NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x00000140
filepath:
C:\Users\test22\Desktop\~SDF83A.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\Desktop\~SDF83A.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x00000144
filepath:
C:\Users\test22\Documents\~SDF85B.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\test22\Documents\~SDF85B.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x00000150
filepath:
C:\Users\Default\Desktop\~SDFAAD.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\Default\Desktop\~SDFAAD.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x00000150
filepath:
C:\Users\Default User\Desktop\~SDFAAE.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\Default User\Desktop\~SDFAAE.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x00000150
filepath:
C:\Users\Public\Desktop\~SDFAAF.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\Public\Desktop\~SDFAAF.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x00000154
filepath:
C:\Users\Default\Documents\~SDFAB0.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\Default\Documents\~SDFAB0.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x00000154
filepath:
C:\Users\Default User\Documents\~SDFAC1.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\Default User\Documents\~SDFAC1.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x00000154
filepath:
C:\Users\Public\Documents\~SDFAC2.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Users\Public\Documents\~SDFAC2.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x00000150
filepath:
C:\~SDFAC3.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\~SDFAC3.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\$Recycle.Bin\~SDFAD4.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\$Recycle.Bin\~SDFAD4.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\$Recycle.Bin\S-1-5-21-3832866432-4053218753-3017428901-1001\~SDFAD5.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\$Recycle.Bin\S-1-5-21-3832866432-4053218753-3017428901-1001\~SDFAD5.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\GPKI\~SDFAD6.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\GPKI\~SDFAD6.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\~SDFAD7.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\~SDFAD7.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\~SDFAE7.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\~SDFAE7.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-0015-0412-0000-0000000FF1CE}-C\~SDFAE8.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-0015-0412-0000-0000000FF1CE}-C\~SDFAE8.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-0016-0412-0000-0000000FF1CE}-C\~SDFAE9.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-0016-0412-0000-0000000FF1CE}-C\~SDFAE9.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-0018-0412-0000-0000000FF1CE}-C\~SDFAEA.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-0018-0412-0000-0000000FF1CE}-C\~SDFAEA.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-0019-0412-0000-0000000FF1CE}-C\~SDFAEB.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-0019-0412-0000-0000000FF1CE}-C\~SDFAEB.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-001A-0412-0000-0000000FF1CE}-C\~SDFAEC.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-001A-0412-0000-0000000FF1CE}-C\~SDFAEC.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-001B-0412-0000-0000000FF1CE}-C\~SDFAFD.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-001B-0412-0000-0000000FF1CE}-C\~SDFAFD.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-002A-0412-1000-0000000FF1CE}-C\~SDFAFE.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-002A-0412-1000-0000000FF1CE}-C\~SDFAFE.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-002C-0412-0000-0000000FF1CE}-C\~SDFAFF.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-002C-0412-0000-0000000FF1CE}-C\~SDFAFF.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-002C-0412-0000-0000000FF1CE}-C\Proof.en\~SDFB00.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-002C-0412-0000-0000000FF1CE}-C\Proof.en\~SDFB00.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-002C-0412-0000-0000000FF1CE}-C\Proof.ko\~SDFB01.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-002C-0412-0000-0000000FF1CE}-C\Proof.ko\~SDFB01.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-0030-0000-0000-0000000FF1CE}-C\~SDFB12.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-0030-0000-0000-0000000FF1CE}-C\~SDFB12.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-0044-0412-0000-0000000FF1CE}-C\~SDFB13.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-0044-0412-0000-0000000FF1CE}-C\~SDFB13.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-006E-0412-0000-0000000FF1CE}-C\~SDFB14.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-006E-0412-0000-0000000FF1CE}-C\~SDFB14.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-006E-0412-0000-0000000FF1CE}-C\1042\~SDFB15.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-006E-0412-0000-0000000FF1CE}-C\1042\~SDFB15.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-00A1-0412-0000-0000000FF1CE}-C\~SDFB16.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-00A1-0412-0000-0000000FF1CE}-C\~SDFB16.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-0114-0412-0000-0000000FF1CE}-C\~SDFB26.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-0114-0412-0000-0000000FF1CE}-C\~SDFB26.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-0114-0412-0000-0000000FF1CE}-C\Groove.en-us\~SDFB27.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-0114-0412-0000-0000000FF1CE}-C\Groove.en-us\~SDFB27.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-0114-0412-0000-0000000FF1CE}-C\Office.en-us\~SDFB28.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-0114-0412-0000-0000000FF1CE}-C\Office.en-us\~SDFB28.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\MSOCache\All Users\{90120000-0114-0412-0000-0000000FF1CE}-C\Office64.en-us\~SDFB29.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\MSOCache\All Users\{90120000-0114-0412-0000-0000000FF1CE}-C\Office64.en-us\~SDFB29.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\PerfLogs\~SDFB2A.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\PerfLogs\~SDFB2A.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\PerfLogs\Admin\~SDFB2B.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\PerfLogs\Admin\~SDFB2B.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\Python27\~SDFB3C.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\~SDFB3C.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x00000150
filepath:
C:\Python27\click\~SDFB5C.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\click\~SDFB5C.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x00000150
filepath:
C:\Python27\click\click\~SDFB5D.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\click\click\~SDFB5D.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x00000150
filepath:
C:\Python27\click\click\click_image\~SDFB5E.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\click\click\click_image\~SDFB5E.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\Python27\click\click_image\~SDFB5F.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\click\click_image\~SDFB5F.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\Python27\DLLs\~SDFB60.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\DLLs\~SDFB60.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\Python27\Doc\~SDFB61.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\Doc\~SDFB61.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\Python27\include\~SDFB72.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\include\~SDFB72.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\Python27\Lib\~SDFB73.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\Lib\~SDFB73.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\Python27\Lib\bsddb\~SDFB74.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\Lib\bsddb\~SDFB74.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\Python27\Lib\bsddb\test\~SDFB84.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\Lib\bsddb\test\~SDFB84.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\Python27\Lib\compiler\~SDFB85.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\Lib\compiler\~SDFB85.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\Python27\Lib\ctypes\~SDFB86.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\Lib\ctypes\~SDFB86.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\Python27\Lib\ctypes\macholib\~SDFB87.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\Lib\ctypes\macholib\~SDFB87.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0
NtCreateFile
June 19, 2023, 4:16 p.m.
create_disposition:
5
(FILE_OVERWRITE_IF)
file_handle:
0x0000014c
filepath:
C:\Python27\Lib\ctypes\test\~SDFB98.tmp
desired_access:
0x40100080
(FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes:
2
(FILE_ATTRIBUTE_HIDDEN)
filepath_r:
\??\C:\Python27\Lib\ctypes\test\~SDFB98.tmp
create_options:
96
(FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info:
3
(FILE_OVERWRITTEN)
share_access:
0
()
1
0
0