Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ArtifactCollectorFlow
- Artifact data collection InternetExplorerBrowserHelperObjects completed successfully in flow ArtifactCollectorFlow with 13 responses
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsAlternateShell data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\System\\\\CurrentControlSet\\\\Control\\\\SafeBoot\\\\Option\\\\UseAlternateShell'\n pathtype : REGISTRY\n}" network_bytes_sent : 308 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsAlternateShell completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsAppCertDLLs completed successfully in flow ArtifactCollectorFlow with 0 responses
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsAppInitDLLs completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsAppInitDLLs data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\AppInit_DLLs'\n pathtype : REGISTRY\n}" network_bytes_sent : 376 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsAppInitDLLs data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\AppInit_DLLs'\n pathtype : REGISTRY\n}" network_bytes_sent : 347 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsAppInitDLLs data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\AppInit_DLLs'\n pathtype : REGISTRY\n}" network_bytes_sent : 359 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsAppInitDLLs completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsAppInitDLLs data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\AppInit_DLLs'\n pathtype : REGISTRY\n}" network_bytes_sent : 363 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsAppInitDLLs data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\AppInit_DLLs'\n pathtype : REGISTRY\n}" network_bytes_sent : 346 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsAppInitDLLs data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\AppInit_DLLs'\n pathtype : REGISTRY\n}" network_bytes_sent : 360 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsBootVerificationProgram data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\System\\\\CurrentControlSet\\\\Control\\\\BootVerificationProgram\\\\ImagePath'\n pathtype : REGISTRY\n}" network_bytes_sent : 307 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsCommandProcessorAutoRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Command Processor\\\\AutoRun'\n pathtype : REGISTRY\n}" network_bytes_sent : 337 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsCommandProcessorAutoRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.03125 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Command Processor\\\\AutoRun'\n pathtype : REGISTRY\n}" network_bytes_sent : 297 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsCommandProcessorAutoRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Microsoft\\\\Command Processor\\\\AutoRun'\n pathtype : REGISTRY\n}" network_bytes_sent : 323 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsCommandProcessorAutoRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Microsoft\\\\Command Processor\\\\AutoRun'\n pathtype : REGISTRY\n}" network_bytes_sent : 340 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsCommandProcessorAutoRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\Software\\\\Microsoft\\\\Command Processor\\\\AutoRun'\n pathtype : REGISTRY\n}" network_bytes_sent : 284 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsCommandProcessorAutoRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Command Processor\\\\AutoRun'\n pathtype : REGISTRY\n}" network_bytes_sent : 336 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsCommandProcessorAutoRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Command Processor\\\\AutoRun'\n pathtype : REGISTRY\n}" network_bytes_sent : 353 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact WindowsCommandProcessorAutoRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Microsoft\\\\Command Processor\\\\AutoRun'\n pathtype : REGISTRY\n}" network_bytes_sent : 324 status : IOERROR }.
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsCredentialProviderFilters completed successfully in flow ArtifactCollectorFlow with 3 responses
- 2018-02-23 18:45:44 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsCredentialProviders completed successfully in flow ArtifactCollectorFlow with 35 responses
- 2018-02-23 18:45:57 UTC
- FileFinder
- Found and processed 1 files.
- 2018-02-23 18:46:02 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsDebugger completed successfully in flow ArtifactCollectorFlow with 0 responses
- 2018-02-23 18:46:02 UTC
- ArtifactCollectorFlow
- Artifact WindowsEnvironmentUserLoginScripts data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Environment\\\\UserInitLogonScript'\n pathtype : REGISTRY\n}" network_bytes_sent : 309 status : IOERROR }.
- 2018-02-23 18:46:02 UTC
- ArtifactCollectorFlow
- Artifact WindowsEnvironmentUserLoginScripts data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Environment\\\\UserMprLogonScript'\n pathtype : REGISTRY\n}" network_bytes_sent : 324 status : IOERROR }.
- 2018-02-23 18:46:02 UTC
- ArtifactCollectorFlow
- Artifact WindowsEnvironmentUserLoginScripts data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Environment\\\\UserMprLogonScript'\n pathtype : REGISTRY\n}" network_bytes_sent : 307 status : IOERROR }.
- 2018-02-23 18:46:02 UTC
- ArtifactCollectorFlow
- Artifact WindowsEnvironmentUserLoginScripts data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Environment\\\\UserInitLogonServer'\n pathtype : REGISTRY\n}" network_bytes_sent : 309 status : IOERROR }.
- 2018-02-23 18:46:02 UTC
- ArtifactCollectorFlow
- Artifact WindowsEnvironmentUserLoginScripts data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Environment\\\\UserInitLogonScript'\n pathtype : REGISTRY\n}" network_bytes_sent : 308 status : IOERROR }.
- 2018-02-23 18:46:02 UTC
- ArtifactCollectorFlow
- Artifact WindowsEnvironmentUserLoginScripts data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Environment\\\\UserInitLogonScript'\n pathtype : REGISTRY\n}" network_bytes_sent : 325 status : IOERROR }.
- 2018-02-23 18:46:02 UTC
- ArtifactCollectorFlow
- Artifact WindowsEnvironmentUserLoginScripts data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Environment\\\\UserMprLogonScript'\n pathtype : REGISTRY\n}" network_bytes_sent : 308 status : IOERROR }.
