NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001e0
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
2
(FILE_CREATED)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001a8
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001bc
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001d8
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001d8
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001d8
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001bc
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001d8
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001bc
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001d8
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001bc
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001d8
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001bc
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001d8
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001bc
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001d8
filepath:
C:\Users\test22\nodesinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\nodesinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
|
1
|
0 |
0
|
NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000001bc
filepath:
C:\Users\test22\cmdinfo.dat
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\cmdinfo.dat
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
2
(FILE_CREATED)
share_access:
0
()
|
1
|
0 |
0
|