Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- "Time of Day","Process Name","PID","Operation","Path","Result","Detail"
- "14:57:55.3495633","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Open Requiring Oplock, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3498808","Explorer.EXE","2568","FileSystemControl","C:\Test.exe","SUCCESS","Control: FSCTL_REQUEST_FILTER_OPLOCK"
- "14:57:55.3507711","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3511547","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:55.3512979","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3520030","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3522797","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:55.3528992","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:55.3532249","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3544834","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3547511","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:55.3549028","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3555414","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3558163","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:55.3563620","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:55.3566573","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3578176","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3580861","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:55.3582215","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3588592","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3591463","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:55.3596739","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:55.3599814","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3611177","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3613804","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:55.3615144","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3621526","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3624256","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:55.3629311","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:55.3632182","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3651774","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3654550","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","BUFFER OVERFLOW","Information: Owner, DACL"
- "14:57:55.3655954","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Owner, DACL"
- "14:57:55.3657299","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3667552","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3671836","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:55.3673218","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3692030","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3694834","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","BUFFER OVERFLOW","Information: Owner, DACL"
- "14:57:55.3696867","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Owner, DACL"
- "14:57:55.3698307","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3710091","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3712745","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:55.3714072","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3730580","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3733261","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","BUFFER OVERFLOW","Information: Owner, DACL"
- "14:57:55.3734660","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Owner, DACL"
- "14:57:55.3736055","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3755466","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3758228","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","BUFFER OVERFLOW","Information: Owner, DACL"
- "14:57:55.3759637","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Owner, DACL"
- "14:57:55.3760982","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3771706","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3774287","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:55.3775664","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3791882","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3794703","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","BUFFER OVERFLOW","Information: Owner, DACL"
- "14:57:55.3796130","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Owner, DACL"
- "14:57:55.3797543","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3807814","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3810735","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:55.3812262","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3828516","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3831346","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","BUFFER OVERFLOW","Information: Owner, DACL"
- "14:57:55.3832782","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Owner, DACL"
- "14:57:55.3834222","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3861073","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3863777","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","BUFFER OVERFLOW","Information: Owner, DACL"
- "14:57:55.3865095","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Owner, DACL"
- "14:57:55.3866408","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3876449","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3879587","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:55.3880860","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3896747","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3899627","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","BUFFER OVERFLOW","Information: Owner, DACL"
- "14:57:55.3900959","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Owner, DACL"
- "14:57:55.3902281","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3912602","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3915148","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:55.3916447","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3932181","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:55.3934898","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","BUFFER OVERFLOW","Information: Owner, DACL"
- "14:57:55.3936238","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Owner, DACL"
- "14:57:55.3937588","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:55.3942139","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.3274703","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.3278485","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","BUFFER OVERFLOW","Information: Label"
- "14:57:56.3280174","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Label"
- "14:57:56.3281596","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.3291682","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.3294132","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.3295350","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.3305988","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.3308497","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.3309765","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.3479003","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.3481689","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.3520985","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.3525727","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Label"
- "14:57:56.3531338","Explorer.EXE","2568","QueryNameInformationFile","C:\Test.exe","SUCCESS","Name: \Test.exe"
- "14:57:56.3825762","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.3828212","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.3888369","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.3892259","vsmon.exe","1268","QueryInformationVolume","C:\Test.exe","SUCCESS","VolumeCreationTime: 11/09/2012 06:59:15, VolumeSerialNumber: C4A4-4F6C, SupportsObjects: True, VolumeLabel: "
