NtCreateFile
|
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x000004a8
filepath:
C:\Users\test22\AppData\Local\Temp\~$w Profits Distributions.docx
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\AppData\Local\Temp\~$w Profits Distributions.docx
create_options:
4194400
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
2
(FILE_CREATED)
share_access:
0
()
|
1
|
0 |
0
|