- 2018-02-23 18:46:02 UTC
- ArtifactCollectorFlow
- Artifact WindowsEnvironmentUserLoginScripts data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Environment\\\\UserInitLogonServer'\n pathtype : REGISTRY\n}" network_bytes_sent : 308 status : IOERROR }.
- 2018-02-23 18:46:02 UTC
- ArtifactCollectorFlow
- Artifact WindowsEnvironmentUserLoginScripts data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Environment\\\\UserInitLogonServer'\n pathtype : REGISTRY\n}" network_bytes_sent : 325 status : IOERROR }.
- 2018-02-23 18:46:02 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsExplorerAutoplayHandlers completed successfully in flow ArtifactCollectorFlow with 21 responses
- 2018-02-23 18:46:02 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsFileTypeAutorunAssociations completed successfully in flow ArtifactCollectorFlow with 856 responses
- 2018-02-23 18:46:03 UTC
- ArtifactCollectorFlow
- Artifact WindowsLSAAuthenticationPackages data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\System\\\\CurrentControlSet\\\\Control\\\\Lsa\\\\OSConfig\\\\Authentication Packages'\n pathtype : REGISTRY\n}" network_bytes_sent : 311 status : IOERROR }.
- 2018-02-23 18:46:03 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsLSAAuthenticationPackages completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:46:03 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsLSANotificationPackages completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:46:03 UTC
- ArtifactCollectorFlow
- Artifact WindowsLSANotificationPackages data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\System\\\\CurrentControlSet\\\\Control\\\\Lsa\\\\OSConfig\\\\Notification Packages'\n pathtype : REGISTRY\n}" network_bytes_sent : 309 status : IOERROR }.
- 2018-02-23 18:46:03 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsLSASecurityPackages completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:46:03 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsLSASecurityPackages completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:46:03 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsMSDTCDLLs completed successfully in flow ArtifactCollectorFlow with 6 responses
- 2018-02-23 18:46:03 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsMultiMediaDrivers completed successfully in flow ArtifactCollectorFlow with 56 responses
- 2018-02-23 18:46:03 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsNetworkShellHelpers completed successfully in flow ArtifactCollectorFlow with 2 responses
- 2018-02-23 18:46:03 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsPLAPProviders completed successfully in flow ArtifactCollectorFlow with 2 responses
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsPrintMonitors completed successfully in flow ArtifactCollectorFlow with 8 responses
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsRunKeys completed successfully in flow ArtifactCollectorFlow with 25 responses
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsRunServices completed successfully in flow ArtifactCollectorFlow with 0 responses
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsScreenSaverExecutable data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Policies\\\\Microsoft\\\\Windows\\\\Control Panel\\\\Desktop\\\\scrnsave.exe'\n pathtype : REGISTRY\n}" network_bytes_sent : 369 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsScreenSaverExecutable data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Control Panel\\\\Desktop\\\\scrnsave.exe'\n pathtype : REGISTRY\n}" network_bytes_sent : 313 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsScreenSaverExecutable data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Control Panel\\\\Desktop\\\\scrnsave.exe'\n pathtype : REGISTRY\n}" network_bytes_sent : 312 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsScreenSaverExecutable data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Control Panel\\\\Desktop\\\\scrnsave.exe'\n pathtype : REGISTRY\n}" network_bytes_sent : 329 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsScreenSaverExecutable data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Policies\\\\Microsoft\\\\Windows\\\\Control Panel\\\\Desktop\\\\scrnsave.exe'\n pathtype : REGISTRY\n}" network_bytes_sent : 353 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsScreenSaverExecutable data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Policies\\\\Microsoft\\\\Windows\\\\Control Panel\\\\Desktop\\\\scrnsave.exe'\n pathtype : REGISTRY\n}" network_bytes_sent : 352 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsSecurityProviders completed successfully in flow ArtifactCollectorFlow with 4 responses
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsServiceControlManagerExtension data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\System\\\\CurrentControlSet\\\\Control\\\\ServiceControlManagerExtension'\n pathtype : REGISTRY\n}" network_bytes_sent : 303 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsSessionManagerBootExecute completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsSessionManagerExecute data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\System\\\\CurrentControlSet\\\\Control\\\\Session Manager\\\\Execute'\n pathtype : REGISTRY\n}" network_bytes_sent : 297 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsSessionManagerSetupExecute completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsSessionManagerSubSystems completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsSessionManagerWOWCommandLine data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\System\\\\CurrentControlSet\\\\Control\\\\Session Manager\\\\WOW\\\\wowcmdline'\n pathtype : REGISTRY\n}" network_bytes_sent : 305 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsSessionManagerWOWCommandLine data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\System\\\\CurrentControlSet\\\\Control\\\\Session Manager\\\\WOW\\\\cmdline'\n pathtype : REGISTRY\n}" network_bytes_sent : 302 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsSharedTaskScheduler completed successfully in flow ArtifactCollectorFlow with 0 responses
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsShellExecuteHooks completed successfully in flow ArtifactCollectorFlow with 0 responses
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsShellExtensions completed successfully in flow ArtifactCollectorFlow with 2 responses
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsShellIconOverlayIdentifiers completed successfully in flow ArtifactCollectorFlow with 15 responses
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsShellLoadAndRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\Run'\n pathtype : REGISTRY\n}" network_bytes_sent : 338 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsShellLoadAndRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\Load'\n pathtype : REGISTRY\n}" network_bytes_sent : 339 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsShellLoadAndRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\Run'\n pathtype : REGISTRY\n}" network_bytes_sent : 367 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsShellLoadAndRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\Load'\n pathtype : REGISTRY\n}" network_bytes_sent : 351 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsShellLoadAndRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\Load'\n pathtype : REGISTRY\n}" network_bytes_sent : 368 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsShellLoadAndRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\Run'\n pathtype : REGISTRY\n}" network_bytes_sent : 337 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsShellLoadAndRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\Run'\n pathtype : REGISTRY\n}" network_bytes_sent : 354 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsShellLoadAndRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\Load'\n pathtype : REGISTRY\n}" network_bytes_sent : 338 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsShellLoadAndRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\Load'\n pathtype : REGISTRY\n}" network_bytes_sent : 355 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsShellLoadAndRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\Run'\n pathtype : REGISTRY\n}" network_bytes_sent : 351 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsShellLoadAndRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\Load'\n pathtype : REGISTRY\n}" network_bytes_sent : 352 status : IOERROR }.