- "14:57:56.3893192","vsmon.exe","1268","QueryAllInformationFile","C:\Test.exe","BUFFER OVERFLOW","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A, AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1600000000fc36, EaSize: 0, Access: Generic Read, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word"
- "14:57:56.3902716","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.3911905","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.3915786","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.3916955","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.3919138","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.3922860","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.3924002","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.3926216","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.4006372","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.4014709","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.4042177","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4055424","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4066619","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.4074522","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.4076745","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4090160","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.4092288","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4126635","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4130172","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4142613","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4159818","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4162150","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4173540","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4184224","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4191569","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4193779","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4204422","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4211854","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4214204","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.4215196","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4248682","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4251902","vsmon.exe","1268","QueryNetworkOpenInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, AllocationSize: 01/01/1601 01:00:00, EndOfFile: 01/01/1601 01:00:00, FileAttributes: A"
- "14:57:56.4252926","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4263673","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4300818","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4303422","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4315134","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4424510","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4426760","vsmon.exe","1268","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.4427698","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4702842","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4705243","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.4706262","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4714744","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4717031","vsmon.exe","1268","ReadFile","C:\Test.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal"
- "14:57:56.4719192","vsmon.exe","1268","ReadFile","C:\Test.exe","SUCCESS","Offset: 128, Length: 4, Priority: Normal"
- "14:57:56.4720229","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4735572","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4745083","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4747293","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4762057","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4764167","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4775621","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4796734","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4868833","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4871179","vsmon.exe","1268","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.4872112","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4876867","vsmon.exe","1268","QueryDirectory","C:\Test.exe","SUCCESS","Filter: Test.exe, 1: Test.exe"
- "14:57:56.4884204","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4886509","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4891826","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4895571","vsmon.exe","1268","ReadFile","C:\Test.exe","SUCCESS","Offset: 0, Length: 5,120, Priority: Normal"
- "14:57:56.4897786","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4903180","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4905453","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.4906327","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.4907949","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.4909497","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.4911146","vsmon.exe","1268","ReadFile","C:\Test.exe","SUCCESS","Offset: 0, Length: 5,120, Priority: Normal"
- "14:57:56.4913184","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4918609","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4987588","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.4988924","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.4995745","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.4997850","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.4998919","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.5000622","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.5015490","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5017519","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5020245","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5033492","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5151754","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5159865","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5161980","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5173275","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5213319","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5225999","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5229278","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5246782","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5247131","Explorer.EXE","2568","Process Create","C:\Test.exe","SUCCESS","PID: 11888, Command line: ""C:\Test.exe"" "
- "14:57:56.5255450","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5264137","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5266360","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5278144","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5286853","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5296409","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: None, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5298664","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5310987","Explorer.EXE","2568","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
- "14:57:56.5312491","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.5323423","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5383861","csrss.exe","532","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
- "14:57:56.5385133","csrss.exe","532","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.5392316","csrss.exe","532","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.5397665","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5473278","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5476421","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.5480017","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.5495437","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.5497566","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5536745","Explorer.EXE","2568","QueryDirectory","C:\Test.exe","SUCCESS","Filter: Test.exe, 1: Test.exe"
- "14:57:56.5548130","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5550725","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.5551867","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5557401","Explorer.EXE","2568","QueryDirectory","C:\Test.exe","SUCCESS","Filter: Test.exe, 1: Test.exe"
- "14:57:56.5597807","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5600515","Explorer.EXE","2568","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.5601756","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.5606335","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.5612236","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5614944","Explorer.EXE","2568","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.5616090","Explorer.EXE","2568","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.5617290","Explorer.EXE","2568","ReadFile","C:\Test.exe","SUCCESS","Offset: 4,068, Length: 1,024, Priority: Normal"
- "14:57:56.5619152","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5622675","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5636307","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5638897","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.5640152","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5646823","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5649703","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.5653960","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.5658444","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.5663720","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5675214","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5677927","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.5679199","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5685571","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.5688225","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.5693216","Explorer.EXE","2568","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.5695879","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5803493","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.5806618","svchost.exe","952","QuerySecurityFile","C:\Test.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
- "14:57:56.5807931","svchost.exe","952","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.5846689","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.5850113","svchost.exe","952","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.5854465","svchost.exe","952","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.5880316","svchost.exe","952","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.5887933","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5901732","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.5912271","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.5914789","svchost.exe","952","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.5916003","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5922538","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, Impersonating: Foo\Bar, OpenResult: Opened"
- "14:57:56.5925192","svchost.exe","952","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.5929567","svchost.exe","952","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.5932066","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5937447","svchost.exe","952","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.5939027","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.5941962","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6005456","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6008006","svchost.exe","952","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.6019274","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6052850","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6055210","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.6056215","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.6059897","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.6062261","vsmon.exe","1268","Load Image","C:\Test.exe","SUCCESS","Image Base: 0x2c70000, Image Size: 0x2000"
- "14:57:56.6063371","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6070160","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6072365","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6081142","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6083098","vsmon.exe","1268","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.6084000","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6088574","vsmon.exe","1268","QueryDirectory","C:\Test.exe","SUCCESS","Filter: Test.exe, 1: Test.exe"
- "14:57:56.6099570","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6101585","vsmon.exe","1268","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.6102504","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6108315","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6110516","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.6113795","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.6115810","vsmon.exe","1268","Load Image","C:\Test.exe","SUCCESS","Image Base: 0x2c70000, Image Size: 0x8000"
- "14:57:56.6116752","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6126793","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6129528","vsmon.exe","1268","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.6130452","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6135859","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6138051","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.6141321","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.6156882","svchost.exe","952","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.6158852","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6187678","vsmon.exe","1268","Load Image","C:\Test.exe","SUCCESS","Image Base: 0x2c70000, Image Size: 0x8000"
- "14:57:56.6188896","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6197556","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6199951","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.6200771","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.6202347","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.6203846","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.6205440","vsmon.exe","1268","ReadFile","C:\Test.exe","SUCCESS","Offset: 0, Length: 5,120, Priority: Normal"
- "14:57:56.6208705","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6214878","vsmon.exe","1268","QueryDirectory","C:\Test.exe","SUCCESS","Filter: Test.exe, 1: Test.exe"
- "14:57:56.6221898","vsmon.exe","1268","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6224099","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.6225086","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.6225865","vsmon.exe","1268","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.6227437","vsmon.exe","1268","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.6229706","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6245054","vsmon.exe","1268","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6254415","svchost.exe","952","QueryDirectory","C:\Test.exe","SUCCESS","Filter: Test.exe, 1: Test.exe"
- "14:57:56.6275605","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6278065","svchost.exe","952","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.6279224","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6284835","svchost.exe","952","QueryDirectory","C:\Test.exe","SUCCESS","Filter: Test.exe, 1: Test.exe"
- "14:57:56.6324123","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6326727","svchost.exe","952","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.6327954","svchost.exe","952","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.6332841","svchost.exe","952","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.6338425","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6341051","svchost.exe","952","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.6342193","svchost.exe","952","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.6343393","svchost.exe","952","ReadFile","C:\Test.exe","SUCCESS","Offset: 4,068, Length: 1,024, Priority: Normal"
- "14:57:56.6345159","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6347179","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6360512","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6363125","svchost.exe","952","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.6364434","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6371241","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6373872","svchost.exe","952","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.6378568","svchost.exe","952","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.6381086","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6412734","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6415474","svchost.exe","952","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.6416751","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6423485","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6426212","svchost.exe","952","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.6430881","svchost.exe","952","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.6433489","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6687684","svchost.exe","952","QueryDirectory","C:\Test.exe","SUCCESS","Filter: Test.exe, 1: Test.exe"
- "14:57:56.6699341","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6701682","svchost.exe","952","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.6702642","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6708109","svchost.exe","952","QueryDirectory","C:\Test.exe","SUCCESS","Filter: Test.exe, 1: Test.exe"
- "14:57:56.6747736","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6750141","svchost.exe","952","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.6751182","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6757260","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6759746","svchost.exe","952","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.6763659","svchost.exe","952","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.6765928","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6776630","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6779012","svchost.exe","952","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:56.6780135","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6786041","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6788486","svchost.exe","952","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.6792757","svchost.exe","952","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.6795058","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6814183","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6816597","svchost.exe","952","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.6817634","svchost.exe","952","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:56.6822856","svchost.exe","952","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:56.6828014","svchost.exe","952","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:56.6830473","svchost.exe","952","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.6831478","svchost.exe","952","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:56.6832497","svchost.exe","952","ReadFile","C:\Test.exe","SUCCESS","Offset: 4,068, Length: 1,024, Priority: Normal"
- "14:57:56.6834164","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.6835948","svchost.exe","952","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:56.7000983","Test.exe","11888","Load Image","C:\Test.exe","SUCCESS","Image Base: 0x190000, Image Size: 0x8000"
- "14:57:57.2326466","svchost.exe","3224","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.2329283","svchost.exe","3224","QueryInformationVolume","C:\Test.exe","SUCCESS","VolumeCreationTime: 11/09/2012 06:59:15, VolumeSerialNumber: C4A4-4F6C, SupportsObjects: True, VolumeLabel: "
- "14:57:57.2330515","svchost.exe","3224","QueryAllInformationFile","C:\Test.exe","BUFFER OVERFLOW","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A, AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1600000000fc36, EaSize: 0, Access: Read Attributes, Synchronize, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word"
- "14:57:57.2331837","svchost.exe","3224","QueryInformationVolume","C:\Test.exe","SUCCESS","VolumeCreationTime: 11/09/2012 06:59:15, VolumeSerialNumber: C4A4-4F6C, SupportsObjects: True, VolumeLabel: "
- "14:57:57.3495126","conhost.exe","8288","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.3497494","conhost.exe","8288","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:57.3498409","conhost.exe","8288","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.3554861","svchost.exe","3224","QueryAllInformationFile","C:\Test.exe","BUFFER OVERFLOW","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A, AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1600000000fc36, EaSize: 0, Access: Read Attributes, Synchronize, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word"
- "14:57:57.3809078","svchost.exe","3224","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.3834095","svchost.exe","3224","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.3836930","svchost.exe","3224","QueryInformationVolume","C:\Test.exe","SUCCESS","VolumeCreationTime: 11/09/2012 06:59:15, VolumeSerialNumber: C4A4-4F6C, SupportsObjects: True, VolumeLabel: "
- "14:57:57.3838130","svchost.exe","3224","QueryAllInformationFile","C:\Test.exe","BUFFER OVERFLOW","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A, AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1600000000fc36, EaSize: 0, Access: Read Attributes, Synchronize, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word"
- "14:57:57.3839439","svchost.exe","3224","QueryInformationVolume","C:\Test.exe","SUCCESS","VolumeCreationTime: 11/09/2012 06:59:15, VolumeSerialNumber: C4A4-4F6C, SupportsObjects: True, VolumeLabel: "
- "14:57:57.3840571","svchost.exe","3224","QueryAllInformationFile","C:\Test.exe","BUFFER OVERFLOW","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A, AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1600000000fc36, EaSize: 0, Access: Read Attributes, Synchronize, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word"
- "14:57:57.3841885","svchost.exe","3224","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.3886688","conhost.exe","8288","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.3889030","conhost.exe","8288","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:57.3890130","conhost.exe","8288","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.3899799","conhost.exe","8288","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.3902462","conhost.exe","8288","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:57.3903463","conhost.exe","8288","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.3909079","conhost.exe","8288","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.3911516","conhost.exe","8288","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:57.3915139","conhost.exe","8288","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:57.3917158","conhost.exe","8288","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.4025927","svchost.exe","3224","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.4034659","svchost.exe","3224","QueryInformationVolume","C:\Test.exe","SUCCESS","VolumeCreationTime: 11/09/2012 06:59:15, VolumeSerialNumber: C4A4-4F6C, SupportsObjects: True, VolumeLabel: "
- "14:57:57.4036054","svchost.exe","3224","QueryAllInformationFile","C:\Test.exe","BUFFER OVERFLOW","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A, AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1600000000fc36, EaSize: 0, Access: Read Attributes, Synchronize, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word"
- "14:57:57.4037643","svchost.exe","3224","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.6238804","Explorer.EXE","2568","QueryNameInformationFile","C:\Test.exe","SUCCESS","Name: \Test.exe"
- "14:57:57.6248374","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.6251132","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:57.6252214","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.6257508","Explorer.EXE","2568","QueryDirectory","C:\Test.exe","SUCCESS","Filter: Test.exe, 1: Test.exe"
- "14:57:57.6274437","Explorer.EXE","2568","QueryNameInformationFile","C:\Test.exe","SUCCESS","Name: \Test.exe"
- "14:57:57.6282752","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.6285089","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:57.6286112","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.6291379","Explorer.EXE","2568","QueryDirectory","C:\Test.exe","SUCCESS","Filter: Test.exe, 1: Test.exe"
- "14:57:57.6483578","Explorer.EXE","2568","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.6486436","Explorer.EXE","2568","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:57.6487632","Explorer.EXE","2568","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.8020328","Test.exe","11888","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.8022946","Test.exe","11888","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:57.8023983","Test.exe","11888","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:57.8024848","Test.exe","11888","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:57.8026464","Test.exe","11888","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:57.8028924","Test.exe","11888","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.8038348","Test.exe","11888","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.8040771","Test.exe","11888","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:57.8041790","Test.exe","11888","CreateFileMapping","C:\Test.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "14:57:57.8042628","Test.exe","11888","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:57.8045123","Test.exe","11888","CreateFileMapping","C:\Test.exe","SUCCESS","SyncType: SyncTypeOther"
- "14:57:57.8047447","Test.exe","11888","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.8190576","svchost.exe","3224","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.8193442","svchost.exe","3224","FileSystemControl","C:\Test.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
- "14:57:57.8194855","svchost.exe","3224","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.8863591","svchost.exe","3224","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.8867686","svchost.exe","3224","QueryNetworkOpenInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, AllocationSize: 01/01/1601 01:00:00, EndOfFile: 01/01/1601 01:00:00, FileAttributes: A"
- "14:57:57.8868994","svchost.exe","3224","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.8910247","svchost.exe","3224","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Open For Backup, Open No Recall, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.8918141","svchost.exe","3224","FileSystemControl","C:\Test.exe","SUCCESS","Control: FSCTL_REQUEST_FILTER_OPLOCK"
- "14:57:57.8925134","svchost.exe","3224","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Open No Recall, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.8928091","svchost.exe","3224","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:57.8929269","svchost.exe","3224","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:57.8930799","svchost.exe","3224","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:57.8932335","svchost.exe","3224","ReadFile","C:\Test.exe","SUCCESS","Offset: 0, Length: 4,096, Priority: Very Low"
- "14:57:57.9282010","svchost.exe","3224","ReadFile","C:\Test.exe","SUCCESS","Offset: 4,096, Length: 1,024"
- "14:57:57.9580274","svchost.exe","3224","QueryStreamInformationFile","C:\Test.exe","SUCCESS",""
- "14:57:57.9582081","svchost.exe","3224","QueryEAFile","C:\Test.exe","NO EAS ON FILE",""
- "14:57:57.9583861","svchost.exe","3224","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.9585990","svchost.exe","3224","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.9604078","svchost.exe","3224","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.9606840","svchost.exe","3224","QueryStreamInformationFile","C:\Test.exe","SUCCESS",""
- "14:57:57.9608312","svchost.exe","3224","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.9616446","svchost.exe","3224","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.9618905","svchost.exe","3224","FileSystemControl","C:\Test.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
- "14:57:57.9620250","svchost.exe","3224","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:57.9627025","svchost.exe","3224","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:57.9629607","svchost.exe","3224","QueryStandardInformationFile","C:\Test.exe","SUCCESS","AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False"
- "14:57:57.9631138","svchost.exe","3224","ReadFile","C:\Test.exe","SUCCESS","Offset: 0, Length: 5,120, Priority: Very Low"
- "14:57:57.9633017","svchost.exe","3224","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:58.0260844","Test.exe","11888","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:58.0263281","Test.exe","11888","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:58.0264304","Test.exe","11888","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:58.0269517","Test.exe","11888","QueryDirectory","C:\Test.exe","SUCCESS","Filter: Test.exe, 1: Test.exe"
- "14:57:58.0281450","Test.exe","11888","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:58.0283615","Test.exe","11888","QueryBasicInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A"
- "14:57:58.0284543","Test.exe","11888","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:58.0290848","Test.exe","11888","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
- "14:57:58.0293284","Test.exe","11888","QueryInformationVolume","C:\Test.exe","SUCCESS","VolumeCreationTime: 11/09/2012 06:59:15, VolumeSerialNumber: C4A4-4F6C, SupportsObjects: True, VolumeLabel: "
- "14:57:58.0294289","Test.exe","11888","QueryAllInformationFile","C:\Test.exe","BUFFER OVERFLOW","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, FileAttributes: A, AllocationSize: 8,192, EndOfFile: 5,120, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1600000000fc36, EaSize: 0, Access: Generic Read, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word"
- "14:57:58.0301916","Test.exe","11888","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:58.0305009","Test.exe","11888","QueryNetworkOpenInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, AllocationSize: 01/01/1601 01:00:00, EndOfFile: 01/01/1601 01:00:00, FileAttributes: A"
- "14:57:58.0306037","Test.exe","11888","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:58.0308877","Test.exe","11888","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:58.0410064","Test.exe","11888","CreateFile","C:\Test.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
- "14:57:58.0413194","Test.exe","11888","QueryNetworkOpenInformationFile","C:\Test.exe","SUCCESS","CreationTime: 27/09/2012 14:54:32, LastAccessTime: 27/09/2012 14:54:32, LastWriteTime: 20/09/2012 14:43:44, ChangeTime: 27/09/2012 14:54:33, AllocationSize: 01/01/1601 01:00:00, EndOfFile: 01/01/1601 01:00:00, FileAttributes: A"
- "14:57:58.0414222","Test.exe","11888","CloseFile","C:\Test.exe","SUCCESS",""
- "14:57:58.1219375","Test.exe","11888","QueryNameInformationFile","C:\Test.exe","SUCCESS","Name: \Test.exe"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement