NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x000000000012f262
filepath:
C:\Users\test22\AppData\Roaming\Microsoft
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x000000000012f262
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x000000000012f262
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x000000000012f262
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x000000000012f262
filepath:
C:\Users\test22\AppData\Roaming\Microsoft
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x000000000012f262
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x000000000012f262
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x000000000012f262
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x000000003b00003b
filepath:
C:\Users\test22\AppData\Roaming\Microsoft
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x000000003b00003b
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x000000003b00003b
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x000000003b00003b
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000026000026
filepath:
C:\Users\test22\AppData\Roaming\Microsoft
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000026000026
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000026000026
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000026000026
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000020000020
filepath:
C:\Users\test22\AppData\Roaming\Microsoft
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000020000020
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000020000020
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000020000020
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000015000015
filepath:
C:\Users\test22\AppData\Roaming\Microsoft
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000015000015
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000015000015
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000015000015
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000020000020
filepath:
C:\Users\test22\AppData\Roaming\Microsoft
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000020000020
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000020000020
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000020000020
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000015000015
filepath:
C:\Users\test22\AppData\Roaming\Microsoft
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000015000015
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000015000015
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|
NtCreateFile
|
create_disposition:
2
(FILE_CREATE)
file_handle:
0x0000000015000015
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access:
0x00100001
(FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes:
4
(FILE_ATTRIBUTE_SYSTEM)
filepath_r:
\??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options:
16417
(FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info:
4294967295
()
share_access:
3
(FILE_SHARE_READ|FILE_SHARE_WRITE)
|
|
-1073741771 |
0
|