- 2018-02-23 18:46:33 UTC
- ArtifactCollectorFlow
- Artifact WindowsShellLoadAndRun data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Windows\\\\Run'\n pathtype : REGISTRY\n}" network_bytes_sent : 350 status : IOERROR }.
- 2018-02-23 18:47:37 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsShellOpenCommand completed successfully in flow ArtifactCollectorFlow with 548 responses
- 2018-02-23 18:47:37 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsShellServiceObjects completed successfully in flow ArtifactCollectorFlow with 2 responses
- 2018-02-23 18:47:37 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsStubPaths completed successfully in flow ArtifactCollectorFlow with 19 responses
- 2018-02-23 18:47:37 UTC
- ArtifactCollectorFlow
- Artifact WindowsSystemPolicyShell data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.03125 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Policies\\\\System\\\\Shell'\n pathtype : REGISTRY\n}" network_bytes_sent : 306 status : IOERROR }.
- 2018-02-23 18:47:37 UTC
- ArtifactCollectorFlow
- Artifact WindowsSystemPolicyShell data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\Software\\\\Wow6432Node\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Policies\\\\System\\\\Shell'\n pathtype : REGISTRY\n}" network_bytes_sent : 319 status : IOERROR }.
- 2018-02-23 18:47:37 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsTerminalServerRunKeys completed successfully in flow ArtifactCollectorFlow with 0 responses
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsTerminalServerStartupPrograms completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsToolPaths completed successfully in flow ArtifactCollectorFlow with 3 responses
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonGinaDLL data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\GinaDLL'\n pathtype : REGISTRY\n}" network_bytes_sent : 343 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonGinaDLL data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\GinaDLL'\n pathtype : REGISTRY\n}" network_bytes_sent : 342 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonGinaDLL data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\GinaDLL'\n pathtype : REGISTRY\n}" network_bytes_sent : 359 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonGinaDLL data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.046875 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\GinaDLL'\n pathtype : REGISTRY\n}" network_bytes_sent : 303 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsWinlogonNotify completed successfully in flow ArtifactCollectorFlow with 0 responses
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonShell data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\Shell'\n pathtype : REGISTRY\n}" network_bytes_sent : 357 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonShell data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\Shell'\n pathtype : REGISTRY\n}" network_bytes_sent : 340 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsWinlogonShell completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonShell data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\Shell'\n pathtype : REGISTRY\n}" network_bytes_sent : 341 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonSystem data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\System'\n pathtype : REGISTRY\n}" network_bytes_sent : 341 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonSystem data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\System'\n pathtype : REGISTRY\n}" network_bytes_sent : 342 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonSystem data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.046875 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\System'\n pathtype : REGISTRY\n}" network_bytes_sent : 302 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonSystem data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\System'\n pathtype : REGISTRY\n}" network_bytes_sent : 358 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- aff4:/C.9ecc1d4dea73c41d
- ArtifactCollectorFlow
- Artifact WindowsWinlogonTaskman data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.046875 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\Taskman'\n pathtype : REGISTRY\n}" network_bytes_sent : 303 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonTaskman data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\Taskman'\n pathtype : REGISTRY\n}" network_bytes_sent : 342 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonTaskman data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\Taskman'\n pathtype : REGISTRY\n}" network_bytes_sent : 359 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonTaskman data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\Taskman'\n pathtype : REGISTRY\n}" network_bytes_sent : 343 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonUiHost data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0625 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_LOCAL_MACHINE\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\UiHost'\n pathtype : REGISTRY\n}" network_bytes_sent : 302 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonUiHost data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\UiHost'\n pathtype : REGISTRY\n}" network_bytes_sent : 342 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonUiHost data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\UiHost'\n pathtype : REGISTRY\n}" network_bytes_sent : 341 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonUiHost data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\UiHost'\n pathtype : REGISTRY\n}" network_bytes_sent : 358 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsWinlogonUserinit completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonUserinit data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\Userinit'\n pathtype : REGISTRY\n}" network_bytes_sent : 343 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonUserinit data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\Userinit'\n pathtype : REGISTRY\n}" network_bytes_sent : 344 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonUserinit data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\Userinit'\n pathtype : REGISTRY\n}" network_bytes_sent : 360 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsWinlogonVMApplet completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonVMApplet data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-80-1044544286-2763731348-267423293-2293503259-2593316332\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\VMApplet'\n pathtype : REGISTRY\n}" network_bytes_sent : 360 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonVMApplet data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-3074471230-1509454340-965560753-1000\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\VMApplet'\n pathtype : REGISTRY\n}" network_bytes_sent : 343 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact WindowsWinlogonVMApplet data collection failed. Status: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'HKEY_USERS\\\\S-1-5-21-823518204-362288127-1606980848-518115\\\\Software\\\\Microsoft\\\\Windows NT\\\\CurrentVersion\\\\Winlogon\\\\VMApplet'\n pathtype : REGISTRY\n}" network_bytes_sent : 344 status : IOERROR }.
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact data collection WinSock2LayeredServiceProviders completed successfully in flow ArtifactCollectorFlow with 13 responses
- 2018-02-23 18:47:38 UTC
- ArtifactCollectorFlow
- Artifact data collection WinSock2NamespaceProviders completed successfully in flow ArtifactCollectorFlow with 7 responses
- 2018-02-23 18:47:40 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsPersistenceRegistryKeys completed successfully in flow ArtifactCollectorFlow with 1654 responses
- 2018-02-23 18:47:41 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsPowerShellDefaultProfiles completed successfully in flow ArtifactCollectorFlow with 1 responses
- 2018-02-23 18:47:42 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsServices completed successfully in flow ArtifactCollectorFlow with 8188 responses
- 2018-02-23 18:47:45 UTC
- ArtifactCollectorFlow
- Artifact data collection WindowsPersistenceMechanisms completed successfully in flow ArtifactCollectorFlow with 2329 responses
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'cmd.exe'\n pathtype : OS\n}" network_bytes_sent : 195 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'oci.dll'\n pathtype : OS\n}" network_bytes_sent : 195 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'SQLLib80.dll'\n pathtype : OS\n}" network_bytes_sent : 200 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'xa80.dll'\n pathtype : OS\n}" network_bytes_sent : 196 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'midimap.dll'\n pathtype : OS\n}" network_bytes_sent : 199 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'iyuv_32.dll'\n pathtype : OS\n}" network_bytes_sent : 199 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'msrle32.dll'\n pathtype : OS\n}" network_bytes_sent : 199 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'msvidc32.dll'\n pathtype : OS\n}" network_bytes_sent : 200 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'msyuv.dll'\n pathtype : OS\n}" network_bytes_sent : 197 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'tsbyuv.dll'\n pathtype : OS\n}" network_bytes_sent : 198 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'VfWWDM32.dll'\n pathtype : OS\n}" network_bytes_sent : 200 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'AdobePDF.dll'\n pathtype : OS\n}" network_bytes_sent : 200 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'localspl.dll'\n pathtype : OS\n}" network_bytes_sent : 200 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'FXSMON.DLL'\n pathtype : OS\n}" network_bytes_sent : 198 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'PJLMON.DLL'\n pathtype : OS\n}" network_bytes_sent : 198 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'ricA5Glm.dll'\n pathtype : OS\n}" network_bytes_sent : 200 status : IOERROR }
- 2018-02-23 18:47:52 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'rc4mon64.dll'\n pathtype : OS\n}" network_bytes_sent : 200 status : IOERROR }
- 2018-02-23 18:47:53 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'usbmon.dll'\n pathtype : OS\n}" network_bytes_sent : 198 status : IOERROR }
- 2018-02-23 18:47:53 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'WSDMon.dll'\n pathtype : OS\n}" network_bytes_sent : 198 status : IOERROR }
- 2018-02-23 18:47:54 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'credssp.dll'\n pathtype : OS\n}" network_bytes_sent : 199 status : IOERROR }
- 2018-02-23 18:47:55 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.03125 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\Windows\\\\System32\\\\dfshim.dll,ShOpenVerbApplication %1'\n pathtype : OS\n}" network_bytes_sent : 247 status : IOERROR }
- 2018-02-23 18:47:55 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\Windows\\\\System32\\\\dfshim.dll,ShOpenVerbShortcut %1|%2'\n pathtype : OS\n}" network_bytes_sent : 247 status : IOERROR }
- 2018-02-23 18:47:55 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\_SMSTaskSequence\\\\WDPackage\\\\Tools\\\\X64\\\\BGInfo64.exe'\n pathtype : OS\n}" network_bytes_sent : 246 status : IOERROR }
- 2018-02-23 18:47:56 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\Program Files (x86)\\\\Common Files\\\\Microsoft Shared\\\\VSTO\\\\vstoee.dll,InstallVstoSolution %1'\n pathtype : OS\n}" network_bytes_sent : 286 status : IOERROR }
- 2018-02-23 18:47:56 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'rundll32.exe'\n pathtype : OS\n}" network_bytes_sent : 200 status : IOERROR }
- 2018-02-23 18:47:56 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'PrintBrmUI.exe'\n pathtype : OS\n}" network_bytes_sent : 202 status : IOERROR }
- 2018-02-23 18:47:56 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'cryptext.dll,CryptExtOpenCAT %1'\n pathtype : OS\n}" network_bytes_sent : 219 status : IOERROR }
- 2018-02-23 18:47:56 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'cryptext.dll,CryptExtOpenCER %1'\n pathtype : OS\n}" network_bytes_sent : 219 status : IOERROR }
- 2018-02-23 18:47:56 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'cryptext.dll,CryptExtOpenSTR %1'\n pathtype : OS\n}" network_bytes_sent : 219 status : IOERROR }
- 2018-02-23 18:47:56 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'cryptext.dll,CryptExtOpenCRL %1'\n pathtype : OS\n}" network_bytes_sent : 220 status : IOERROR }
- 2018-02-23 18:47:56 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\WINDOWS\\\\system32\\\\themecpl.dll,OpenThemeAction %1'\n pathtype : OS\n}" network_bytes_sent : 244 status : IOERROR }
- 2018-02-23 18:47:57 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\WINDOWS\\\\system32\\\\perfmon /sys'\n pathtype : OS\n}" network_bytes_sent : 224 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\Windows\\\\System32\\\\ieframe.dll,OpenURL %l'\n pathtype : OS\n}" network_bytes_sent : 234 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'iexplore.exe'\n pathtype : OS\n}" network_bytes_sent : 201 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'c:\\\\Program Files\\\\Microsoft SQL Server\\\\120\\\\DTS\\\\Binn\\\\dtsinstall.exe'\n pathtype : OS\n}" network_bytes_sent : 262 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'c:\\\\Program Files\\\\Microsoft SQL Server\\\\120\\\\DTS\\\\Binn\\\\isdeploymentwizard.exe'\n pathtype : OS\n}" network_bytes_sent : 270 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'GfxUIEx.exe'\n pathtype : OS\n}" network_bytes_sent : 200 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\Program Files (x86)\\\\AS2\\\\bin\\\\kst30.exe'\n pathtype : OS\n}" network_bytes_sent : 233 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'%CommonProgramFiles%\\\\System\\\\OLE DB\\\\oledb32.dll,OpenDSLFile %1'\n pathtype : OS\n}" network_bytes_sent : 254 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'Rundll32.exe'\n pathtype : OS\n}" network_bytes_sent : 201 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.0 } error_message : u'File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\system32\\\\shell32.dll,Control_RunDLL C:\\\\WINDOWS\\\\system32\\\\desk.cpl desk,@Appearance /Action:OpenMSTheme /file:"%1"\'\n pathtype : OS\n}' network_bytes_sent : 320 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\PROGRA~2\\\\MICROS~1\\\\Office16\\\\OMSMAIN.DLL, OmsProtocolHandler %1'\n pathtype : OS\n}" network_bytes_sent : 259 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'cryptext.dll,CryptExtOpenP7R %1'\n pathtype : OS\n}" network_bytes_sent : 220 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'cryptext.dll,CryptExtOpenPKCS7 %1'\n pathtype : OS\n}" network_bytes_sent : 222 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'cryptext.dll,CryptExtOpenPFX %1'\n pathtype : OS\n}" network_bytes_sent : 220 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\Program Files\\\\Windows Photo Viewer\\\\PhotoViewer.dll, ImageView_Fullscreen %1'\n pathtype : OS\n}" network_bytes_sent : 272 status : IOERROR }
- 2018-02-23 18:47:58 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.03125 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\WINDOWS\\\\System32\\\\msrating.dll,ClickedOnPRF %1'\n pathtype : OS\n}" network_bytes_sent : 241 status : IOERROR }
- 2018-02-23 18:47:59 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\WINDOWS\\\\System32\\\\msrating.dll,ClickedOnRAT %1'\n pathtype : OS\n}" network_bytes_sent : 241 status : IOERROR }
- 2018-02-23 18:47:59 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'regedit.exe'\n pathtype : OS\n}" network_bytes_sent : 200 status : IOERROR }
- 2018-02-23 18:47:59 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.03125 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\Windows\\\\System32\\\\url.dll,TelnetProtocolHandler %l'\n pathtype : OS\n}" network_bytes_sent : 245 status : IOERROR }
- 2018-02-23 18:47:59 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.015625 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\WINDOWS\\\\system32\\\\dsquery.dll,OpenSavedDsQuery %1'\n pathtype : OS\n}" network_bytes_sent : 244 status : IOERROR }
- 2018-02-23 18:48:05 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\WINDOWS\\\\System32\\\\ieframe.dll,OpenURL %l'\n pathtype : OS\n}" network_bytes_sent : 234 status : IOERROR }
- 2018-02-23 18:48:09 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'msiexec.exe'\n pathtype : OS\n}" network_bytes_sent : 200 status : IOERROR }
- 2018-02-23 18:48:10 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'explorer.exe'\n pathtype : OS\n}" network_bytes_sent : 201 status : IOERROR }
- 2018-02-23 18:48:10 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'SystemPropertiesPerformance.exe'\n pathtype : OS\n}" network_bytes_sent : 220 status : IOERROR }
- 2018-02-23 18:48:12 UTC
- MultiGetFile
- Hashed 200 files, skipped 0 already stored.
- 2018-02-23 18:48:13 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'\\\\??\\\\C:\\\\ProgramData\\\\Microsoft\\\\Windows Defender\\\\Definition Updates\\\\{A2895139-C576-438B-8BC0-7E9AD8A7AF53}\\\\MpKslbb01cc7a.sys'\n pathtype : OS\n}" network_bytes_sent : 320 status : IOERROR }
- 2018-02-23 18:48:31 UTC
- MultiGetFile
- Hashed 400 files, skipped 0 already stored.
- 2018-02-23 18:48:34 UTC
- MultiGetFile
- Failed to stat file: message GrrStatus { cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u"File not found: message PathSpec {\n path : u'C:\\\\WINDOWS\\\\C:\\\\WINDOWS\\\\system32\\\\svchost.exe'\n pathtype : OS\n}" network_bytes_sent : 236 status : IOERROR }
- 2018-02-23 18:48:44 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'cmd.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'cmd.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'cmd.exe\'\n pathtype : OS\n}' network_bytes_sent : 626 status : GENERIC_ERROR }
- 2018-02-23 18:48:44 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'oci.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'oci.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'oci.dll\'\n pathtype : OS\n}' network_bytes_sent : 626 status : GENERIC_ERROR }
- 2018-02-23 18:48:44 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'SQLLib80.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'SQLLib80.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'SQLLib80.dll\'\n pathtype : OS\n}' network_bytes_sent : 641 status : GENERIC_ERROR }
- 2018-02-23 18:48:44 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'xa80.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'xa80.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'xa80.dll\'\n pathtype : OS\n}' network_bytes_sent : 629 status : GENERIC_ERROR }
- 2018-02-23 18:48:44 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'midimap.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'midimap.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'midimap.dll\'\n pathtype : OS\n}' network_bytes_sent : 638 status : GENERIC_ERROR }
- 2018-02-23 18:48:44 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'iyuv_32.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'iyuv_32.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'iyuv_32.dll\'\n pathtype : OS\n}' network_bytes_sent : 638 status : GENERIC_ERROR }
- 2018-02-23 18:48:44 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'msrle32.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'msrle32.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'msrle32.dll\'\n pathtype : OS\n}' network_bytes_sent : 638 status : GENERIC_ERROR }
- 2018-02-23 18:48:44 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'msvidc32.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'msvidc32.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'msvidc32.dll\'\n pathtype : OS\n}' network_bytes_sent : 641 status : GENERIC_ERROR }
- 2018-02-23 18:48:44 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'msyuv.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'msyuv.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'msyuv.dll\'\n pathtype : OS\n}' network_bytes_sent : 632 status : GENERIC_ERROR }
- 2018-02-23 18:48:44 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'tsbyuv.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'tsbyuv.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'tsbyuv.dll\'\n pathtype : OS\n}' network_bytes_sent : 635 status : GENERIC_ERROR }
- 2018-02-23 18:48:44 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'VfWWDM32.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'VfWWDM32.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'VfWWDM32.dll\'\n pathtype : OS\n}' network_bytes_sent : 641 status : GENERIC_ERROR }
- 2018-02-23 18:48:44 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'AdobePDF.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'AdobePDF.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'AdobePDF.dll\'\n pathtype : OS\n}' network_bytes_sent : 641 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'localspl.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'localspl.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'localspl.dll\'\n pathtype : OS\n}' network_bytes_sent : 641 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'FXSMON.DLL\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'FXSMON.DLL\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'FXSMON.DLL\'\n pathtype : OS\n}' network_bytes_sent : 635 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'PJLMON.DLL\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'PJLMON.DLL\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'PJLMON.DLL\'\n pathtype : OS\n}' network_bytes_sent : 635 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'ricA5Glm.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'ricA5Glm.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'ricA5Glm.dll\'\n pathtype : OS\n}' network_bytes_sent : 641 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'rc4mon64.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'rc4mon64.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'rc4mon64.dll\'\n pathtype : OS\n}' network_bytes_sent : 641 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'usbmon.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'usbmon.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'usbmon.dll\'\n pathtype : OS\n}' network_bytes_sent : 635 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'WSDMon.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'WSDMon.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'WSDMon.dll\'\n pathtype : OS\n}' network_bytes_sent : 635 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- aff4:/C.9ecc1d4dea73c41d
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'credssp.dll\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'credssp.dll\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'credssp.dll\'\n pathtype : OS\n}' network_bytes_sent : 638 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\Windows\\\\System32\\\\dfshim.dll,ShOpenVerbApplication %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.03125 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\dfshim.dll,ShOpenVerbApplication %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\Windows\\\\System32\\\\dfshim.dll,ShOpenVerbApplication %1\'\n pathtype : OS\n}' network_bytes_sent : 785 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\Windows\\\\System32\\\\dfshim.dll,ShOpenVerbShortcut %1|%2\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.03125 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\dfshim.dll,ShOpenVerbShortcut %1|%2\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\Windows\\\\System32\\\\dfshim.dll,ShOpenVerbShortcut %1|%2\'\n pathtype : OS\n}' network_bytes_sent : 785 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\_SMSTaskSequence\\\\WDPackage\\\\Tools\\\\X64\\\\BGInfo64.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\_SMSTaskSequence\\\\\\\\WDPackage\\\\\\\\Tools\\\\\\\\X64\\\\\\\\BGInfo64.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\_SMSTaskSequence\\\\WDPackage\\\\Tools\\\\X64\\\\BGInfo64.exe\'\n pathtype : OS\n}' network_bytes_sent : 786 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\Program Files (x86)\\\\Common Files\\\\Microsoft Shared\\\\VSTO\\\\vstoee.dll,InstallVstoSolution %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\Program Files (x86)\\\\\\\\Common Files\\\\\\\\Microsoft Shared\\\\\\\\VSTO\\\\\\\\vstoee.dll,InstallVstoSolution %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\Program Files (x86)\\\\Common Files\\\\Microsoft Shared\\\\VSTO\\\\vstoee.dll,InstallVstoSolution %1\'\n pathtype : OS\n}' network_bytes_sent : 903 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'rundll32.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'rundll32.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'rundll32.exe\'\n pathtype : OS\n}' network_bytes_sent : 641 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'PrintBrmUI.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'PrintBrmUI.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'PrintBrmUI.exe\'\n pathtype : OS\n}' network_bytes_sent : 647 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenCAT %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'cryptext.dll,CryptExtOpenCAT %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenCAT %1\'\n pathtype : OS\n}' network_bytes_sent : 698 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenCER %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'cryptext.dll,CryptExtOpenCER %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenCER %1\'\n pathtype : OS\n}' network_bytes_sent : 698 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenSTR %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'cryptext.dll,CryptExtOpenSTR %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenSTR %1\'\n pathtype : OS\n}' network_bytes_sent : 698 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenCRL %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'cryptext.dll,CryptExtOpenCRL %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenCRL %1\'\n pathtype : OS\n}' network_bytes_sent : 698 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\system32\\\\themecpl.dll,OpenThemeAction %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.015625 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\WINDOWS\\\\\\\\system32\\\\\\\\themecpl.dll,OpenThemeAction %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\system32\\\\themecpl.dll,OpenThemeAction %1\'\n pathtype : OS\n}' network_bytes_sent : 773 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\system32\\\\perfmon /sys\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.046875 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\WINDOWS\\\\\\\\system32\\\\\\\\perfmon /sys\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\system32\\\\perfmon /sys\'\n pathtype : OS\n}' network_bytes_sent : 716 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\Windows\\\\System32\\\\ieframe.dll,OpenURL %l\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.03125 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\ieframe.dll,OpenURL %l\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\Windows\\\\System32\\\\ieframe.dll,OpenURL %l\'\n pathtype : OS\n}' network_bytes_sent : 746 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'iexplore.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'iexplore.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'iexplore.exe\'\n pathtype : OS\n}' network_bytes_sent : 641 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'c:\\\\Program Files\\\\Microsoft SQL Server\\\\120\\\\DTS\\\\Binn\\\\dtsinstall.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'c:\\\\\\\\Program Files\\\\\\\\Microsoft SQL Server\\\\\\\\120\\\\\\\\DTS\\\\\\\\Binn\\\\\\\\dtsinstall.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'c:\\\\Program Files\\\\Microsoft SQL Server\\\\120\\\\DTS\\\\Binn\\\\dtsinstall.exe\'\n pathtype : OS\n}' network_bytes_sent : 830 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'c:\\\\Program Files\\\\Microsoft SQL Server\\\\120\\\\DTS\\\\Binn\\\\isdeploymentwizard.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'c:\\\\\\\\Program Files\\\\\\\\Microsoft SQL Server\\\\\\\\120\\\\\\\\DTS\\\\\\\\Binn\\\\\\\\isdeploymentwizard.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'c:\\\\Program Files\\\\Microsoft SQL Server\\\\120\\\\DTS\\\\Binn\\\\isdeploymentwizard.exe\'\n pathtype : OS\n}' network_bytes_sent : 854 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'GfxUIEx.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'GfxUIEx.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'GfxUIEx.exe\'\n pathtype : OS\n}' network_bytes_sent : 638 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\Program Files (x86)\\\\AS2\\\\bin\\\\kst30.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\Program Files (x86)\\\\\\\\AS2\\\\\\\\bin\\\\\\\\kst30.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\Program Files (x86)\\\\AS2\\\\bin\\\\kst30.exe\'\n pathtype : OS\n}' network_bytes_sent : 745 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'%CommonProgramFiles%\\\\System\\\\OLE DB\\\\oledb32.dll,OpenDSLFile %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'%CommonProgramFiles%\\\\\\\\System\\\\\\\\OLE DB\\\\\\\\oledb32.dll,OpenDSLFile %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'%CommonProgramFiles%\\\\System\\\\OLE DB\\\\oledb32.dll,OpenDSLFile %1\'\n pathtype : OS\n}' network_bytes_sent : 803 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'Rundll32.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'Rundll32.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'Rundll32.exe\'\n pathtype : OS\n}' network_bytes_sent : 641 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\system32\\\\shell32.dll,Control_RunDLL C:\\\\WINDOWS\\\\system32\\\\desk.cpl desk,@Appearance /Action:OpenMSTheme /file:"%1"\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.03125 } error_message : u'IOError(\'File not found: message PathSpec {\\n path : u\\\'C:\\\\\\\\WINDOWS\\\\\\\\system32\\\\\\\\shell32.dll,Control_RunDLL C:\\\\\\\\WINDOWS\\\\\\\\system32\\\\\\\\desk.cpl desk,@Appearance /Action:OpenMSTheme /file:"%1"\\\'\\n pathtype : OS\\n}\',): File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\system32\\\\shell32.dll,Control_RunDLL C:\\\\WINDOWS\\\\system32\\\\desk.cpl desk,@Appearance /Action:OpenMSTheme /file:"%1"\'\n pathtype : OS\n}' network_bytes_sent : 1006 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\PROGRA~2\\\\MICROS~1\\\\Office16\\\\OMSMAIN.DLL, OmsProtocolHandler %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\PROGRA~2\\\\\\\\MICROS~1\\\\\\\\Office16\\\\\\\\OMSMAIN.DLL, OmsProtocolHandler %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\PROGRA~2\\\\MICROS~1\\\\Office16\\\\OMSMAIN.DLL, OmsProtocolHandler %1\'\n pathtype : OS\n}' network_bytes_sent : 817 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenP7R %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'cryptext.dll,CryptExtOpenP7R %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenP7R %1\'\n pathtype : OS\n}' network_bytes_sent : 698 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenPKCS7 %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'cryptext.dll,CryptExtOpenPKCS7 %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenPKCS7 %1\'\n pathtype : OS\n}' network_bytes_sent : 704 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenPFX %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'cryptext.dll,CryptExtOpenPFX %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'cryptext.dll,CryptExtOpenPFX %1\'\n pathtype : OS\n}' network_bytes_sent : 698 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\Program Files\\\\Windows Photo Viewer\\\\PhotoViewer.dll, ImageView_Fullscreen %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.015625 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\Program Files\\\\\\\\Windows Photo Viewer\\\\\\\\PhotoViewer.dll, ImageView_Fullscreen %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\Program Files\\\\Windows Photo Viewer\\\\PhotoViewer.dll, ImageView_Fullscreen %1\'\n pathtype : OS\n}' network_bytes_sent : 854 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\System32\\\\msrating.dll,ClickedOnPRF %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.046875 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\WINDOWS\\\\\\\\System32\\\\\\\\msrating.dll,ClickedOnPRF %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\System32\\\\msrating.dll,ClickedOnPRF %1\'\n pathtype : OS\n}' network_bytes_sent : 764 status : GENERIC_ERROR }
- 2018-02-23 18:48:46 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\System32\\\\msrating.dll,ClickedOnRAT %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.03125 user_cpu_time : 0.015625 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\WINDOWS\\\\\\\\System32\\\\\\\\msrating.dll,ClickedOnRAT %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\System32\\\\msrating.dll,ClickedOnRAT %1\'\n pathtype : OS\n}' network_bytes_sent : 764 status : GENERIC_ERROR }
- 2018-02-23 18:48:47 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'regedit.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'regedit.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'regedit.exe\'\n pathtype : OS\n}' network_bytes_sent : 638 status : GENERIC_ERROR }
- 2018-02-23 18:48:47 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\Windows\\\\System32\\\\url.dll,TelnetProtocolHandler %l\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.046875 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\url.dll,TelnetProtocolHandler %l\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\Windows\\\\System32\\\\url.dll,TelnetProtocolHandler %l\'\n pathtype : OS\n}' network_bytes_sent : 776 status : GENERIC_ERROR }
- 2018-02-23 18:48:47 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\system32\\\\dsquery.dll,OpenSavedDsQuery %1\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.015625 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\WINDOWS\\\\\\\\system32\\\\\\\\dsquery.dll,OpenSavedDsQuery %1\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\system32\\\\dsquery.dll,OpenSavedDsQuery %1\'\n pathtype : OS\n}' network_bytes_sent : 773 status : GENERIC_ERROR }
- 2018-02-23 18:48:47 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\System32\\\\ieframe.dll,OpenURL %l\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.015625 user_cpu_time : 0.015625 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'C:\\\\\\\\WINDOWS\\\\\\\\System32\\\\\\\\ieframe.dll,OpenURL %l\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'C:\\\\WINDOWS\\\\System32\\\\ieframe.dll,OpenURL %l\'\n pathtype : OS\n}' network_bytes_sent : 746 status : GENERIC_ERROR }
- 2018-02-23 18:48:47 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'msiexec.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'msiexec.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'msiexec.exe\'\n pathtype : OS\n}' network_bytes_sent : 638 status : GENERIC_ERROR }
- 2018-02-23 18:48:47 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'explorer.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'explorer.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'explorer.exe\'\n pathtype : OS\n}' network_bytes_sent : 641 status : GENERIC_ERROR }
- 2018-02-23 18:48:47 UTC
- MultiGetFile
- Failed to hash file: message GrrStatus { backtrace : u'Traceback (most recent call last):\n File "site-packages\\grr\\client\\actions.py", line 144, in Execute\n File "site-packages\\grr\\client\\client_actions\\file_fingerprint.py", line 46, in Run\n File "site-packages\\grr\\client\\vfs.py", line 410, in VFSOpen\nIOError: File not found: message PathSpec {\n path : u\'SystemPropertiesPerformance.exe\'\n pathtype : OS\n}\n' cpu_time_used : message CpuSeconds { system_cpu_time : 0.0 user_cpu_time : 0.0 } error_message : u'IOError("File not found: message PathSpec {\\n path : u\'SystemPropertiesPerformance.exe\'\\n pathtype : OS\\n}",): File not found: message PathSpec {\n path : u\'SystemPropertiesPerformance.exe\'\n pathtype : OS\n}' network_bytes_sent : 698 status : GENERIC_ERROR }
- 2018-02-23 19:31:19 UTC
- GenericHunt
- Hunt stop. Terminating all the started flows.
- 2018-02-23 19:31:19 UTC
- GenericHunt
- 1 flows terminated.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement