C:\test\~uovo collegamento.tmp","SUCCESS","EndOfFile: 0"
- "09:29:16,7421113","explorer.exe","9544","SetAllocationInformationFile","C:\test\~uovo collegamento.tmp","SUCCESS","AllocationSize: 0"
- "09:29:16,7422250","explorer.exe","9544","WriteFile","C:\test\~uovo collegamento.tmp","SUCCESS","Offset: 0, Length: 202, Priority: Normal"
- "09:29:16,7423636","explorer.exe","9544","CloseFile","C:\test\~uovo collegamento.tmp","SUCCESS",""
- "09:29:16,7427485","explorer.exe","9544","QueryAttributeInformationVolume","C:\test\Nuovo collegamento.lnk","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c00000, MaximumComponentNameLength: 255, FileSystemName: NTFS"
- "09:29:16,7428107","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,7428854","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,7430044","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","PRIVILEGE NOT HELD","Desired Access: Generic Read, Delete, Access System Security, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "09:29:16,7431619","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Delete, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7432940","explorer.exe","9544","CreateFile","C:\test\~uovo collegamento.tmp","SUCCESS","Desired Access: Generic Read/Write, Delete, Write DAC, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7436458","explorer.exe","9544","QueryBasicInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: A"
- "09:29:16,7436997","explorer.exe","9544","QueryBasicInformationFile","C:\test\~uovo collegamento.tmp","SUCCESS","CreationTime: 07/08/2011 09:29:16, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: HAT"
- "09:29:16,7437530","explorer.exe","9544","SetBasicInformationFile","C:\test\~uovo collegamento.tmp","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 01/01/1601 02:00:00, LastWriteTime: 01/01/1601 02:00:00, ChangeTime: 01/01/1601 02:00:00, FileAttributes: A"
- "09:29:16,7438839","explorer.exe","9544","QueryAttributeInformationVolume","C:\test\~uovo collegamento.tmp","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c00000, MaximumComponentNameLength: 255, FileSystemName: NTFS"
- "09:29:16,7715146","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:16,7715637","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Information: Owner, DACL"
- "09:29:16,7716336","explorer.exe","9544","QuerySecurityFile","C:\test\~uovo collegamento.tmp","BUFFER OVERFLOW","Information: Owner"
- "09:29:16,7716768","explorer.exe","9544","QuerySecurityFile","C:\test\~uovo collegamento.tmp","SUCCESS","Information: Owner"
- "09:29:16,7717260","explorer.exe","9544","QueryBasicInformationFile","C:\test\~uovo collegamento.tmp","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: A"
- "09:29:16,7788531","explorer.exe","9544","QueryNameInformationFile","C:\test\~uovo collegamento.tmp","SUCCESS","Name: \test\~uovo collegamento.tmp"
- "09:29:16,7789709","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7791202","explorer.exe","9544","QuerySecurityFile","C:\test","BUFFER OVERFLOW","Information: DACL, DACL Unprotected"
- "09:29:16,7791841","explorer.exe","9544","QuerySecurityFile","C:\test","SUCCESS","Information: DACL, DACL Unprotected"
- "09:29:16,7792434","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,7793115","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,7793837","explorer.exe","9544","QuerySecurityFile","C:\test\~uovo collegamento.tmp","BUFFER OVERFLOW","Information: Owner, Group, DACL, DACL Unprotected"
- "09:29:16,7794435","explorer.exe","9544","QuerySecurityFile","C:\test\~uovo collegamento.tmp","SUCCESS","Information: Owner, Group, DACL, DACL Unprotected"
- "09:29:16,7795324","explorer.exe","9544","SetSecurityFile","C:\test\~uovo collegamento.tmp","SUCCESS","Information: DACL, DACL Unprotected"
- "09:29:16,7797184","explorer.exe","9544","QueryStreamInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","0: ::$DATA"
- "09:29:16,7798540","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk~RF1202c678.TMP","SUCCESS","Desired Access: Generic Write, Read Attributes, Delete, Disposition: Create, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: HT, ShareMode: None, AllocationSize: 0, OpenResult: Created"
- "09:29:16,7801975","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk~RF1202c678.TMP","SUCCESS",""
- "09:29:16,7803207","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk~RF1202c678.TMP","SUCCESS",""
- "09:29:16,7803965","explorer.exe","9544","QueryBasicInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: A"
- "09:29:16,7804841","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Write Data/Add File, Synchronize, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7805996","explorer.exe","9544","SetRenameInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","ReplaceIfExists: True, FileName: C:\test\Nuovo collegamento.lnk~RF1202c678.TMP"
- "09:29:16,7808276","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,7809017","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,7809733","explorer.exe","9544","QueryBasicInformationFile","C:\test\~uovo collegamento.tmp","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: A"
- "09:29:16,7810876","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Write Data/Add File, Synchronize, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7812398","explorer.exe","9544","SetRenameInformationFile","C:\test\~uovo collegamento.tmp","SUCCESS","ReplaceIfExists: True, FileName: C:\test\Nuovo collegamento.lnk"
- "09:29:16,7841122","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,7841869","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,7842982","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk~RF1202c678.TMP","SUCCESS",""
- "09:29:16,7844344","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,7845404","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,7846749","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,7848052","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk~RF1202c678.TMP","SUCCESS","Desired Access: Read Attributes, Delete, Disposition: Open, Options: Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7849799","explorer.exe","9544","QueryAttributeTagFile","C:\test\Nuovo collegamento.lnk~RF1202c678.TMP","SUCCESS","Attributes: A, ReparseTag: 0x0"
- "09:29:16,7850776","explorer.exe","9544","SetDispositionInformationFile","C:\test\Nuovo collegamento.lnk~RF1202c678.TMP","SUCCESS","Delete: True"
- "09:29:16,7851759","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk~RF1202c678.TMP","SUCCESS",""
- "09:29:16,7853719","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk~RF1202c678.TMP","SUCCESS",""
- "09:29:16,7855218","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7856994","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,7857533","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,7930528","explorer.exe","9544","QueryDirectory","C:\test","SUCCESS","Filter: test, 1: test"
- "09:29:16,7931493","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7932494","explorer.exe","9544","FileSystemControl","C:\test","INVALID DEVICE REQUEST","Control: FSCTL_LMR_QUERY_DEBUG_INFO"
- "09:29:16,7932778","explorer.exe","9544","QueryDirectory","C:\test\Nuovo collegamento.lnk","SUCCESS","Filter: Nuovo collegamento.lnk, 1: Nuovo collegamento.lnk"
- "09:29:16,7933151","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,7933513","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,7935663","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7936598","explorer.exe","9544","FileSystemControl","C:\test","INVALID DEVICE REQUEST","Control: FSCTL_LMR_QUERY_DEBUG_INFO"
- "09:29:16,7936865","explorer.exe","9544","QueryDirectory","C:\test\Nuovo collegamento.lnk","SUCCESS","Filter: Nuovo collegamento.lnk, 1: Nuovo collegamento.lnk"
- "09:29:16,7937220","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,7937576","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,7938428","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7939595","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: D"
- "09:29:16,7939945","explorer.exe","9544","NotifyChangeDirectory","C:\test","","Filter: FILE_NOTIFY_CHANGE_DIR_NAME"
- "09:29:16,7941360","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7942621","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: D"
- "09:29:16,7942965","explorer.exe","9544","NotifyChangeDirectory","C:\test","","Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_ATTRIBUTES, FILE_NOTIFY_CHANGE_LAST_WRITE"
- "09:29:16,7959471","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,7960691","explorer.exe","9544","FileSystemControl","C:\test","INVALID DEVICE REQUEST","Control: FSCTL_LMR_QUERY_DEBUG_INFO"
- "09:29:16,7960969","explorer.exe","9544","QueryDirectory","C:\test","SUCCESS","0: ., 1: .., 2: Nuovo collegamento.lnk"
- "09:29:16,7962450","explorer.exe","9544","QueryDirectory","C:\test","NO MORE FILES",""
- "09:29:16,8114817","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8115694","explorer.exe","9544","QuerySecurityFile","C:\test","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:16,8116043","explorer.exe","9544","QuerySecurityFile","C:\test","SUCCESS","Information: Owner, DACL"
- "09:29:16,8116381","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8116766","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8117814","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:16,8117956","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8118406","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8118578","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8118993","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: D"
- "09:29:16,8119300","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8119893","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8123997","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8124773","explorer.exe","9544","QuerySecurityFile","C:\test","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:16,8125116","explorer.exe","9544","QuerySecurityFile","C:\test","SUCCESS","Information: Owner, DACL"
- "09:29:16,8125430","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8125815","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8126834","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:16,8127574","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8127989","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: D"
- "09:29:16,8128285","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8128788","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8135262","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8136434","explorer.exe","9544","QuerySecurityFile","C:\test","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:16,8137009","explorer.exe","9544","QuerySecurityFile","C:\test","SUCCESS","Information: Owner, DACL"
- "09:29:16,8137613","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8138205","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8143689","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8144773","explorer.exe","9544","QuerySecurityFile","C:\test","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:16,8145312","explorer.exe","9544","QuerySecurityFile","C:\test","SUCCESS","Information: Owner, DACL"
- "09:29:16,8145815","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8146419","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8147805","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:16,8148865","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8149475","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: D"
- "09:29:16,8150192","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8150956","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8156612","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8157678","explorer.exe","9544","QuerySecurityFile","C:\test","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:16,8158199","explorer.exe","9544","QuerySecurityFile","C:\test","SUCCESS","Information: Owner, DACL"
- "09:29:16,8158709","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8159313","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8160864","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:16,8161930","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8162558","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: D"
- "09:29:16,8163079","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8163826","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8168747","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8169890","explorer.exe","9544","QuerySecurityFile","C:\test","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:16,8170465","explorer.exe","9544","QuerySecurityFile","C:\test","SUCCESS","Information: Owner, DACL"
- "09:29:16,8170986","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8171631","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8253166","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:16,8253918","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8254339","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: D"
- "09:29:16,8254653","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8255156","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8256086","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:16,8256773","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8257152","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: D"
- "09:29:16,8257424","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:16,8257880","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:16,8736309","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Open Requiring Oplock, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8738121","explorer.exe","9544","FileSystemControl","C:\test\Nuovo collegamento.lnk","SUCCESS","Control: FSCTL_REQUEST_FILTER_OPLOCK"
- "09:29:16,8742421","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8743611","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Offset: 0, Length: 202, Priority: Normal"
- "09:29:16,8744044","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,8744482","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,8746774","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,8747277","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,8754207","Dropbox.exe","5248","QueryOpen","C:\test\Nuovo collegamento.lnk","FAST IO DISALLOWED",""
- "09:29:16,8754965","Dropbox.exe","5248","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:16,8755403","Dropbox.exe","5248","QueryBasicInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: HAT"
- "09:29:16,8755610","Dropbox.exe","5248","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,8756125","Dropbox.exe","5248","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:16,8757772","Dropbox.exe","5248","QueryDirectory","C:\test","SUCCESS","Filter: test, 1: test"
- "09:29:17,0018967","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0020903","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Offset: 0, Length: 202, Priority: Normal"
- "09:29:17,0021739","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0022200","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0062065","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0062900","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","BUFFER OVERFLOW","Information: Owner, Group, DACL"
- "09:29:17,0063231","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0063646","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0064611","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0065340","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Information: Owner, Group, DACL"
- "09:29:17,0065671","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0066056","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0124002","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0125228","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Offset: 0, Length: 202, Priority: Normal"
- "09:29:17,0125684","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0126122","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0182314","System","4","WriteFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Offset: 0, Length: 4.096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal"
- "09:29:17,0182539","System","4","SetEndOfFileInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","EndOfFile: 202"
- "09:29:17,0182676","System","4","CreateFileMapping","C:\test\Nuovo collegamento.lnk","SUCCESS","SyncType: SyncTypeOther"
- "09:29:17,0182806","System","4","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0342902","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:17,0343719","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0344181","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: D"
- "09:29:17,0344454","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:17,0344963","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:17,0345982","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:17,0346716","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0347101","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: D"
- "09:29:17,0347391","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:17,0347853","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:17,0941853","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Open Requiring Oplock, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0943357","explorer.exe","9544","FileSystemControl","C:\test\Nuovo collegamento.lnk","SUCCESS","Control: FSCTL_REQUEST_FILTER_OPLOCK"
- "09:29:17,0947834","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0948977","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Offset: 0, Length: 202, Priority: Normal"
- "09:29:17,0949511","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0952797","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0953579","explorer.exe","9544","QuerySecurityFile","C:\test","BUFFER OVERFLOW","Information: DACL"
- "09:29:17,0953923","explorer.exe","9544","QuerySecurityFile","C:\test","SUCCESS","Information: DACL"
- "09:29:17,0954059","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0954201","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:17,0954556","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:17,0954864","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:17,0955226","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Information: Owner, DACL"
- "09:29:17,0955557","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0955972","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0956979","explorer.exe","9544","QueryOpen","C:\test\Nuovo collegamento.lnk","FAST IO DISALLOWED",""
- "09:29:17,0958104","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0958714","explorer.exe","9544","QueryBasicInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: HAT"
- "09:29:17,0959075","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0959703","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0964844","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0965673","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:17,0966182","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Information: Owner, DACL"
- "09:29:17,0966692","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0967242","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0968237","explorer.exe","9544","QueryOpen","C:\test\Nuovo collegamento.lnk","FAST IO DISALLOWED",""
- "09:29:17,0969025","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0969481","explorer.exe","9544","QueryBasicInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: HAT"
- "09:29:17,0969836","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0971240","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0975818","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0976618","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:17,0976967","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Information: Owner, DACL"
- "09:29:17,0977299","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0977713","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0981705","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0982499","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:17,0982872","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Information: Owner, DACL"
- "09:29:17,0983334","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0983855","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0985235","explorer.exe","9544","QueryOpen","C:\test\Nuovo collegamento.lnk","FAST IO DISALLOWED",""
- "09:29:17,0985975","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0986425","explorer.exe","9544","QueryBasicInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: HAT"
- "09:29:17,0986751","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0987278","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0991199","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0992525","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:17,0992970","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Information: Owner, DACL"
- "09:29:17,0993313","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0993787","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0995149","explorer.exe","9544","QueryOpen","C:\test\Nuovo collegamento.lnk","FAST IO DISALLOWED",""
- "09:29:17,0996286","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,0996967","explorer.exe","9544","QueryBasicInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: HAT"
- "09:29:17,0997465","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,0998223","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1002363","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,1003180","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:17,1003535","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Information: Owner, DACL"
- "09:29:17,1003873","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1004364","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1010447","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,1011584","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:17,1012123","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Information: Owner, DACL"
- "09:29:17,1012603","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1013201","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1014628","explorer.exe","9544","QueryOpen","C:\test\Nuovo collegamento.lnk","FAST IO DISALLOWED",""
- "09:29:17,1015410","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,1015895","explorer.exe","9544","QueryBasicInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: HAT"
- "09:29:17,1016197","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1016719","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1020710","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,1021498","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:17,1022001","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Information: Owner, DACL"
- "09:29:17,1022671","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1023150","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1024187","explorer.exe","9544","QueryOpen","C:\test\Nuovo collegamento.lnk","FAST IO DISALLOWED",""
- "09:29:17,1024903","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,1025324","explorer.exe","9544","QueryBasicInformationFile","C:\test\Nuovo collegamento.lnk","SUCCESS","CreationTime: 07/08/2011 09:24:36, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: HAT"
- "09:29:17,1025614","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1026224","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1030068","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,1030879","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","BUFFER OVERFLOW","Information: Owner, DACL"
- "09:29:17,1031235","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Information: Owner, DACL"
- "09:29:17,1031548","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1031939","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1032638","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,1032994","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,2365744","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,2366810","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Offset: 0, Length: 202, Priority: Normal"
- "09:29:17,2367361","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,2367680","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,2391163","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,2391886","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","BUFFER OVERFLOW","Information: Owner, Group, DACL"
- "09:29:17,2392146","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,2392442","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,2393177","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,2393727","explorer.exe","9544","QuerySecurityFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Information: Owner, Group, DACL"
- "09:29:17,2393970","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,2394254","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,2441451","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,2442878","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Offset: 0, Length: 202, Priority: Normal"
- "09:29:17,2443340","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,2443796","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,2595387","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:17,2596157","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,2596584","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: D"
- "09:29:17,2596862","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:17,2597360","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:17,2598272","explorer.exe","9544","QueryOpen","C:\test","FAST IO DISALLOWED",""
- "09:29:17,2598970","explorer.exe","9544","CreateFile","C:\test","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,2599361","explorer.exe","9544","QueryBasicInformationFile","C:\test","SUCCESS","CreationTime: 07/08/2011 09:12:47, LastAccessTime: 07/08/2011 09:29:16, LastWriteTime: 07/08/2011 09:29:16, ChangeTime: 07/08/2011 09:29:16, FileAttributes: D"
- "09:29:17,2599634","explorer.exe","9544","CloseFile","C:\test","SUCCESS",""
- "09:29:17,2600131","explorer.exe","9544","IRP_MJ_CLOSE","C:\test","SUCCESS",""
- "09:29:17,3126105","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Open Requiring Oplock, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,3127580","explorer.exe","9544","FileSystemControl","C:\test\Nuovo collegamento.lnk","SUCCESS","Control: FSCTL_REQUEST_FILTER_OPLOCK"
- "09:29:17,3130672","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","CANNOT BREAK OPLOCK","Desired Access: Generic Read, Disposition: Open, Options: Open Requiring Oplock, Attributes: N, ShareMode: Read, AllocationSize: n/a"
- "09:29:17,3132099","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,3133242","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Offset: 0, Length: 202, Priority: Normal"
- "09:29:17,3133686","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3134113","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3134965","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3135368","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3136428","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,3137518","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Offset: 0, Length: 202, Priority: Normal"
- "09:29:17,3137944","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3138371","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3144702","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,3146058","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,3146094","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Offset: 0, Length: 202, Priority: Normal"
- "09:29:17,3146538","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3147006","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3147260","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Offset: 0, Length: 202, Priority: Normal"
- "09:29:17,3147740","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3148214","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3160562","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Open Requiring Oplock, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,3162001","explorer.exe","9544","FileSystemControl","C:\test\Nuovo collegamento.lnk","SUCCESS","Control: FSCTL_REQUEST_FILTER_OPLOCK"
- "09:29:17,3166372","explorer.exe","9544","CreateFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "09:29:17,3167551","explorer.exe","9544","ReadFile","C:\test\Nuovo collegamento.lnk","SUCCESS","Offset: 0, Length: 202, Priority: Normal"
- "09:29:17,3168025","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3168457","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3171122","explorer.exe","9544","CloseFile","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:17,3171572","explorer.exe","9544","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:19,0004244","System","4","CreateFileMapping","C:\test\Nuovo collegamento.lnk","SUCCESS","SyncType: SyncTypeOther"
- "09:29:19,0004368","System","4","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:19,0004498","System","4","IRP_MJ_CLOSE","C:\test\Nuovo collegamento.lnk","SUCCESS",""
- "09:29:35,0002135","System","4","WriteFile","C:\test","SUCCESS","Offset: 0, Length: 4.096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement