Files
2025-10-20 19:09:19 +02:00

844 KiB

1Time of DayProcess NamePIDOperationPathResultDetail
213:48:27.5486279MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
313:48:27.5486430MsMpEng.exe3220RegOpenKeyHKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultActionSUCCESSDesired Access: Read/Write
413:48:27.5487033MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
513:48:27.5487114MsMpEng.exe3220RegOpenKeyHKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultActionNAME NOT FOUNDDesired Access: Read
613:48:27.5487301MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultActionNO MORE ENTRIESIndex: 0, Length: 220
713:48:27.5487496MsMpEng.exe3220RegCloseKeyHKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultActionSUCCESS
813:48:27.5771694MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
913:48:27.5771900MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 144’256, Length: 4’096
1013:48:27.5772238MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 403’816, Length: 4’096
1113:48:27.5772477MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
1213:48:27.5775423MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
1313:48:27.5775761MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 399’696, Length: 4’096
1413:48:27.5776013MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
1513:48:27.5835398MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
1613:48:27.5835887MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
1713:48:27.5836207MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
1813:48:27.5836339MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
1913:48:27.5837392MsMpEng.exe3220CreateFileC:\Windows\System32\ntdll.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
2013:48:27.5837908MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntdll.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
2113:48:27.5838018MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntdll.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
2213:48:27.5838093MsMpEng.exe3220CloseFileC:\Windows\System32\ntdll.dllSUCCESS
2313:48:27.5846645MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
2413:48:27.5846816MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 395’576, Length: 4’096
2513:48:27.5847044MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
2613:48:27.5854297MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
2713:48:27.5854567MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
2813:48:27.5854879MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
2913:48:27.5854967MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 148’376, Length: 4’096
3013:48:27.5855268MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 679’856, Length: 4’096
3113:48:27.5855498MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
3213:48:27.5855746MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
3313:48:27.5860527MsMpEng.exe3220CreateFileC:\Windows\System32\ntdll.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
3413:48:27.5860818MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\ntdll.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
3513:48:27.5860965MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\ntdll.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:42:55, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 1’433’600, EndOfFile: 2’521’976
3613:48:27.5861087MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\ntdll.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
3713:48:27.5861142MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\ntdll.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:42:55, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 1’433’600, EndOfFile: 2’521’976
3813:48:27.5861221MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntdll.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
3913:48:27.5861303MsMpEng.exe3220QueryIdInformationC:\Windows\System32\ntdll.dllSUCCESS
4013:48:27.5861475MsMpEng.exe3220CloseFileC:\Windows\System32\ntdll.dllSUCCESS
4113:48:27.6098690MsMpEng.exe3220CreateFileC:\Windows\System32\kernel32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
4213:48:27.6099149MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
4313:48:27.6099290MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
4413:48:27.6099395MsMpEng.exe3220CloseFileC:\Windows\System32\kernel32.dllSUCCESS
4513:48:27.6103226MsMpEng.exe3220CreateFileC:\Windows\System32\kernel32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
4613:48:27.6103637MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\kernel32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
4713:48:27.6103722MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\kernel32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 466’944, EndOfFile: 836’136
4813:48:27.6103935MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\kernel32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
4913:48:27.6104073MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\kernel32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 466’944, EndOfFile: 836’136
5013:48:27.6104186MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel32.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
5113:48:27.6104270MsMpEng.exe3220QueryIdInformationC:\Windows\System32\kernel32.dllSUCCESS
5213:48:27.6104488MsMpEng.exe3220CloseFileC:\Windows\System32\kernel32.dllSUCCESS
5313:48:27.6105220MsMpEng.exe3220CreateFileC:\Windows\System32\KernelBase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
5413:48:27.6105433MsMpEng.exe3220FileSystemControlC:\Windows\System32\KernelBase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
5513:48:27.6105521MsMpEng.exe3220FileSystemControlC:\Windows\System32\KernelBase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
5613:48:27.6105714MsMpEng.exe3220CloseFileC:\Windows\System32\KernelBase.dllSUCCESS
5713:48:27.6107812MsMpEng.exe3220CreateFileC:\Windows\System32\KernelBase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
5813:48:27.6108005MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\KernelBase.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
5913:48:27.6108165MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\KernelBase.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 1’785’856, EndOfFile: 4’150’008
6013:48:27.6108514MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\KernelBase.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
6113:48:27.6108570MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\KernelBase.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 1’785’856, EndOfFile: 4’150’008
6213:48:27.6108649MsMpEng.exe3220FileSystemControlC:\Windows\System32\KernelBase.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
6313:48:27.6108817MsMpEng.exe3220QueryIdInformationC:\Windows\System32\KernelBase.dllSUCCESS
6413:48:27.6108948MsMpEng.exe3220CloseFileC:\Windows\System32\KernelBase.dllSUCCESS
6513:48:27.6114914MsMpEng.exe3220CreateFileC:\Windows\System32\advapi32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
6613:48:27.6115505MsMpEng.exe3220FileSystemControlC:\Windows\System32\advapi32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
6713:48:27.6115761MsMpEng.exe3220FileSystemControlC:\Windows\System32\advapi32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
6813:48:27.6115853MsMpEng.exe3220CloseFileC:\Windows\System32\advapi32.dllSUCCESS
6913:48:27.6117397MsMpEng.exe3220CreateFileC:\Windows\System32\msvcrt.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
7013:48:27.6117811MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
7113:48:27.6117915MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
7213:48:27.6117997MsMpEng.exe3220CloseFileC:\Windows\System32\msvcrt.dllSUCCESS
7313:48:27.6118829MsMpEng.exe3220CreateFileC:\Windows\System32\advapi32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
7413:48:27.6119405MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\advapi32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
7513:48:27.6119516MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\advapi32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:25, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:25, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 393’216, EndOfFile: 745’192
7613:48:27.6119609MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\advapi32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
7713:48:27.6119660MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\advapi32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:25, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:25, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 393’216, EndOfFile: 745’192
7813:48:27.6119745MsMpEng.exe3220FileSystemControlC:\Windows\System32\advapi32.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
7913:48:27.6119821MsMpEng.exe3220QueryIdInformationC:\Windows\System32\advapi32.dllSUCCESS
8013:48:27.6120045MsMpEng.exe3220CloseFileC:\Windows\System32\advapi32.dllSUCCESS
8113:48:27.6120412MsMpEng.exe3220CreateFileC:\Windows\System32\sechost.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
8213:48:27.6120716MsMpEng.exe3220FileSystemControlC:\Windows\System32\sechost.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
8313:48:27.6120804MsMpEng.exe3220FileSystemControlC:\Windows\System32\sechost.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
8413:48:27.6120876MsMpEng.exe3220CloseFileC:\Windows\System32\sechost.dllSUCCESS
8513:48:27.6122052MsMpEng.exe3220CreateFileC:\Windows\System32\rpcrt4.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
8613:48:27.6122414MsMpEng.exe3220FileSystemControlC:\Windows\System32\rpcrt4.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
8713:48:27.6122493MsMpEng.exe3220FileSystemControlC:\Windows\System32\rpcrt4.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
8813:48:27.6122567MsMpEng.exe3220CloseFileC:\Windows\System32\rpcrt4.dllSUCCESS
8913:48:27.6124017MsMpEng.exe3220CreateFileC:\Windows\System32\msvcrt.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
9013:48:27.6126810MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\msvcrt.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ
9113:48:27.6127107MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\msvcrt.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:58, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 405’504, EndOfFile: 699’768
9213:48:27.6127962MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\msvcrt.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
9313:48:27.6128189MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\msvcrt.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:58, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 405’504, EndOfFile: 699’768
9413:48:27.6128333MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
9513:48:27.6129082MsMpEng.exe3220QueryIdInformationC:\Windows\System32\msvcrt.dllSUCCESS
9613:48:27.6129750MsMpEng.exe3220CloseFileC:\Windows\System32\msvcrt.dllSUCCESS
9713:48:27.6136426MsMpEng.exe3220CreateFileC:\Windows\System32\setupapi.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
9813:48:27.6137211MsMpEng.exe3220FileSystemControlC:\Windows\System32\setupapi.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
9913:48:27.6137333MsMpEng.exe3220FileSystemControlC:\Windows\System32\setupapi.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
10013:48:27.6137415MsMpEng.exe3220CloseFileC:\Windows\System32\setupapi.dllSUCCESS
10113:48:27.6144921MsMpEng.exe3220CreateFileC:\Windows\System32\sechost.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
10213:48:27.6151458MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\sechost.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ
10313:48:27.6152471MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\sechost.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:09, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:09, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 385’024, EndOfFile: 691’520
10413:48:27.6154232MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\sechost.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ
10513:48:27.6154744MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\sechost.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:09, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:09, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 385’024, EndOfFile: 691’520
10613:48:27.6157337MsMpEng.exe3220FileSystemControlC:\Windows\System32\sechost.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
10713:48:27.6157806MsMpEng.exe3220QueryIdInformationC:\Windows\System32\sechost.dllSUCCESS
10813:48:27.6158874MsMpEng.exe3220CloseFileC:\Windows\System32\sechost.dllSUCCESS
10913:48:27.6159486MsMpEng.exe3220CreateFileC:\Windows\System32\bcrypt.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
11013:48:27.6159879MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcrypt.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
11113:48:27.6159980MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcrypt.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
11213:48:27.6160061MsMpEng.exe3220CloseFileC:\Windows\System32\bcrypt.dllSUCCESS
11313:48:27.6164003MsMpEng.exe3220CreateFileC:\Windows\System32\fltLib.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
11413:48:27.6164789MsMpEng.exe3220FileSystemControlC:\Windows\System32\fltLib.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
11513:48:27.6164907MsMpEng.exe3220FileSystemControlC:\Windows\System32\fltLib.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
11613:48:27.6165002MsMpEng.exe3220CloseFileC:\Windows\System32\fltLib.dllSUCCESS
11713:48:27.6171188MsMpEng.exe3220CreateFileC:\Windows\System32\newdev.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
11813:48:27.6171656MsMpEng.exe3220FileSystemControlC:\Windows\System32\newdev.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
11913:48:27.6171766MsMpEng.exe3220FileSystemControlC:\Windows\System32\newdev.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
12013:48:27.6171848MsMpEng.exe3220CloseFileC:\Windows\System32\newdev.dllSUCCESS
12113:48:27.6177155MsMpEng.exe3220CreateFileC:\Windows\System32\rpcrt4.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
12213:48:27.6177819MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\rpcrt4.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
12313:48:27.6177993MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\rpcrt4.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 708’608, EndOfFile: 1’162’552
12413:48:27.6178130MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\rpcrt4.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win(಼�㈀
12513:48:27.6178193MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\rpcrt4.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 708’608, EndOfFile: 1’162’552
12613:48:27.6178282MsMpEng.exe3220FileSystemControlC:\Windows\System32\rpcrt4.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
12713:48:27.6178359MsMpEng.exe3220QueryIdInformationC:\Windows\System32\rpcrt4.dllSUCCESS
12813:48:27.6178574MsMpEng.exe3220CloseFileC:\Windows\System32\rpcrt4.dllSUCCESS
12913:48:27.6178784MsMpEng.exe3220CreateFileC:\Windows\System32\ucrtbase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
13013:48:27.6179311MsMpEng.exe3220FileSystemControlC:\Windows\System32\ucrtbase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
13113:48:27.6179408MsMpEng.exe3220FileSystemControlC:\Windows\System32\ucrtbase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
13213:48:27.6179553MsMpEng.exe3220CloseFileC:\Windows\System32\ucrtbase.dllSUCCESS
13313:48:27.6180384MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
13413:48:27.6180593MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
13513:48:27.6186380MsMpEng.exe3220CreateFileC:\Windows\System32\msdelta.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
13613:48:27.6187227MsMpEng.exe3220FileSystemControlC:\Windows\System32\msdelta.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
13713:48:27.6187581MsMpEng.exe3220FileSystemControlC:\Windows\System32\msdelta.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
13813:48:27.6187677MsMpEng.exe3220CloseFileC:\Windows\System32\msdelta.dllSUCCESS
13913:48:27.6187807MsMpEng.exe3220CreateFileC:\Windows\System32\setupapi.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14013:48:27.6188917MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\setupapi.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
14113:48:27.6189036MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\setupapi.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 2’146’304, EndOfFile: 4’794’560
14213:48:27.6189156MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\setupapi.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
14313:48:27.6189222MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\setupapi.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 2’146’304, EndOfFile: 4’794’560
14413:48:27.6189423MsMpEng.exe3220FileSystemControlC:\Windows\System32\setupapi.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
14513:48:27.6189536MsMpEng.exe3220QueryIdInformationC:\Windows\System32\setupapi.dllSUCCESS
14613:48:27.6189691MsMpEng.exe3220CloseFileC:\Windows\System32\setupapi.dllSUCCESS
14713:48:27.6192022MsMpEng.exe3220CreateFileC:\Windows\System32\cryptsp.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14813:48:27.6192430MsMpEng.exe3220FileSystemControlC:\Windows\System32\cryptsp.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
14913:48:27.6192541MsMpEng.exe3220FileSystemControlC:\Windows\System32\cryptsp.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
15013:48:27.6192616MsMpEng.exe3220CloseFileC:\Windows\System32\cryptsp.dllSUCCESS
15113:48:27.6197451MsMpEng.exe3220CreateFileC:\Windows\System32\bcrypt.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
15213:48:27.6198096MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\bcrypt.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
15313:48:27.6198174MsMpEng.exe3220CreateFileC:\Windows\System32\cabinet.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
15413:48:27.6198208MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\bcrypt.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 90’112, EndOfFile: 166’736
15513:48:27.6198313MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\bcrypt.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
15613:48:27.6198377MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\bcrypt.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 90’112, EndOfFile: 166’736
15713:48:27.6198567MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcrypt.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
15813:48:27.6198592MsMpEng.exe3220FileSystemControlC:\Windows\System32\cabinet.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
15913:48:27.6198679MsMpEng.exe3220QueryIdInformationC:\Windows\System32\bcrypt.dllSUCCESS
16013:48:27.6198692MsMpEng.exe3220FileSystemControlC:\Windows\System32\cabinet.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
16113:48:27.6198769MsMpEng.exe3220CloseFileC:\Windows\System32\cabinet.dllSUCCESS
16213:48:27.6198830MsMpEng.exe3220CloseFileC:\Windows\System32\bcrypt.dllSUCCESS
16313:48:27.6200180MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
16413:48:27.6200461MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
16513:48:27.6202065MsMpEng.exe3220CreateFileC:\Windows\System32\fltLib.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
16613:48:27.6202608MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\fltLib.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
16713:48:27.6202686MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\fltLib.dllBUFFER OVERFLOWCreationTime: 06.09.2024 06:02:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:10, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 20’480, EndOfFile: 59’312
16813:48:27.6202774MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\fltLib.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
16913:48:27.6202827MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\fltLib.dllBUFFER OVERFLOWCreationTime: 06.09.2024 06:02:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:10, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 20’480, EndOfFile: 59’312
17013:48:27.6202905MsMpEng.exe3220FileSystemControlC:\Windows\System32\fltLib.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
17113:48:27.6203085MsMpEng.exe3220QueryIdInformationC:\Windows\System32\fltLib.dllSUCCESS
17213:48:27.6203220MsMpEng.exe3220CloseFileC:\Windows\System32\fltLib.dllSUCCESS
17313:48:27.6204470MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
17413:48:27.6204602MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
17513:48:27.6205803MsMpEng.exe3220CreateFileC:\Windows\System32\newdev.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
17613:48:27.6206222MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\newdev.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ
17713:48:27.6206442MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\newdev.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:29:14, LastWriteTime: 30.09.2025 13:53:59, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 188’416, EndOfFile: 348’160
17813:48:27.6206728MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\newdev.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
17913:48:27.6206802MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\newdev.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:29:14, LastWriteTime: 30.09.2025 13:53:59, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 188’416, EndOfFile: 348’160
18013:48:27.6206893MsMpEng.exe3220FileSystemControlC:\Windows\System32\newdev.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
18113:48:27.6206972MsMpEng.exe3220QueryIdInformationC:\Windows\System32\newdev.dllSUCCESS
18213:48:27.6207095MsMpEng.exe3220CloseFileC:\Windows\System32\newdev.dllSUCCESS
18313:48:27.6210475MsMpEng.exe3220CreateFileC:\Windows\System32\ucrtbase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
18413:48:27.6210988MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\ucrtbase.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ
18513:48:27.6211175MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\ucrtbase.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 802’816, EndOfFile: 1’373’280
18613:48:27.6211364MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\ucrtbase.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
18713:48:27.6211895MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\ucrtbase.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 802’816, EndOfFile: 1’373’280
18813:48:27.6212124MsMpEng.exe3220FileSystemControlC:\Windows\System32\ucrtbase.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
18913:48:27.6212206MsMpEng.exe3220QueryIdInformationC:\Windows\System32\ucrtbase.dllSUCCESS
19013:48:27.6212381MsMpEng.exe3220CloseFileC:\Windows\System32\ucrtbase.dllSUCCESS
19113:48:27.6213952MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
19213:48:27.6214089MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
19313:48:27.6215052MsMpEng.exe3220CreateFileC:\Windows\System32\msdelta.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
19413:48:27.6215325MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\msdelta.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
19513:48:27.6215394MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\msdelta.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:15:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:05, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 278’528, EndOfFile: 595’360
19613:48:27.6215468MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\msdelta.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ
19713:48:27.6215703MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\msdelta.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:15:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:05, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 278’528, EndOfFile: 595’360
19813:48:27.6215811MsMpEng.exe3220FileSystemControlC:\Windows\System32\msdelta.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
19913:48:27.6215885MsMpEng.exe3220QueryIdInformationC:\Windows\System32\msdelta.dllSUCCESS
20013:48:27.6216009MsMpEng.exe3220CloseFileC:\Windows\System32\msdelta.dllSUCCESS
20113:48:27.6218401MsMpEng.exe3220CreateFileC:\Windows\System32\cryptsp.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
20213:48:27.6235566MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\cryptsp.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
20313:48:27.6235764MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\cryptsp.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 57’344, EndOfFile: 121’304
20413:48:27.6235868MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\cryptsp.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
20513:48:27.6235995MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\cryptsp.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 57’344, EndOfFile: 121’304
20613:48:27.6236107MsMpEng.exe3220FileSystemControlC:\Windows\System32\cryptsp.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
20713:48:27.6236193MsMpEng.exe3220QueryIdInformationC:\Windows\System32\cryptsp.dllSUCCESS
20813:48:27.6236387MsMpEng.exe3220CloseFileC:\Windows\System32\cryptsp.dllSUCCESS
20913:48:27.6239253MsMpEng.exe3220CreateFileC:\Windows\System32\cabinet.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
21013:48:27.6239720MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\cabinet.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
21113:48:27.6239844MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\cabinet.dllBUFFER OVERFLOWCreationTime: 01.04.2024 09:22:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:11, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 98’304, EndOfFile: 175’024
21213:48:27.6239953MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\cabinet.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
21313:48:27.6240004MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\cabinet.dllBUFFER OVERFLOWCreationTime: 01.04.2024 09:22:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:11, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 98’304, EndOfFile: 175’024
21413:48:27.6240092MsMpEng.exe3220FileSystemControlC:\Windows\System32\cabinet.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
21513:48:27.6240250MsMpEng.exe3220QueryIdInformationC:\Windows\System32\cabinet.dllSUCCESS
21613:48:27.6240748MsMpEng.exe3220CloseFileC:\Windows\System32\cabinet.dllSUCCESS
21713:48:27.6309257MsMpEng.exe3220CreateFileC:\Windows\System32\combase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
21813:48:27.6309663MsMpEng.exe3220FileSystemControlC:\Windows\System32\combase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
21913:48:27.6309906MsMpEng.exe3220FileSystemControlC:\Windows\System32\combase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
22013:48:27.6310005MsMpEng.exe3220CloseFileC:\Windows\System32\combase.dllSUCCESS
22113:48:27.6313950MsMpEng.exe3220CreateFileC:\Windows\System32\SHCore.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
22213:48:27.6314425MsMpEng.exe3220FileSystemControlC:\Windows\System32\SHCore.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
22313:48:27.6314543MsMpEng.exe3220CreateFileC:\Windows\System32\combase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
22413:48:27.6314565MsMpEng.exe3220FileSystemControlC:\Windows\System32\SHCore.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
22513:48:27.6314787MsMpEng.exe3220CloseFileC:\Windows\System32\SHCore.dllSUCCESS
22613:48:27.6315075MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\combase.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
22713:48:27.6315186MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\combase.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 1’937’408, EndOfFile: 3’674’784
22813:48:27.6315301MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\combase.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
22913:48:27.6315361MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\combase.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 1’937’408, EndOfFile: 3’674’784
23013:48:27.6315561MsMpEng.exe3220FileSystemControlC:\Windows\System32\combase.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
23113:48:27.6315796MsMpEng.exe3220QueryIdInformationC:\Windows\System32\combase.dllSUCCESS
23213:48:27.6315957MsMpEng.exe3220CloseFileC:\Windows\System32\combase.dllSUCCESS
23313:48:27.6323592MsMpEng.exe3220CreateFileC:\Windows\System32\SHCore.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
23413:48:27.6324402MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\SHCore.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
23513:48:27.6324529MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\SHCore.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:14, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 512’000, EndOfFile: 988’984
23613:48:27.6324633MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\SHCore.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
23713:48:27.6324685MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\SHCore.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:14, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 512’000, EndOfFile: 988’984
23813:48:27.6324762MsMpEng.exe3220FileSystemControlC:\Windows\System32\SHCore.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
23913:48:27.6324834MsMpEng.exe3220QueryIdInformationC:\Windows\System32\SHCore.dllSUCCESS
24013:48:27.6325112MsMpEng.exe3220CloseFileC:\Windows\System32\SHCore.dllSUCCESS
24113:48:27.6333499MsMpEng.exe3220CreateFileC:\Windows\System32\cfgmgr32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24213:48:27.6334200MsMpEng.exe3220FileSystemControlC:\Windows\System32\cfgmgr32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
24313:48:27.6334334MsMpEng.exe3220FileSystemControlC:\Windows\System32\cfgmgr32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
24413:48:27.6334407MsMpEng.exe3220CloseFileC:\Windows\System32\cfgmgr32.dllSUCCESS
24513:48:27.6338266MsMpEng.exe3220CreateFileC:\Windows\System32\WofUtil.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24613:48:27.6338278MsMpEng.exe3220CreateFileC:\Windows\System32\cfgmgr32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24713:48:27.6338615MsMpEng.exe3220FileSystemControlC:\Windows\System32\WofUtil.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
24813:48:27.6338667MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\cfgmgr32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
24913:48:27.6338749MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\cfgmgr32.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:14:29, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:29, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 204’800, EndOfFile: 365’120
25013:48:27.6338828MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\cfgmgr32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
25113:48:27.6338840MsMpEng.exe3220FileSystemControlC:\Windows\System32\WofUtil.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
25213:48:27.6338909MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\cfgmgr32.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:14:29, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:29, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 204’800, EndOfFile: 365’120
25313:48:27.6338935MsMpEng.exe3220CloseFileC:\Windows\System32\WofUtil.dllSUCCESS
25413:48:27.6338988MsMpEng.exe3220FileSystemControlC:\Windows\System32\cfgmgr32.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
25513:48:27.6339166MsMpEng.exe3220QueryIdInformationC:\Windows\System32\cfgmgr32.dllSUCCESS
25613:48:27.6339300MsMpEng.exe3220CloseFileC:\Windows\System32\cfgmgr32.dllSUCCESS
25713:48:27.6340113MsMpEng.exe3220CreateFileC:\Windows\System32\devrtl.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25813:48:27.6340405MsMpEng.exe3220FileSystemControlC:\Windows\System32\devrtl.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
25913:48:27.6340633MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
26013:48:27.6340646MsMpEng.exe3220FileSystemControlC:\Windows\System32\devrtl.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
26113:48:27.6340742MsMpEng.exe3220CloseFileC:\Windows\System32\devrtl.dllSUCCESS
26213:48:27.6340789MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
26313:48:27.6341773MsMpEng.exe3220CreateFileC:\Windows\System32\WofUtil.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
26413:48:27.6342017MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\WofUtil.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
26513:48:27.6342197MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\WofUtil.dllBUFFER OVERFLOWCreationTime: 01.04.2024 09:22:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:10, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 24’576, EndOfFile: 61’440
26613:48:27.6342285MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\WofUtil.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
26713:48:27.6342337MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\WofUtil.dllBUFFER OVERFLOWCreationTime: 01.04.2024 09:22:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:10, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 24’576, EndOfFile: 61’440
26813:48:27.6342409MsMpEng.exe3220FileSystemControlC:\Windows\System32\WofUtil.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
26913:48:27.6342480MsMpEng.exe3220QueryIdInformationC:\Windows\System32\WofUtil.dllSUCCESS
27013:48:27.6342597MsMpEng.exe3220CloseFileC:\Windows\System32\WofUtil.dllSUCCESS
27113:48:27.6344055MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
27213:48:27.6344188MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
27313:48:27.6347807MsMpEng.exe3220CreateFileC:\Windows\System32\devrtl.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27413:48:27.6348444MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\devrtl.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ
27513:48:27.6348546MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\devrtl.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:14:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:30, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 45’056, EndOfFile: 90’112
27613:48:27.6348643MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\devrtl.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
27713:48:27.6348698MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\devrtl.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:14:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:30, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 45’056, EndOfFile: 90’112
27813:48:27.6348784MsMpEng.exe3220FileSystemControlC:\Windows\System32\devrtl.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
27913:48:27.6348974MsMpEng.exe3220QueryIdInformationC:\Windows\System32\devrtl.dllSUCCESS
28013:48:27.6349111MsMpEng.exe3220CloseFileC:\Windows\System32\devrtl.dllSUCCESS
28113:48:27.6405153MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28213:48:27.6406282MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
28313:48:27.6406763MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
28413:48:27.6407083MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dllSUCCESS
28513:48:27.6409561MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
28613:48:27.6409824MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
28713:48:27.6571981MsMpEng.exe3220CreateFileC:\Windows\System32\rsaenh.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28813:48:27.6572385MsMpEng.exe3220FileSystemControlC:\Windows\System32\rsaenh.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
28913:48:27.6572487MsMpEng.exe3220FileSystemControlC:\Windows\System32\rsaenh.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
29013:48:27.6572567MsMpEng.exe3220CloseFileC:\Windows\System32\rsaenh.dllSUCCESS
29113:48:27.6575479MsMpEng.exe3220CreateFileC:\Windows\System32\rsaenh.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29213:48:27.6575986MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\rsaenh.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
29313:48:27.6576073MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\rsaenh.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 135’168, EndOfFile: 253’488
29413:48:27.6576160MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\rsaenh.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
29513:48:27.6576210MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\rsaenh.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 135’168, EndOfFile: 253’488
29613:48:27.6576287MsMpEng.exe3220FileSystemControlC:\Windows\System32\rsaenh.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
29713:48:27.6576365MsMpEng.exe3220QueryIdInformationC:\Windows\System32\rsaenh.dllSUCCESS
29813:48:27.6576626MsMpEng.exe3220CloseFileC:\Windows\System32\rsaenh.dllSUCCESS
29913:48:27.6586879MsMpEng.exe3220CreateFileC:\Windows\System32\cryptbase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
30013:48:27.6587335MsMpEng.exe3220FileSystemControlC:\Windows\System32\cryptbase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
30113:48:27.6587519MsMpEng.exe3220FileSystemControlC:\Windows\System32\cryptbase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
30213:48:27.6587624MsMpEng.exe3220CloseFileC:\Windows\System32\cryptbase.dllSUCCESS
30313:48:27.6590178MsMpEng.exe3220CreateFileC:\Windows\System32\bcryptprimitives.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
30413:48:27.6590189MsMpEng.exe3220CreateFileC:\Windows\System32\cryptbase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
30513:48:27.6590412MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\cryptbase.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win
30613:48:27.6590570MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\cryptbase.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 20’480, EndOfFile: 59’320
30713:48:27.6590572MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcryptprimitives.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
30813:48:27.6590696MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\cryptbase.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
30913:48:27.6590731MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcryptprimitives.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
31013:48:27.6590759MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\cryptbase.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 20’480, EndOfFile: 59’320
31113:48:27.6590839MsMpEng.exe3220FileSystemControlC:\Windows\System32\cryptbase.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
31213:48:27.6590922MsMpEng.exe3220QueryIdInformationC:\Windows\System32\cryptbase.dllSUCCESS
31313:48:27.6591060MsMpEng.exe3220CloseFileC:\Windows\System32\cryptbase.dllSUCCESS
31413:48:27.6591454MsMpEng.exe3220CloseFileC:\Windows\System32\bcryptprimitives.dllSUCCESS
31513:48:27.6594151MsMpEng.exe3220CreateFileC:\Windows\System32\bcryptprimitives.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
31613:48:27.6594423MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\bcryptprimitives.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
31713:48:27.6594509MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\bcryptprimitives.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 368’640, EndOfFile: 637’800
31813:48:27.6594942MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\bcryptprimitives.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win怀
31913:48:27.6595061MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\bcryptprimitives.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 368’640, EndOfFile: 637’800
32013:48:27.6595293MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcryptprimitives.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
32113:48:27.6595418MsMpEng.exe3220QueryIdInformationC:\Windows\System32\bcryptprimitives.dllSUCCESS
32213:48:27.6595573MsMpEng.exe3220CloseFileC:\Windows\System32\bcryptprimitives.dllSUCCESS
32313:48:27.6786002MsMpEng.exe3220CreateFileC:\Windows\System32\spinf.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
32413:48:27.6786532MsMpEng.exe3220FileSystemControlC:\Windows\System32\spinf.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
32513:48:27.6786680MsMpEng.exe3220FileSystemControlC:\Windows\System32\spinf.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
32613:48:27.6786777MsMpEng.exe3220CloseFileC:\Windows\System32\spinf.dllSUCCESS
32713:48:27.6788949MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
32813:48:27.6789179MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
32913:48:27.6790385MsMpEng.exe3220CreateFileC:\Windows\System32\spinf.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
33013:48:27.6790818MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\spinf.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
33113:48:27.6790924MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\spinf.dllBUFFER OVERFLOWCreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 69’632, EndOfFile: 126’976
33213:48:27.6791032MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\spinf.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
33313:48:27.6791098MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\spinf.dllBUFFER OVERFLOWCreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 69’632, EndOfFile: 126’976
33413:48:27.6791193MsMpEng.exe3220FileSystemControlC:\Windows\System32\spinf.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
33513:48:27.6791455MsMpEng.exe3220QueryIdInformationC:\Windows\System32\spinf.dllSUCCESS
33613:48:27.6791616MsMpEng.exe3220CloseFileC:\Windows\System32\spinf.dllSUCCESS
33713:48:27.6805104MsMpEng.exe3220CreateFileC:\Windows\System32\wldp.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
33813:48:27.6805531MsMpEng.exe3220FileSystemControlC:\Windows\System32\wldp.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
33913:48:27.6805817MsMpEng.exe3220FileSystemControlC:\Windows\System32\wldp.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
34013:48:27.6805916MsMpEng.exe3220CloseFileC:\Windows\System32\wldp.dllSUCCESS
34113:48:27.6807569MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
34213:48:27.6807755MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
34313:48:27.6807781MsMpEng.exe3220CreateFileC:\Windows\System32\msvcp_win.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
34413:48:27.6808022MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp_win.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
34513:48:27.6808097MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp_win.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
34613:48:27.6808255MsMpEng.exe3220CloseFileC:\Windows\System32\msvcp_win.dllSUCCESS
34713:48:27.6809834MsMpEng.exe3220CreateFileC:\Windows\System32\wldp.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
34813:48:27.6810355MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\wldp.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
34913:48:27.6810497MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\wldp.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 233’472, EndOfFile: 422’920
35013:48:27.6810614MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\wldp.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
35113:48:27.6810677MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\wldp.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 233’472, EndOfFile: 422’920
35213:48:27.6810773MsMpEng.exe3220FileSystemControlC:\Windows\System32\wldp.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
35313:48:27.6810960MsMpEng.exe3220QueryIdInformationC:\Windows\System32\wldp.dllSUCCESS
35413:48:27.6811140MsMpEng.exe3220CloseFileC:\Windows\System32\wldp.dllSUCCESS
35513:48:27.6813632MsMpEng.exe3220CreateFileC:\Windows\System32\msvcp_win.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
35613:48:27.6813990MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\msvcp_win.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
35713:48:27.6814098MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\msvcp_win.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 278’528, EndOfFile: 641’920
35813:48:27.6814212MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\msvcp_win.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
35913:48:27.6814274MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\msvcp_win.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 278’528, EndOfFile: 641’920
36013:48:27.6814375MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp_win.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
36113:48:27.6814543MsMpEng.exe3220QueryIdInformationC:\Windows\System32\msvcp_win.dllSUCCESS
36213:48:27.6814735MsMpEng.exe3220CloseFileC:\Windows\System32\msvcp_win.dllSUCCESS
36313:48:27.6829721MsMpEng.exe3220CreateFileC:\Windows\System32\spfileq.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
36413:48:27.6830160MsMpEng.exe3220FileSystemControlC:\Windows\System32\spfileq.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
36513:48:27.6830251MsMpEng.exe3220FileSystemControlC:\Windows\System32\spfileq.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
36613:48:27.6830325MsMpEng.exe3220CloseFileC:\Windows\System32\spfileq.dllSUCCESS
36713:48:27.6831971MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
36813:48:27.6832126MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
36913:48:27.6834129MsMpEng.exe3220CreateFileC:\Windows\System32\spfileq.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
37013:48:27.6834450MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\spfileq.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
37113:48:27.6834522MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\spfileq.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:16:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:40, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 73’728, EndOfFile: 139’264
37213:48:27.6834609MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\spfileq.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
37313:48:27.6834747MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\spfileq.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:16:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:40, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 73’728, EndOfFile: 139’264
37413:48:27.6838485MsMpEng.exe3220FileSystemControlC:\Windows\System32\spfileq.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
37513:48:27.6838604MsMpEng.exe3220QueryIdInformationC:\Windows\System32\spfileq.dllSUCCESS
37613:48:27.6838849MsMpEng.exe3220CloseFileC:\Windows\System32\spfileq.dllSUCCESS
37713:48:27.6848873MsMpEng.exe3220CreateFileC:\Windows\System32\win32u.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
37813:48:27.6849423MsMpEng.exe3220FileSystemControlC:\Windows\System32\win32u.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
37913:48:27.6849763MsMpEng.exe3220FileSystemControlC:\Windows\System32\win32u.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
38013:48:27.6849972MsMpEng.exe3220CloseFileC:\Windows\System32\win32u.dllSUCCESS
38113:48:27.6854787MsMpEng.exe3220CreateFileC:\Windows\System32\gdi32full.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
38213:48:27.6855032MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32full.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
38313:48:27.6855119MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32full.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
38413:48:27.6855298MsMpEng.exe3220CloseFileC:\Windows\System32\gdi32full.dllSUCCESS
38513:48:27.6855485MsMpEng.exe3220CreateFileC:\Windows\System32\win32u.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
38613:48:27.6856346MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\win32u.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
38713:48:27.6856486MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\win32u.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:35, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:35, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 170’872
38813:48:27.6856698MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\win32u.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
38913:48:27.6856783MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\win32u.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:35, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:35, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 170’872
39013:48:27.6856905MsMpEng.exe3220FileSystemControlC:\Windows\System32\win32u.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
39113:48:27.6856996MsMpEng.exe3220QueryIdInformationC:\Windows\System32\win32u.dllSUCCESS
39213:48:27.6857118MsMpEng.exe3220CreateFileC:\Windows\System32\user32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
39313:48:27.6857156MsMpEng.exe3220CloseFileC:\Windows\System32\win32u.dllSUCCESS
39413:48:27.6857601MsMpEng.exe3220FileSystemControlC:\Windows\System32\user32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
39513:48:27.6857694MsMpEng.exe3220FileSystemControlC:\Windows\System32\user32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
39613:48:27.6857763MsMpEng.exe3220CloseFileC:\Windows\System32\user32.dllSUCCESS
39713:48:27.6861703MsMpEng.exe3220CreateFileC:\Windows\System32\gdi32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
39813:48:27.6862206MsMpEng.exe3220CreateFileC:\Windows\System32\gdi32full.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
39913:48:27.6862309MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
40013:48:27.6862462MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
40113:48:27.6862549MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\gdi32full.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ
40213:48:27.6862627MsMpEng.exe3220CloseFileC:\Windows\System32\gdi32.dllSUCCESS
40313:48:27.6862635MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\gdi32full.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 659’456, EndOfFile: 1’236’920
40413:48:27.6862873MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\gdi32full.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ
40513:48:27.6862941MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\gdi32full.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 659’456, EndOfFile: 1’236’920
40613:48:27.6863041MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32full.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
40713:48:27.6863129MsMpEng.exe3220QueryIdInformationC:\Windows\System32\gdi32full.dllSUCCESS
40813:48:27.6863269MsMpEng.exe3220CloseFileC:\Windows\System32\gdi32full.dllSUCCESS
40913:48:27.6863551MsMpEng.exe3220CreateFileC:\Windows\System32\msvcp_win.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
41013:48:27.6863820MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp_win.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
41113:48:27.6863916MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp_win.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
41213:48:27.6864048MsMpEng.exe3220CloseFileC:\Windows\System32\msvcp_win.dllSUCCESS
41313:48:27.6867690MsMpEng.exe3220CreateFileC:\Windows\System32\user32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
41413:48:27.6867828MsMpEng.exe3220CreateFileC:\Windows\System32\imm32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
41513:48:27.6868059MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\user32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win
41613:48:27.6868146MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\user32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:32, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:32, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 868’352, EndOfFile: 1’873’232
41713:48:27.6868211MsMpEng.exe3220FileSystemControlC:\Windows\System32\imm32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
41813:48:27.6868309MsMpEng.exe3220FileSystemControlC:\Windows\System32\imm32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
41913:48:27.6868373MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\user32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
42013:48:27.6868411MsMpEng.exe3220CloseFileC:\Windows\System32\imm32.dllSUCCESS
42113:48:27.6868465MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\user32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:32, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:32, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 868’352, EndOfFile: 1’873’232
42213:48:27.6868587MsMpEng.exe3220FileSystemControlC:\Windows\System32\user32.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
42313:48:27.6868677MsMpEng.exe3220QueryIdInformationC:\Windows\System32\user32.dllSUCCESS
42413:48:27.6868933MsMpEng.exe3220CloseFileC:\Windows\System32\user32.dllSUCCESS
42513:48:27.6873265MsMpEng.exe3220CreateFileC:\Windows\System32\gdi32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
42613:48:27.6873769MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\gdi32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
42713:48:27.6873885MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\gdi32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 69’632, EndOfFile: 187’392
42813:48:27.6873991MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\gdi32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ
42913:48:27.6874054MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\gdi32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 69’632, EndOfFile: 187’392
43013:48:27.6874145MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
43113:48:27.6874229MsMpEng.exe3220QueryIdInformationC:\Windows\System32\gdi32.dllSUCCESS
43213:48:27.6874626MsMpEng.exe3220CloseFileC:\Windows\System32\gdi32.dllSUCCESS
43313:48:27.6877239MsMpEng.exe3220CreateFileC:\Windows\System32\imm32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
43413:48:27.6878021MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\imm32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
43513:48:27.6878137MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\imm32.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:15:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:39, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 102’400, EndOfFile: 203’904
43613:48:27.6878227MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\imm32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
43713:48:27.6878280MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\imm32.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:15:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:39, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 102’400, EndOfFile: 203’904
43813:48:27.6878351MsMpEng.exe3220FileSystemControlC:\Windows\System32\imm32.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
43913:48:27.6878421MsMpEng.exe3220QueryIdInformationC:\Windows\System32\imm32.dllSUCCESS
44013:48:27.6878620MsMpEng.exe3220CloseFileC:\Windows\System32\imm32.dllSUCCESS
44113:48:27.6878666MsMpEng.exe3220CreateFileC:\Windows\System32\uxtheme.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
44213:48:27.6879086MsMpEng.exe3220FileSystemControlC:\Windows\System32\uxtheme.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
44313:48:27.6879172MsMpEng.exe3220FileSystemControlC:\Windows\System32\uxtheme.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
44413:48:27.6879350MsMpEng.exe3220CloseFileC:\Windows\System32\uxtheme.dllSUCCESS
44513:48:27.6886650MsMpEng.exe3220CreateFileC:\Windows\System32\uxtheme.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
44613:48:27.6887003MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\uxtheme.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
44713:48:27.6887185MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\uxtheme.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:33, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 360’448, EndOfFile: 688’128
44813:48:27.6887310MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\uxtheme.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win?
44913:48:27.6887372MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\uxtheme.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:33, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 360’448, EndOfFile: 688’128
45013:48:27.6887455MsMpEng.exe3220FileSystemControlC:\Windows\System32\uxtheme.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
45113:48:27.6887628MsMpEng.exe3220QueryIdInformationC:\Windows\System32\uxtheme.dllSUCCESS
45213:48:27.6887766MsMpEng.exe3220CloseFileC:\Windows\System32\uxtheme.dllSUCCESS
45313:48:27.7030359MsMpEng.exe3220CreateFileC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
45413:48:27.7030753MsMpEng.exe3220FileSystemControlC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
45513:48:27.7030866MsMpEng.exe3220FileSystemControlC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
45613:48:27.7030966MsMpEng.exe3220CloseFileC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESS
45713:48:27.7033874MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
45813:48:27.7034105MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
45913:48:27.7035319MsMpEng.exe3220CreateFileC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
46013:48:27.7035800MsMpEng.exe3220QueryInformationVolumeC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
46113:48:27.7035890MsMpEng.exe3220QueryAllInformationFileC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 26.09.2025 09:40:09, ChangeTime: 01.10.2025 17:35:48, FileAttributes: A, AllocationSize: 1’576’960, EndOfFile: 2’696’592
46213:48:27.7036154MsMpEng.exe3220QueryInformationVolumeC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
46313:48:27.7036233MsMpEng.exe3220QueryAllInformationFileC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 26.09.2025 09:40:09, ChangeTime: 01.10.2025 17:35:48, FileAttributes: A, AllocationSize: 1’576’960, EndOfFile: 2’696’592
46413:48:27.7036340MsMpEng.exe3220FileSystemControlC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
46513:48:27.7036431MsMpEng.exe3220QueryIdInformationC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESS
46613:48:27.7036586MsMpEng.exe3220CloseFileC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESS
46713:48:27.7040260MsMpEng.exe3220CreateFileMappingC:\Windows\WindowsShell.ManifestFILE LOCKED WITH ONLY READERSSyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ
46813:48:27.7040408MsMpEng.exe3220QueryStandardInformationFileC:\Windows\WindowsShell.ManifestSUCCESSAllocationSize: 4’096, EndOfFile: 670, NumberOfLinks: 4, DeletePending: False, Directory: False
46913:48:27.7060038MsMpEng.exe3220CreateFileC:\Windows\System32\msctf.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
47013:48:27.7060421MsMpEng.exe3220FileSystemControlC:\Windows\System32\msctf.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
47113:48:27.7060525MsMpEng.exe3220FileSystemControlC:\Windows\System32\msctf.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
47213:48:27.7060604MsMpEng.exe3220CloseFileC:\Windows\System32\msctf.dllSUCCESS
47313:48:27.7063141MsMpEng.exe3220CreateFileC:\Windows\System32\msctf.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
47413:48:27.7063507MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\msctf.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
47513:48:27.7063594MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\msctf.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:43:00, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 847’872, EndOfFile: 1’435’240
47613:48:27.7063681MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\msctf.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
47713:48:27.7063732MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\msctf.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:43:00, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 847’872, EndOfFile: 1’435’240
47813:48:27.7063807MsMpEng.exe3220FileSystemControlC:\Windows\System32\msctf.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
47913:48:27.7063882MsMpEng.exe3220QueryIdInformationC:\Windows\System32\msctf.dllSUCCESS
48013:48:27.7064106MsMpEng.exe3220CloseFileC:\Windows\System32\msctf.dllSUCCESS
48113:48:27.7140642MsMpEng.exe3220CreateFileC:\Windows\System32\kernel.appcore.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
48213:48:27.7140893MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
48313:48:27.7140981MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
48413:48:27.7141145MsMpEng.exe3220CloseFileC:\Windows\System32\kernel.appcore.dllSUCCESS
48513:48:27.7144992MsMpEng.exe3220CreateFileC:\Windows\System32\kernel.appcore.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
48613:48:27.7145217MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\kernel.appcore.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
48713:48:27.7145426MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\kernel.appcore.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 121’280
48813:48:27.7145548MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\kernel.appcore.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
48913:48:27.7145695MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\kernel.appcore.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 121’280
49013:48:27.7145813MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
49113:48:27.7145899MsMpEng.exe3220QueryIdInformationC:\Windows\System32\kernel.appcore.dllSUCCESS
49213:48:27.7146173MsMpEng.exe3220CloseFileC:\Windows\System32\kernel.appcore.dllSUCCESS
49313:48:27.7148925MsMpEng.exe3220CreateFileC:\Windows\System32\oleaut32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
49413:48:27.7149479MsMpEng.exe3220FileSystemControlC:\Windows\System32\oleaut32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
49513:48:27.7149652MsMpEng.exe3220FileSystemControlC:\Windows\System32\oleaut32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
49613:48:27.7149770MsMpEng.exe3220CloseFileC:\Windows\System32\oleaut32.dllSUCCESS
49713:48:27.7154325MsMpEng.exe3220CreateFileC:\Windows\System32\oleaut32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
49813:48:27.7154950MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\oleaut32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win
49913:48:27.7155064MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\oleaut32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:00, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 483’328, EndOfFile: 889’816
50013:48:27.7155574MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\oleaut32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
50113:48:27.7158252MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\oleaut32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:00, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 483’328, EndOfFile: 889’816
50213:48:27.7158815MsMpEng.exe3220FileSystemControlC:\Windows\System32\oleaut32.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
50313:48:27.7159262MsMpEng.exe3220QueryIdInformationC:\Windows\System32\oleaut32.dllSUCCESS
50413:48:27.7159673MsMpEng.exe3220CloseFileC:\Windows\System32\oleaut32.dllSUCCESS
50513:48:27.7203923MsMpEng.exe3220CreateFileC:\Windows\System32\TextInputFramework.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
50613:48:27.7204151MsMpEng.exe3220FileSystemControlC:\Windows\System32\TextInputFramework.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
50713:48:27.7204234MsMpEng.exe3220FileSystemControlC:\Windows\System32\TextInputFramework.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
50813:48:27.7204410MsMpEng.exe3220CloseFileC:\Windows\System32\TextInputFramework.dllSUCCESS
50913:48:27.7207056MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
51013:48:27.7207283MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
51113:48:27.7208684MsMpEng.exe3220CreateFileC:\Windows\System32\TextInputFramework.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
51213:48:27.7209567MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\TextInputFramework.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
51313:48:27.7210020MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\TextInputFramework.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:43, FileAttributes: A, AllocationSize: 774’144, EndOfFile: 1’369’128
51413:48:27.7210146MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\TextInputFramework.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
51513:48:27.7210210MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\TextInputFramework.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:43, FileAttributes: A, AllocationSize: 774’144, EndOfFile: 1’369’128
51613:48:27.7210291MsMpEng.exe3220FileSystemControlC:\Windows\System32\TextInputFramework.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
51713:48:27.7210372MsMpEng.exe3220QueryIdInformationC:\Windows\System32\TextInputFramework.dllSUCCESS
51813:48:27.7210644MsMpEng.exe3220CloseFileC:\Windows\System32\TextInputFramework.dllSUCCESS
51913:48:27.7324914MsMpEng.exe3220CreateFileMappingC:\Windows\Fonts\StaticCache.datFILE LOCKED WITH ONLY READERSSyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ
52013:48:27.7325032MsMpEng.exe3220QueryStandardInformationFileC:\Windows\Fonts\StaticCache.datSUCCESSAllocationSize: 9’203’712, EndOfFile: 20’381’696, NumberOfLinks: 2, DeletePending: False, Directory: False
52113:48:27.7378599MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
52213:48:27.7378807MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
52313:48:27.7412452MsMpEng.exe3220CreateFileC:\Windows\System32\TextShaping.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
52413:48:27.7412831MsMpEng.exe3220FileSystemControlC:\Windows\System32\TextShaping.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
52513:48:27.7412953MsMpEng.exe3220FileSystemControlC:\Windows\System32\TextShaping.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
52613:48:27.7413214MsMpEng.exe3220CloseFileC:\Windows\System32\TextShaping.dllSUCCESS
52713:48:27.7416000MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
52813:48:27.7416304MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
52913:48:27.7418481MsMpEng.exe3220CreateFileC:\Windows\System32\TextShaping.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
53013:48:27.7418847MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\TextShaping.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ
53113:48:27.7418945MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\TextShaping.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:37, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:37, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 270’336, EndOfFile: 749’328
53213:48:27.7419051MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\TextShaping.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
53313:48:27.7419218MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\TextShaping.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:37, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:37, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 270’336, EndOfFile: 749’328
53413:48:27.7419359MsMpEng.exe3220FileSystemControlC:\Windows\System32\TextShaping.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
53513:48:27.7419493MsMpEng.exe3220QueryIdInformationC:\Windows\System32\TextShaping.dllSUCCESS
53613:48:27.7419674MsMpEng.exe3220CloseFileC:\Windows\System32\TextShaping.dllSUCCESS
53713:48:27.7493089MsMpEng.exe3220CreateFileC:\Windows\System32\windows.storage.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
53813:48:27.7493339MsMpEng.exe3220FileSystemControlC:\Windows\System32\windows.storage.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
53913:48:27.7493442MsMpEng.exe3220FileSystemControlC:\Windows\System32\windows.storage.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
54013:48:27.7493517MsMpEng.exe3220CloseFileC:\Windows\System32\windows.storage.dllSUCCESS
54113:48:27.7497009MsMpEng.exe3220CreateFileC:\Windows\System32\windows.storage.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
54213:48:27.7497435MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\windows.storage.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win
54313:48:27.7497687MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\windows.storage.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:01, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:01, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 4’902’912, EndOfFile: 8’831’584
54413:48:27.7498270MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\windows.storage.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
54513:48:27.7503231MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\windows.storage.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:01, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:01, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 4’902’912, EndOfFile: 8’831’584
54613:48:27.7503472MsMpEng.exe3220FileSystemControlC:\Windows\System32\windows.storage.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
54713:48:27.7503602MsMpEng.exe3220QueryIdInformationC:\Windows\System32\windows.storage.dllSUCCESS
54813:48:27.7503768MsMpEng.exe3220CloseFileC:\Windows\System32\windows.storage.dllSUCCESS
54913:48:27.7507536MsMpEng.exe3220CreateFileC:\Windows\System32\shlwapi.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
55013:48:27.7507905MsMpEng.exe3220FileSystemControlC:\Windows\System32\shlwapi.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
55113:48:27.7507991MsMpEng.exe3220FileSystemControlC:\Windows\System32\shlwapi.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
55213:48:27.7508065MsMpEng.exe3220CloseFileC:\Windows\System32\shlwapi.dllSUCCESS
55313:48:27.7514323MsMpEng.exe3220CreateFileC:\Windows\System32\shlwapi.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
55413:48:27.7527477MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\shlwapi.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
55513:48:27.7527836MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\shlwapi.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:16, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:54:16, ChangeTime: 01.10.2025 17:29:40, FileAttributes: A, AllocationSize: 200’704, EndOfFile: 410’504
55613:48:27.7527960MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\shlwapi.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
55713:48:27.7528016MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\shlwapi.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:16, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:54:16, ChangeTime: 01.10.2025 17:29:40, FileAttributes: A, AllocationSize: 200’704, EndOfFile: 410’504
55813:48:27.7528098MsMpEng.exe3220FileSystemControlC:\Windows\System32\shlwapi.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
55913:48:27.7528175MsMpEng.exe3220QueryIdInformationC:\Windows\System32\shlwapi.dllSUCCESS
56013:48:27.7528317MsMpEng.exe3220CloseFileC:\Windows\System32\shlwapi.dllSUCCESS
56113:48:27.7560581MsMpEng.exe3220CreateFileC:\Windows\System32\ntmarta.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
56213:48:27.7560947MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntmarta.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
56313:48:27.7561041MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntmarta.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
56413:48:27.7561117MsMpEng.exe3220CloseFileC:\Windows\System32\ntmarta.dllSUCCESS
56513:48:27.7565416MsMpEng.exe3220CreateFileC:\Windows\System32\ntmarta.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
56613:48:27.7566698MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\ntmarta.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
56713:48:27.7566820MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\ntmarta.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:16:22, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:23, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 118’784, EndOfFile: 224’632
56813:48:27.7566929MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\ntmarta.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
56913:48:27.7566986MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\ntmarta.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:16:22, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:23, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 118’784, EndOfFile: 224’632
57013:48:27.7567278MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntmarta.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
57113:48:27.7567514MsMpEng.exe3220QueryIdInformationC:\Windows\System32\ntmarta.dllSUCCESS
57213:48:27.7567694MsMpEng.exe3220CloseFileC:\Windows\System32\ntmarta.dllSUCCESS
57313:48:27.7574225MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
57413:48:27.7574386MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: True, Offset: 120, Length: 1, Fail Immediately: True
57513:48:27.7574877MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 120, Length: 1
57613:48:27.7574994MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
57713:48:27.7575971MsMpEng.exe3220CreateFileMappingC:\Windows\System32\drivers\SET9BED.tmpFILE LOCKED WITH ONLY READERSSyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ
57813:48:27.7576124MsMpEng.exe3220QueryStandardInformationFileC:\Windows\System32\drivers\SET9BED.tmpSUCCESSAllocationSize: 2’519’040, EndOfFile: 2’518’232, NumberOfLinks: 1, DeletePending: False, Directory: False
57913:48:27.7600356MsMpEng.exe3220CreateFileC:\Windows\System32\CoreMessaging.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
58013:48:27.7600878MsMpEng.exe3220FileSystemControlC:\Windows\System32\CoreMessaging.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
58113:48:27.7601007MsMpEng.exe3220FileSystemControlC:\Windows\System32\CoreMessaging.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
58213:48:27.7601089MsMpEng.exe3220CloseFileC:\Windows\System32\CoreMessaging.dllSUCCESS
58313:48:27.7603229MsMpEng.exe3220CreateFileC:\Windows\System32\CoreMessaging.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
58413:48:27.7603476MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\CoreMessaging.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
58513:48:27.7603550MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\CoreMessaging.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:14:25, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:25, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 688’128, EndOfFile: 1’216’272
58613:48:27.7603631MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\CoreMessaging.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
58713:48:27.7603904MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\CoreMessaging.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:14:25, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:25, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 688’128, EndOfFile: 1’216’272
58813:48:27.7604018MsMpEng.exe3220FileSystemControlC:\Windows\System32\CoreMessaging.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
58913:48:27.7604099MsMpEng.exe3220QueryIdInformationC:\Windows\System32\CoreMessaging.dllSUCCESS
59013:48:27.7604232MsMpEng.exe3220CloseFileC:\Windows\System32\CoreMessaging.dllSUCCESS
59113:48:27.7636945MsMpEng.exe3220CreateFileC:\Windows\System32\CoreUIComponents.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
59213:48:27.7637274MsMpEng.exe3220FileSystemControlC:\Windows\System32\CoreUIComponents.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
59313:48:27.7637908MsMpEng.exe3220FileSystemControlC:\Windows\System32\CoreUIComponents.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
59413:48:27.7637996MsMpEng.exe3220CloseFileC:\Windows\System32\CoreUIComponents.dllSUCCESS
59513:48:27.7651722MsMpEng.exe3220CreateFileC:\Windows\System32\WinTypes.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
59613:48:27.7652114MsMpEng.exe3220FileSystemControlC:\Windows\System32\WinTypes.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
59713:48:27.7653998MsMpEng.exe3220FileSystemControlC:\Windows\System32\WinTypes.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
59813:48:27.7655395MsMpEng.exe3220CloseFileC:\Windows\System32\WinTypes.dllSUCCESS
59913:48:27.7865004MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
60013:48:27.7871100MsMpEng.exe3220CreateFileC:\Windows\System32\drvstore.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
60113:48:27.7871462MsMpEng.exe3220FileSystemControlC:\Windows\System32\drvstore.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
60213:48:27.7871706MsMpEng.exe3220FileSystemControlC:\Windows\System32\drvstore.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
60313:48:27.7871826MsMpEng.exe3220CloseFileC:\Windows\System32\drvstore.dllSUCCESS
60413:48:27.7873186MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
60513:48:27.7876666MsMpEng.exe3220CreateFileC:\Windows\System32\CoreUIComponents.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
60613:48:27.7876940MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\CoreUIComponents.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
60713:48:27.7877300MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\CoreUIComponents.dllBUFFER OVERFLOWCreationTime: 30.08.2025 10:09:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:09:11, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 1’310’720, EndOfFile: 3’032’976
60813:48:27.7877437MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\CoreUIComponents.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
60913:48:27.7877567MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\CoreUIComponents.dllBUFFER OVERFLOWCreationTime: 30.08.2025 10:09:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:09:11, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 1’310’720, EndOfFile: 3’032’976
61013:48:27.7877682MsMpEng.exe3220CreateFileC:\Windows\System32\ole32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
61113:48:27.7877734MsMpEng.exe3220FileSystemControlC:\Windows\System32\CoreUIComponents.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
61213:48:27.7877824MsMpEng.exe3220QueryIdInformationC:\Windows\System32\CoreUIComponents.dllSUCCESS
61313:48:27.7877996MsMpEng.exe3220CloseFileC:\Windows\System32\CoreUIComponents.dllSUCCESS
61413:48:27.7878091MsMpEng.exe3220FileSystemControlC:\Windows\System32\ole32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
61513:48:27.7878182MsMpEng.exe3220FileSystemControlC:\Windows\System32\ole32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
61613:48:27.7878261MsMpEng.exe3220CloseFileC:\Windows\System32\ole32.dllSUCCESS
61713:48:27.7880496MsMpEng.exe3220CreateFileC:\Windows\System32\WinTypes.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
61813:48:27.7881130MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\WinTypes.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅍ
61913:48:27.7881230MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\WinTypes.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 593’920, EndOfFile: 1’505’496
62013:48:27.7881329MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\WinTypes.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
62113:48:27.7881460MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\WinTypes.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 593’920, EndOfFile: 1’505’496
62213:48:27.7881849MsMpEng.exe3220FileSystemControlC:\Windows\System32\WinTypes.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
62313:48:27.7881979MsMpEng.exe3220QueryIdInformationC:\Windows\System32\WinTypes.dllSUCCESS
62413:48:27.7882121MsMpEng.exe3220CloseFileC:\Windows\System32\WinTypes.dllSUCCESS
62513:48:27.7883592MsMpEng.exe3220CreateFileC:\Windows\System32\ole32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
62613:48:27.7884133MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\ole32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
62713:48:27.7884272MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\ole32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 708’608, EndOfFile: 1’687’288
62813:48:27.7884391MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\ole32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win
62913:48:27.7884529MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\ole32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 708’608, EndOfFile: 1’687’288
63013:48:27.7884661MsMpEng.exe3220FileSystemControlC:\Windows\System32\ole32.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
63113:48:27.7884739MsMpEng.exe3220QueryIdInformationC:\Windows\System32\ole32.dllSUCCESS
63213:48:27.7885043MsMpEng.exe3220CloseFileC:\Windows\System32\ole32.dllSUCCESS
63313:48:27.7887420MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
63413:48:27.7887659MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
63513:48:27.7889541MsMpEng.exe3220CreateFileC:\Windows\System32\drvstore.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
63613:48:27.7889922MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\drvstore.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
63713:48:27.7890003MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\drvstore.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:40, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:40, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 876’544, EndOfFile: 1’542’672
63813:48:27.7908322MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\drvstore.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅍ
63913:48:27.7908394MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\drvstore.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:40, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:40, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 876’544, EndOfFile: 1’542’672
64013:48:27.7908499MsMpEng.exe3220FileSystemControlC:\Windows\System32\drvstore.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
64113:48:27.7908575MsMpEng.exe3220QueryIdInformationC:\Windows\System32\drvstore.dllSUCCESS
64213:48:27.7908806MsMpEng.exe3220CloseFileC:\Windows\System32\drvstore.dllSUCCESS
64313:48:27.8065418MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
64413:48:27.8065827MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
64513:48:27.8216806MsMpEng.exe3220Thread CreateSUCCESSThread ID: 9140
64613:48:27.8228289MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
64713:48:27.8228603MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
64813:48:27.8231013MsMpEng.exe3220CreateFileC:\Windows\System32\runonce.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
64913:48:27.8231398MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\runonce.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
65013:48:27.8231492MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\runonce.exeBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 61’440, EndOfFile: 122’880
65113:48:27.8231701MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\runonce.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
65213:48:27.8231760MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\runonce.exeBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 61’440, EndOfFile: 122’880
65313:48:27.8231856MsMpEng.exe3220FileSystemControlC:\Windows\System32\runonce.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
65413:48:27.8231951MsMpEng.exe3220QueryIdInformationC:\Windows\System32\runonce.exeSUCCESS
65513:48:27.8232278MsMpEng.exe3220CloseFileC:\Windows\System32\runonce.exeSUCCESS
65613:48:27.8261304MsMpEng.exe3220CreateFileC:\Windows\System32\services.exeSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
65713:48:27.8261695MsMpEng.exe3220QueryBasicInformationFileC:\Windows\System32\services.exeSUCCESSCreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:26, LastWriteTime: 30.09.2025 13:54:13, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A
65813:48:27.8261780MsMpEng.exe3220CloseFileC:\Windows\System32\services.exeSUCCESS
65913:48:27.8262905MsMpEng.exe3220CreateFileC:\Windows\System32\services.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
66013:48:27.8263211MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\services.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ
66113:48:27.8263406MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\services.exeBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:26, LastWriteTime: 30.09.2025 13:54:13, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 524’288, EndOfFile: 906’376
66213:48:27.8263515MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\services.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
66313:48:27.8263580MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\services.exeBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:26, LastWriteTime: 30.09.2025 13:54:13, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 524’288, EndOfFile: 906’376
66413:48:27.8264144MsMpEng.exe3220FileSystemControlC:\Windows\System32\services.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
66513:48:27.8264333MsMpEng.exe3220QueryIdInformationC:\Windows\System32\services.exeSUCCESS
66613:48:27.8264628MsMpEng.exe3220CloseFileC:\Windows\System32\services.exeSUCCESS
66713:48:27.8346701MsMpEng.exe3220CreateFileC:\Windows\System32\wtsapi32.dllSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
66813:48:27.8347249MsMpEng.exe3220QueryBasicInformationFileC:\Windows\System32\wtsapi32.dllSUCCESSCreationTime: 30.09.2025 13:54:23, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:23, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A
66913:48:27.8347407MsMpEng.exe3220CloseFileC:\Windows\System32\wtsapi32.dllSUCCESS
67013:48:27.8348586MsMpEng.exe3220CreateFileC:\Windows\System32\wtsapi32.dllSUCCESSDesired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
67113:48:27.8349088MsMpEng.exe3220CreateFileMappingC:\Windows\System32\wtsapi32.dllFILE LOCKED WITH ONLY READERSSyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE
67213:48:27.8349357MsMpEng.exe3220CreateFileMappingC:\Windows\System32\wtsapi32.dllSUCCESSSyncType: SyncTypeOther
67313:48:27.8350376MsMpEng.exe3220Load ImageC:\Windows\System32\wtsapi32.dllSUCCESSImage Base: 0x7ff90e510000, Image Size: 0x2a000
67413:48:27.8353968MsMpEng.exe3220CloseFileC:\Windows\System32\wtsapi32.dllSUCCESS
67513:48:27.8368735MsMpEng.exe3220CreateFileC:\Windows\System32\winsta.dllSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
67613:48:27.8369175MsMpEng.exe3220QueryBasicInformationFileC:\Windows\System32\winsta.dllSUCCESSCreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A
67713:48:27.8369271MsMpEng.exe3220CloseFileC:\Windows\System32\winsta.dllSUCCESS
67813:48:27.8371144MsMpEng.exe3220CreateFileC:\Windows\System32\winsta.dllSUCCESSDesired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
67913:48:27.8371670MsMpEng.exe3220CreateFileMappingC:\Windows\System32\winsta.dllFILE LOCKED WITH ONLY READERSSyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE
68013:48:27.8371865MsMpEng.exe3220CreateFileMappingC:\Windows\System32\winsta.dllSUCCESSSyncType: SyncTypeOther
68113:48:27.8373002MsMpEng.exe3220Load ImageC:\Windows\System32\winsta.dllSUCCESSImage Base: 0x7ff911100000, Image Size: 0x63000
68213:48:27.8374034MsMpEng.exe3220CloseFileC:\Windows\System32\winsta.dllSUCCESS
68313:48:27.8383400MsMpEng.exe3220CreateFileC:\Windows\System32\runonce.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
68413:48:27.8383833MsMpEng.exe3220FileSystemControlC:\Windows\System32\runonce.exeOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
68513:48:27.8383982MsMpEng.exe3220FileSystemControlC:\Windows\System32\runonce.exeSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
68613:48:27.8384067MsMpEng.exe3220CloseFileC:\Windows\System32\runonce.exeSUCCESS
68713:48:27.8385942MsMpEng.exe3220CreateFileC:\Windows\System32\ntdll.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
68813:48:27.8386381MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntdll.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
68913:48:27.8386472MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntdll.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
69013:48:27.8386550MsMpEng.exe3220CloseFileC:\Windows\System32\ntdll.dllSUCCESS
69113:48:27.8398249MsMpEng.exe3220CreateFileC:\Windows\System32\grpconvNAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
69213:48:27.8400229MsMpEng.exe3220CreateFileC:\Windows\System32\grpconv -oNAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
69313:48:27.8403402MsMpEng.exe3220CreateFileC:\Windows\System32\grpconvNAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
69413:48:27.8406491MsMpEng.exe3220CreateFileC:\Windows\System32\grpconv -oNAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
69513:48:27.8408413MsMpEng.exe3220CreateFileC:\Windows\System32\grpconvNAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
69613:48:27.8411750MsMpEng.exe3220CreateFileC:\Windows\System32\grpconv -oNAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
69713:48:27.8415556MsMpEng.exe3220CreateFileC:\Windows\System32\grpconvNAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
69813:48:27.8418233MsMpEng.exe3220CreateFileC:\Windows\System32\grpconv -oNAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
69913:48:27.8466492MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
70013:48:27.8469234MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 263’736, Length: 4’096
70113:48:27.8469672MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 119’536, Length: 4’096
70213:48:27.8470610MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 255’496, Length: 4’096
70313:48:27.8470954MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 848’776, Length: 4’096
70413:48:27.8471154MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 115’416, Length: 4’096
70513:48:27.8471325MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 832’296, Length: 4’096
70613:48:27.8471641MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 852’896, Length: 4’096
70713:48:27.8472315MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
70813:48:27.8473085MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
70913:48:27.8473288MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
71013:48:27.8474541MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
71113:48:27.8474933MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
71213:48:27.8475541MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
71313:48:27.8475783MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
71413:48:27.8476799MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
71513:48:27.8477274MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
71613:48:27.8478381MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
71713:48:27.8478497MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
71813:48:27.8479435MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
71913:48:27.8479546MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
72013:48:27.8480213MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
72113:48:27.8480298MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
72213:48:27.8481434MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
72313:48:27.8481550MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 251’376, Length: 4’096
72413:48:27.8481846MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
72513:48:27.8517858MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
72613:48:27.8518503MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
72713:48:27.8518607MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
72813:48:27.8518700MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
72913:48:27.8518758MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
73013:48:27.8518842MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
73113:48:27.8518936MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
73213:48:27.8519222MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
73313:48:27.8520017MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
73413:48:27.8520512MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win
73513:48:27.8520884MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
73613:48:27.8521704MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჱ
73713:48:27.8521871MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
73813:48:27.8522002MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
73913:48:27.8522130MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
74013:48:27.8526818MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
74113:48:27.8533594MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
74213:48:27.8533782MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
74313:48:27.8533950MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
74413:48:27.8534191MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
74513:48:27.8534434MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
74613:48:27.8534532MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
74713:48:27.8534621MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
74813:48:27.8534902MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
74913:48:27.8535744MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
75013:48:27.8535936MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
75113:48:27.8536028MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
75213:48:27.8540513MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
75313:48:27.8540726MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
75413:48:27.8540812MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
75513:48:27.8540891MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჱ
75613:48:27.8541025MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
75713:48:27.8541126MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
75813:48:27.8541211MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
75913:48:27.8541921MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
76013:48:27.8554461MsMpEng.exe3220CreateFileC:\Windows\System32\kernel32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
76113:48:27.8554857MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
76213:48:27.8555079MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
76313:48:27.8555210MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
76413:48:27.8555288MsMpEng.exe3220CloseFileC:\Windows\System32\kernel32.dllSUCCESS
76513:48:27.8556086MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 844’656, Length: 4’096
76613:48:27.8556392MsMpEng.exe3220CreateFileC:\Windows\System32\KernelBase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
76713:48:27.8556488MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 836’416, Length: 4’096
76813:48:27.8556589MsMpEng.exe3220FileSystemControlC:\Windows\System32\KernelBase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
76913:48:27.8556663MsMpEng.exe3220FileSystemControlC:\Windows\System32\KernelBase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
77013:48:27.8556725MsMpEng.exe3220CloseFileC:\Windows\System32\KernelBase.dllSUCCESS
77113:48:27.8556966MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
77213:48:27.8569509MsMpEng.exe3220CreateFileC:\Windows\System32\advapi32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
77313:48:27.8570030MsMpEng.exe3220FileSystemControlC:\Windows\System32\advapi32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
77413:48:27.8570165MsMpEng.exe3220FileSystemControlC:\Windows\System32\advapi32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
77513:48:27.8570262MsMpEng.exe3220CloseFileC:\Windows\System32\advapi32.dllSUCCESS
77613:48:27.8577655MsMpEng.exe3220CreateFileC:\Windows\System32\msvcrt.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
77713:48:27.8577965MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
77813:48:27.8578055MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
77913:48:27.8578135MsMpEng.exe3220CloseFileC:\Windows\System32\msvcrt.dllSUCCESS
78013:48:27.8579274MsMpEng.exe3220CreateFileC:\Windows\System32\sechost.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
78113:48:27.8579629MsMpEng.exe3220FileSystemControlC:\Windows\System32\sechost.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
78213:48:27.8579715MsMpEng.exe3220FileSystemControlC:\Windows\System32\sechost.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
78313:48:27.8579785MsMpEng.exe3220CloseFileC:\Windows\System32\sechost.dllSUCCESS
78413:48:27.8616801MsMpEng.exe3220CreateFileC:\Windows\System32\rpcrt4.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
78513:48:27.8617279MsMpEng.exe3220FileSystemControlC:\Windows\System32\rpcrt4.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
78613:48:27.8617403MsMpEng.exe3220FileSystemControlC:\Windows\System32\rpcrt4.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
78713:48:27.8617611MsMpEng.exe3220CloseFileC:\Windows\System32\rpcrt4.dllSUCCESS
78813:48:27.8619105MsMpEng.exe3220CreateFileC:\Windows\System32\msvcp_win.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
78913:48:27.8619462MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp_win.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
79013:48:27.8619568MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp_win.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
79113:48:27.8619654MsMpEng.exe3220CloseFileC:\Windows\System32\msvcp_win.dllSUCCESS
79213:48:27.8671965MsMpEng.exe3220CreateFileC:\Windows\System32\gdi32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
79313:48:27.8672557MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
79413:48:27.8672682MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
79513:48:27.8672772MsMpEng.exe3220CloseFileC:\Windows\System32\gdi32.dllSUCCESS
79613:48:27.8674147MsMpEng.exe3220CreateFileC:\Windows\System32\user32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
79713:48:27.8674461MsMpEng.exe3220FileSystemControlC:\Windows\System32\user32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
79813:48:27.8674548MsMpEng.exe3220FileSystemControlC:\Windows\System32\user32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
79913:48:27.8674709MsMpEng.exe3220CloseFileC:\Windows\System32\user32.dllSUCCESS
80013:48:27.8679100MsMpEng.exe3220CreateFileC:\Windows\System32\shell32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
80113:48:27.8679505MsMpEng.exe3220FileSystemControlC:\Windows\System32\shell32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
80213:48:27.8679593MsMpEng.exe3220FileSystemControlC:\Windows\System32\shell32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
80313:48:27.8679666MsMpEng.exe3220CloseFileC:\Windows\System32\shell32.dllSUCCESS
80413:48:27.8681926MsMpEng.exe3220CreateFileC:\Windows\System32\ucrtbase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
80513:48:27.8682651MsMpEng.exe3220FileSystemControlC:\Windows\System32\ucrtbase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
80613:48:27.8682750MsMpEng.exe3220FileSystemControlC:\Windows\System32\ucrtbase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
80713:48:27.8682917MsMpEng.exe3220CloseFileC:\Windows\System32\ucrtbase.dllSUCCESS
80813:48:27.8684329MsMpEng.exe3220CreateFileC:\Windows\System32\shell32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
80913:48:27.8684774MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\shell32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win
81013:48:27.8684871MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\shell32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:15, LastAccessTime: 13.10.2025 13:46:06, LastWriteTime: 30.09.2025 13:54:15, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 4’399’104, EndOfFile: 7’699’432
81113:48:27.8684978MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\shell32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
81213:48:27.8685157MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\shell32.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:15, LastAccessTime: 13.10.2025 13:46:06, LastWriteTime: 30.09.2025 13:54:15, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 4’399’104, EndOfFile: 7’699’432
81313:48:27.8685314MsMpEng.exe3220FileSystemControlC:\Windows\System32\shell32.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
81413:48:27.8685436MsMpEng.exe3220QueryIdInformationC:\Windows\System32\shell32.dllSUCCESS
81513:48:27.8685886MsMpEng.exe3220CloseFileC:\Windows\System32\shell32.dllSUCCESS
81613:48:27.8688099MsMpEng.exe3220CreateFileC:\Windows\System32\win32u.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
81713:48:27.8688415MsMpEng.exe3220FileSystemControlC:\Windows\System32\win32u.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
81813:48:27.8688502MsMpEng.exe3220FileSystemControlC:\Windows\System32\win32u.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
81913:48:27.8688575MsMpEng.exe3220CloseFileC:\Windows\System32\win32u.dllSUCCESS
82013:48:27.8690106MsMpEng.exe3220CreateFileC:\Windows\System32\gdi32full.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
82113:48:27.8690348MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32full.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
82213:48:27.8690430MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32full.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
82313:48:27.8690584MsMpEng.exe3220CloseFileC:\Windows\System32\gdi32full.dllSUCCESS
82413:48:27.8692846MsMpEng.exe3220CreateFileC:\Windows\System32\WinTypes.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
82513:48:27.8693516MsMpEng.exe3220FileSystemControlC:\Windows\System32\WinTypes.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
82613:48:27.8693647MsMpEng.exe3220FileSystemControlC:\Windows\System32\WinTypes.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
82713:48:27.8693727MsMpEng.exe3220CloseFileC:\Windows\System32\WinTypes.dllSUCCESS
82813:48:27.8694757MsMpEng.exe3220CreateFileC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
82913:48:27.8694970MsMpEng.exe3220FileSystemControlC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
83013:48:27.8695150MsMpEng.exe3220FileSystemControlC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
83113:48:27.8695220MsMpEng.exe3220CloseFileC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESS
83213:48:27.8696145MsMpEng.exe3220CreateFileC:\Windows\System32\combase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
83313:48:27.8696529MsMpEng.exe3220FileSystemControlC:\Windows\System32\combase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
83413:48:27.8696607MsMpEng.exe3220FileSystemControlC:\Windows\System32\combase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
83513:48:27.8696671MsMpEng.exe3220CloseFileC:\Windows\System32\combase.dllSUCCESS
83613:48:27.8697570MsMpEng.exe3220CreateFileC:\Windows\System32\shlwapi.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
83713:48:27.8697836MsMpEng.exe3220FileSystemControlC:\Windows\System32\shlwapi.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
83813:48:27.8697910MsMpEng.exe3220FileSystemControlC:\Windows\System32\shlwapi.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
83913:48:27.8697973MsMpEng.exe3220CloseFileC:\Windows\System32\shlwapi.dllSUCCESS
84013:48:27.8704046MsMpEng.exe3220CreateFileC:\Windows\System32\ole32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
84113:48:27.8704420MsMpEng.exe3220FileSystemControlC:\Windows\System32\ole32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
84213:48:27.8704503MsMpEng.exe3220FileSystemControlC:\Windows\System32\ole32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
84313:48:27.8704817MsMpEng.exe3220CloseFileC:\Windows\System32\ole32.dllSUCCESS
84413:48:27.8706575MsMpEng.exe3220CreateFileC:\Windows\System32\SHCore.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
84513:48:27.8706951MsMpEng.exe3220FileSystemControlC:\Windows\System32\SHCore.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
84613:48:27.8707031MsMpEng.exe3220FileSystemControlC:\Windows\System32\SHCore.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
84713:48:27.8707099MsMpEng.exe3220CloseFileC:\Windows\System32\SHCore.dllSUCCESS
84813:48:27.8721067MsMpEng.exe3220CreateFileC:\Windows\System32\imm32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
84913:48:27.8721459MsMpEng.exe3220FileSystemControlC:\Windows\System32\imm32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
85013:48:27.8721553MsMpEng.exe3220FileSystemControlC:\Windows\System32\imm32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
85113:48:27.8721632MsMpEng.exe3220CloseFileC:\Windows\System32\imm32.dllSUCCESS
85213:48:27.8848903MsMpEng.exe3220CreateFileC:\Windows\System32\windows.storage.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
85313:48:27.8849237MsMpEng.exe3220FileSystemControlC:\Windows\System32\windows.storage.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
85413:48:27.8849359MsMpEng.exe3220FileSystemControlC:\Windows\System32\windows.storage.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
85513:48:27.8849542MsMpEng.exe3220CloseFileC:\Windows\System32\windows.storage.dllSUCCESS
85613:48:27.8885109MsMpEng.exe3220CreateFileC:\Windows\System32\kernel.appcore.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
85713:48:27.8885436MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
85813:48:27.8885548MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
85913:48:27.8885763MsMpEng.exe3220CloseFileC:\Windows\System32\kernel.appcore.dllSUCCESS
86013:48:27.8897427MsMpEng.exe3220CreateFileC:\Windows\System32\bcryptprimitives.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
86113:48:27.8897723MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcryptprimitives.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
86213:48:27.8897814MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcryptprimitives.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
86313:48:27.8897976MsMpEng.exe3220CloseFileC:\Windows\System32\bcryptprimitives.dllSUCCESS
86413:48:27.8908487MsMpEng.exe3220CreateFileC:\Windows\System32\uxtheme.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
86513:48:27.8908783MsMpEng.exe3220FileSystemControlC:\Windows\System32\uxtheme.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
86613:48:27.8908875MsMpEng.exe3220FileSystemControlC:\Windows\System32\uxtheme.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
86713:48:27.8909061MsMpEng.exe3220CloseFileC:\Windows\System32\uxtheme.dllSUCCESS
86813:48:27.8972384MsMpEng.exe3220CreateFileC:\Windows\System32\oleaut32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
86913:48:27.8972850MsMpEng.exe3220FileSystemControlC:\Windows\System32\oleaut32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
87013:48:27.8972965MsMpEng.exe3220FileSystemControlC:\Windows\System32\oleaut32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
87113:48:27.8973129MsMpEng.exe3220CloseFileC:\Windows\System32\oleaut32.dllSUCCESS
87213:48:27.8996849MsMpEng.exe3220CreateFileC:\Windows\System32\cfgmgr32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
87313:48:27.8997979MsMpEng.exe3220FileSystemControlC:\Windows\System32\cfgmgr32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
87413:48:27.8998169MsMpEng.exe3220FileSystemControlC:\Windows\System32\cfgmgr32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
87513:48:27.8998279MsMpEng.exe3220CloseFileC:\Windows\System32\cfgmgr32.dllSUCCESS
87613:48:27.9025718MsMpEng.exe3220CreateFileC:\Windows\System32\propsys.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
87713:48:27.9026260MsMpEng.exe3220FileSystemControlC:\Windows\System32\propsys.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
87813:48:27.9026375MsMpEng.exe3220FileSystemControlC:\Windows\System32\propsys.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
87913:48:27.9026457MsMpEng.exe3220CloseFileC:\Windows\System32\propsys.dllSUCCESS
88013:48:27.9028773MsMpEng.exe3220CreateFileC:\Windows\System32\propsys.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
88113:48:27.9029077MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\propsys.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
88213:48:27.9029152MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\propsys.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:05, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 565’248, EndOfFile: 1’079’912
88313:48:27.9029305MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\propsys.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
88413:48:27.9029375MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\propsys.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:05, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 565’248, EndOfFile: 1’079’912
88513:48:27.9029476MsMpEng.exe3220FileSystemControlC:\Windows\System32\propsys.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
88613:48:27.9029562MsMpEng.exe3220QueryIdInformationC:\Windows\System32\propsys.dllSUCCESS
88713:48:27.9029773MsMpEng.exe3220CloseFileC:\Windows\System32\propsys.dllSUCCESS
88813:48:27.9038224MsMpEng.exe3220CreateFileC:\Windows\System32\clbcatq.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
88913:48:27.9038562MsMpEng.exe3220FileSystemControlC:\Windows\System32\clbcatq.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
89013:48:27.9038752MsMpEng.exe3220FileSystemControlC:\Windows\System32\clbcatq.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
89113:48:27.9038840MsMpEng.exe3220CloseFileC:\Windows\System32\clbcatq.dllSUCCESS
89213:48:27.9040821MsMpEng.exe3220CreateFileC:\Windows\System32\clbcatq.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
89313:48:27.9041178MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\clbcatq.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win(찚㈀
89413:48:27.9041312MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\clbcatq.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 385’024, EndOfFile: 724’552
89513:48:27.9041411MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\clbcatq.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
89613:48:27.9041467MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\clbcatq.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 385’024, EndOfFile: 724’552
89713:48:27.9041557MsMpEng.exe3220FileSystemControlC:\Windows\System32\clbcatq.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
89813:48:27.9041652MsMpEng.exe3220QueryIdInformationC:\Windows\System32\clbcatq.dllSUCCESS
89913:48:27.9041902MsMpEng.exe3220CloseFileC:\Windows\System32\clbcatq.dllSUCCESS
90013:48:27.9131771MsMpEng.exe3220CreateFileC:\Windows\System32\profapi.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
90113:48:27.9132194MsMpEng.exe3220FileSystemControlC:\Windows\System32\profapi.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
90213:48:27.9132305MsMpEng.exe3220FileSystemControlC:\Windows\System32\profapi.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
90313:48:27.9132381MsMpEng.exe3220CloseFileC:\Windows\System32\profapi.dllSUCCESS
90413:48:27.9134907MsMpEng.exe3220CreateFileC:\Windows\System32\profapi.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
90513:48:27.9135363MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\profapi.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ
90613:48:27.9135771MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\profapi.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:16:15, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:15, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 90’112, EndOfFile: 179’136
90713:48:27.9135920MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\profapi.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
90813:48:27.9135976MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\profapi.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:16:15, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:15, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 90’112, EndOfFile: 179’136
90913:48:27.9136051MsMpEng.exe3220FileSystemControlC:\Windows\System32\profapi.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
91013:48:27.9136123MsMpEng.exe3220QueryIdInformationC:\Windows\System32\profapi.dllSUCCESS
91113:48:27.9136258MsMpEng.exe3220CloseFileC:\Windows\System32\profapi.dllSUCCESS
91213:48:27.9393615MsMpEng.exe3220CreateFileC:\Windows\System32\Windows.StateRepositoryPS.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
91313:48:27.9394573MsMpEng.exe3220FileSystemControlC:\Windows\System32\Windows.StateRepositoryPS.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
91413:48:27.9394780MsMpEng.exe3220FileSystemControlC:\Windows\System32\Windows.StateRepositoryPS.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
91513:48:27.9395134MsMpEng.exe3220CloseFileC:\Windows\System32\Windows.StateRepositoryPS.dllSUCCESS
91613:48:27.9401344MsMpEng.exe3220CreateFileC:\Windows\System32\Windows.StateRepositoryPS.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
91713:48:27.9401628MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\Windows.StateRepositoryPS.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
91813:48:27.9401721MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\Windows.StateRepositoryPS.dllBUFFER OVERFLOWCreationTime: 30.08.2025 10:11:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:11:03, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 233’472, EndOfFile: 819’608
91913:48:27.9401911MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\Windows.StateRepositoryPS.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
92013:48:27.9401970MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\Windows.StateRepositoryPS.dllBUFFER OVERFLOWCreationTime: 30.08.2025 10:11:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:11:03, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 233’472, EndOfFile: 819’608
92113:48:27.9402069MsMpEng.exe3220FileSystemControlC:\Windows\System32\Windows.StateRepositoryPS.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
92213:48:27.9402162MsMpEng.exe3220QueryIdInformationC:\Windows\System32\Windows.StateRepositoryPS.dllSUCCESS
92313:48:27.9402454MsMpEng.exe3220CloseFileC:\Windows\System32\Windows.StateRepositoryPS.dllSUCCESS
92413:48:27.9631334MsMpEng.exe3220CreateFileC:\Windows\System32\edputil.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
92513:48:27.9632045MsMpEng.exe3220FileSystemControlC:\Windows\System32\edputil.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
92613:48:27.9632372MsMpEng.exe3220FileSystemControlC:\Windows\System32\edputil.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
92713:48:27.9632581MsMpEng.exe3220CloseFileC:\Windows\System32\edputil.dllSUCCESS
92813:48:27.9638337MsMpEng.exe3220CreateFileC:\Windows\System32\edputil.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
92913:48:27.9638741MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\edputil.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
93013:48:27.9638841MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\edputil.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:15:17, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:17, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 81’920, EndOfFile: 167’936
93113:48:27.9638934MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\edputil.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
93213:48:27.9638987MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\edputil.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:15:17, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:17, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 81’920, EndOfFile: 167’936
93313:48:27.9639075MsMpEng.exe3220FileSystemControlC:\Windows\System32\edputil.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
93413:48:27.9639165MsMpEng.exe3220QueryIdInformationC:\Windows\System32\edputil.dllSUCCESS
93513:48:27.9639522MsMpEng.exe3220CloseFileC:\Windows\System32\edputil.dllSUCCESS
93613:48:27.9646724MsMpEng.exe3220CreateFileC:\Windows\System32\urlmon.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
93713:48:27.9647356MsMpEng.exe3220FileSystemControlC:\Windows\System32\urlmon.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
93813:48:27.9647594MsMpEng.exe3220FileSystemControlC:\Windows\System32\urlmon.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
93913:48:27.9647744MsMpEng.exe3220CloseFileC:\Windows\System32\urlmon.dllSUCCESS
94013:48:27.9651470MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
94113:48:27.9652157MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
94213:48:27.9652887MsMpEng.exe3220CreateFileC:\Windows\System32\iertutil.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
94313:48:27.9653151MsMpEng.exe3220FileSystemControlC:\Windows\System32\iertutil.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
94413:48:27.9653313MsMpEng.exe3220FileSystemControlC:\Windows\System32\iertutil.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
94513:48:27.9653412MsMpEng.exe3220CloseFileC:\Windows\System32\iertutil.dllSUCCESS
94613:48:27.9653771MsMpEng.exe3220CreateFileC:\Windows\System32\urlmon.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
94713:48:27.9654258MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\urlmon.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
94813:48:27.9654390MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\urlmon.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:47, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:47, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 1’130’496, EndOfFile: 1’921’024
94913:48:27.9654648MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\urlmon.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
95013:48:27.9654737MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\urlmon.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:47, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:47, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 1’130’496, EndOfFile: 1’921’024
95113:48:27.9654872MsMpEng.exe3220FileSystemControlC:\Windows\System32\urlmon.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
95213:48:27.9654988MsMpEng.exe3220QueryIdInformationC:\Windows\System32\urlmon.dllSUCCESS
95313:48:27.9655321MsMpEng.exe3220CloseFileC:\Windows\System32\urlmon.dllSUCCESS
95413:48:27.9660518MsMpEng.exe3220CreateFileC:\Windows\System32\iertutil.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
95513:48:27.9660945MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\iertutil.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
95613:48:27.9661025MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\iertutil.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:48, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:48, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 1’216’512, EndOfFile: 2’918’640
95713:48:27.9661107MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\iertutil.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
95813:48:27.9661159MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\iertutil.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:48, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:48, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 1’216’512, EndOfFile: 2’918’640
95913:48:27.9661339MsMpEng.exe3220FileSystemControlC:\Windows\System32\iertutil.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
96013:48:27.9661469MsMpEng.exe3220QueryIdInformationC:\Windows\System32\iertutil.dllSUCCESS
96113:48:27.9661615MsMpEng.exe3220CloseFileC:\Windows\System32\iertutil.dllSUCCESS
96213:48:27.9665746MsMpEng.exe3220CreateFileC:\Windows\System32\srvcli.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
96313:48:27.9666171MsMpEng.exe3220FileSystemControlC:\Windows\System32\srvcli.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
96413:48:27.9666408MsMpEng.exe3220FileSystemControlC:\Windows\System32\srvcli.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
96513:48:27.9666551MsMpEng.exe3220CloseFileC:\Windows\System32\srvcli.dllSUCCESS
96613:48:27.9669618MsMpEng.exe3220CreateFileC:\Windows\System32\srvcli.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
96713:48:27.9670101MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\srvcli.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win
96813:48:27.9670230MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\srvcli.dllBUFFER OVERFLOWCreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 65’536, EndOfFile: 146’080
96913:48:27.9670369MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\srvcli.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
97013:48:27.9670462MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\srvcli.dllBUFFER OVERFLOWCreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 65’536, EndOfFile: 146’080
97113:48:27.9670673MsMpEng.exe3220FileSystemControlC:\Windows\System32\srvcli.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
97213:48:27.9670824MsMpEng.exe3220QueryIdInformationC:\Windows\System32\srvcli.dllSUCCESS
97313:48:27.9671031MsMpEng.exe3220CloseFileC:\Windows\System32\srvcli.dllSUCCESS
97413:48:27.9672008MsMpEng.exe3220CreateFileC:\Windows\System32\netutils.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
97513:48:27.9672298MsMpEng.exe3220FileSystemControlC:\Windows\System32\netutils.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
97613:48:27.9672395MsMpEng.exe3220FileSystemControlC:\Windows\System32\netutils.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
97713:48:27.9672469MsMpEng.exe3220CloseFileC:\Windows\System32\netutils.dllSUCCESS
97813:48:27.9676479MsMpEng.exe3220CreateFileC:\Windows\System32\netutils.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
97913:48:27.9677081MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\netutils.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ
98013:48:27.9677225MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\netutils.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:16:04, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:04, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 28’672, EndOfFile: 63’336
98113:48:27.9677380MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\netutils.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
98213:48:27.9677582MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\netutils.dllBUFFER OVERFLOWCreationTime: 12.08.2025 20:16:04, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:04, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 28’672, EndOfFile: 63’336
98313:48:27.9677731MsMpEng.exe3220FileSystemControlC:\Windows\System32\netutils.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
98413:48:27.9677868MsMpEng.exe3220QueryIdInformationC:\Windows\System32\netutils.dllSUCCESS
98513:48:27.9678439MsMpEng.exe3220CloseFileC:\Windows\System32\netutils.dllSUCCESS
98613:48:27.9721593MsMpEng.exe3220CreateFileC:\Windows\System32\sspicli.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
98713:48:27.9722298MsMpEng.exe3220FileSystemControlC:\Windows\System32\sspicli.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
98813:48:27.9722412MsMpEng.exe3220FileSystemControlC:\Windows\System32\sspicli.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
98913:48:27.9722509MsMpEng.exe3220CloseFileC:\Windows\System32\sspicli.dllSUCCESS
99013:48:27.9725350MsMpEng.exe3220CreateFileC:\Windows\System32\sspicli.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
99113:48:27.9725959MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\sspicli.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ
99213:48:27.9726070MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\sspicli.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 151’552, EndOfFile: 307’200
99313:48:27.9726182MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\sspicli.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ
99413:48:27.9726320MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\sspicli.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 151’552, EndOfFile: 307’200
99513:48:27.9726448MsMpEng.exe3220FileSystemControlC:\Windows\System32\sspicli.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
99613:48:27.9726542MsMpEng.exe3220QueryIdInformationC:\Windows\System32\sspicli.dllSUCCESS
99713:48:27.9726707MsMpEng.exe3220CloseFileC:\Windows\System32\sspicli.dllSUCCESS
99813:48:27.9800473MsMpEng.exe3220CreateFileC:\Windows\System32\virtdisk.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
99913:48:27.9800961MsMpEng.exe3220FileSystemControlC:\Windows\System32\virtdisk.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
100013:48:27.9801095MsMpEng.exe3220FileSystemControlC:\Windows\System32\virtdisk.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
100113:48:27.9801200MsMpEng.exe3220CloseFileC:\Windows\System32\virtdisk.dllSUCCESS
100213:48:27.9803349MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
100313:48:27.9803580MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
100413:48:27.9805848MsMpEng.exe3220CreateFileC:\Windows\System32\virtdisk.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
100513:48:27.9806591MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\virtdisk.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ
100613:48:27.9807015MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\virtdisk.dllBUFFER OVERFLOWCreationTime: 30.08.2025 10:10:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:10:39, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 49’152, EndOfFile: 103’832
100713:48:27.9807171MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\virtdisk.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
100813:48:27.9807323MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\virtdisk.dllBUFFER OVERFLOWCreationTime: 30.08.2025 10:10:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:10:39, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 49’152, EndOfFile: 103’832
100913:48:27.9807481MsMpEng.exe3220FileSystemControlC:\Windows\System32\virtdisk.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
101013:48:27.9807586MsMpEng.exe3220QueryIdInformationC:\Windows\System32\virtdisk.dllSUCCESS
101113:48:27.9807769MsMpEng.exe3220CloseFileC:\Windows\System32\virtdisk.dllSUCCESS
101213:48:27.9826642MsMpEng.exe3220CreateFileC:\Windows\System32\wldp.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
101313:48:27.9827308MsMpEng.exe3220FileSystemControlC:\Windows\System32\wldp.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
101413:48:27.9827539MsMpEng.exe3220FileSystemControlC:\Windows\System32\wldp.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
101513:48:27.9827648MsMpEng.exe3220CloseFileC:\Windows\System32\wldp.dllSUCCESS
101613:48:27.9880251MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
101713:48:27.9880560MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
101813:48:27.9883606MsMpEng.exe3220CreateFileC:\Windows\System32\grpconv.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
101913:48:27.9884272MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\grpconv.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
102013:48:27.9884388MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\grpconv.exeBUFFER OVERFLOWCreationTime: 01.04.2024 09:22:17, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 01.04.2024 09:22:17, ChangeTime: 30.09.2025 17:02:35, FileAttributes: A, AllocationSize: 12’288, EndOfFile: 45’056
102113:48:27.9884499MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\grpconv.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
102213:48:27.9884644MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\grpconv.exeBUFFER OVERFLOWCreationTime: 01.04.2024 09:22:17, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 01.04.2024 09:22:17, ChangeTime: 30.09.2025 17:02:35, FileAttributes: A, AllocationSize: 12’288, EndOfFile: 45’056
102313:48:27.9884780MsMpEng.exe3220FileSystemControlC:\Windows\System32\grpconv.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
102413:48:27.9884881MsMpEng.exe3220QueryIdInformationC:\Windows\System32\grpconv.exeSUCCESS
102513:48:27.9885044MsMpEng.exe3220CloseFileC:\Windows\System32\grpconv.exeSUCCESS
102613:48:28.0042802MsMpEng.exe3220CreateFileMappingC:\Windows\System32\en-US\grpconv.exe.muiFILE LOCKED WITH ONLY READERSSyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ
102713:48:28.0042927MsMpEng.exe3220QueryStandardInformationFileC:\Windows\System32\en-US\grpconv.exe.muiSUCCESSAllocationSize: 4’096, EndOfFile: 3’072, NumberOfLinks: 2, DeletePending: False, Directory: False
102813:48:28.0048210MsMpEng.exe3220CreateFileC:\Windows\System32\grpconv.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
102913:48:28.0048550MsMpEng.exe3220FileSystemControlC:\Windows\System32\grpconv.exeOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
103013:48:28.0048650MsMpEng.exe3220FileSystemControlC:\Windows\System32\grpconv.exeSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
103113:48:28.0048969MsMpEng.exe3220CloseFileC:\Windows\System32\grpconv.exeSUCCESS
103213:48:28.0050482MsMpEng.exe3220CreateFileC:\Windows\System32\ntdll.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
103313:48:28.0050860MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntdll.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
103413:48:28.0051060MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntdll.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
103513:48:28.0051174MsMpEng.exe3220CloseFileC:\Windows\System32\ntdll.dllSUCCESS
103613:48:28.0055984MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
103713:48:28.0056270MsMpEng.exe3220QueryBasicInformationFileC:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESSCreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D
103813:48:28.0056356MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESS
103913:48:28.0057689MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
104013:48:28.0057844MsMpEng.exe3220QueryBasicInformationFileC:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESSCreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI
104113:48:28.0058009MsMpEng.exe3220CloseFileC:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESS
104213:48:28.0058804MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2SUCCESSDesired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
104313:48:28.0059048MsMpEng.exe3220QueryDirectoryC:\Windows\System32\catroot2\{????????????????????????????????????}SUCCESSFileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}
104413:48:28.0059990MsMpEng.exe3220CreateFileC:\Windows\System32\CatRootNAME COLLISIONDesired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
104513:48:28.0060720MsMpEng.exe3220CreateFileC:\Windows\System32\CatRootSUCCESSDesired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
104613:48:28.0060890MsMpEng.exe3220QuerySecurityFileC:\Windows\System32\CatRootSUCCESSInformation: DACL
104713:48:28.0061069MsMpEng.exe3220CloseFileC:\Windows\System32\CatRootSUCCESS
104813:48:28.0061960MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2NAME COLLISIONDesired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
104913:48:28.0063817MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2SUCCESSDesired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
105013:48:28.0064082MsMpEng.exe3220QuerySecurityFileC:\Windows\System32\catroot2SUCCESSInformation: DACL
105113:48:28.0064189MsMpEng.exe3220CloseFileC:\Windows\System32\catroot2SUCCESS
105213:48:28.0068237MsMpEng.exe3220QueryDirectoryC:\Windows\System32\catroot2SUCCESSFileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}
105313:48:28.0092005MsMpEng.exe3220CreateFileC:\Windows\System32\CatRootNAME COLLISIONDesired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
105413:48:28.0096665MsMpEng.exe3220CreateFileC:\Windows\System32\CatRootSUCCESSDesired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
105513:48:28.0096864MsMpEng.exe3220QuerySecurityFileC:\Windows\System32\CatRootSUCCESSInformation: DACL
105613:48:28.0096950MsMpEng.exe3220CloseFileC:\Windows\System32\CatRootSUCCESS
105713:48:28.0097856MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2NAME COLLISIONDesired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
105813:48:28.0098965MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2SUCCESSDesired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
105913:48:28.0099148MsMpEng.exe3220QuerySecurityFileC:\Windows\System32\catroot2SUCCESSInformation: DACL
106013:48:28.0099340MsMpEng.exe3220CloseFileC:\Windows\System32\catroot2SUCCESS
106113:48:28.0110987MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
106213:48:28.0111248MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catSUCCESSCreationTime: 06.09.2024 06:05:08, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 06.09.2024 05:59:20, ChangeTime: 12.08.2025 21:30:48, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A
106313:48:28.0111327MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catSUCCESS
106413:48:28.0112696MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
106513:48:28.0112923MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESSCreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A
106613:48:28.0113004MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESS
106713:48:28.0114297MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
106813:48:28.0114588MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catSUCCESSCreationTime: 30.09.2025 16:57:54, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.09.2025 16:45:09, ChangeTime: 30.09.2025 17:06:31, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A
106913:48:28.0114663MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catSUCCESS
107013:48:28.0114915MsMpEng.exe3220QueryDirectoryC:\Windows\System32\catroot2NO MORE FILESFileInformationClass: FileBothDirectoryInformation
107113:48:28.0115170MsMpEng.exe3220CloseFileC:\Windows\System32\catroot2SUCCESS
107213:48:28.0116491MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
107313:48:28.0116657MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESSCreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A
107413:48:28.0116729MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESS
107513:48:28.0117447MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESSDesired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
107613:48:28.0117768MsMpEng.exe3220QueryStandardInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESSAllocationSize: 32’768, EndOfFile: 68’167, NumberOfLinks: 3, DeletePending: False, Directory: False
107713:48:28.0117855MsMpEng.exe3220CreateFileMappingC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catFILE LOCKED WITH ONLY READERSSyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE
107813:48:28.0117934MsMpEng.exe3220QueryStandardInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESSAllocationSize: 32’768, EndOfFile: 68’167, NumberOfLinks: 3, DeletePending: False, Directory: False
107913:48:28.0118056MsMpEng.exe3220CreateFileMapping\Device\HarddiskVolume4曘;SUCCESSSyncType: SyncTypeOther
108013:48:28.0119523MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
108113:48:28.0119611MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catBUFFER OVERFLOWCreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 68’167
108213:48:28.0120931MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
108313:48:28.0121091MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catSUCCESSCreationTime: 30.09.2025 16:57:54, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.09.2025 16:45:09, ChangeTime: 30.09.2025 17:06:31, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A
108413:48:28.0121241MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catSUCCESS
108513:48:28.0121690MsMpEng.exe3220CreateFileC:\Windows\System32\kernel32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
108613:48:28.0121961MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
108713:48:28.0122012MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catSUCCESSDesired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
108813:48:28.0122189MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
108913:48:28.0122329MsMpEng.exe3220CloseFileC:\Windows\System32\kernel32.dllSUCCESS
109013:48:28.0122461MsMpEng.exe3220QueryStandardInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catSUCCESSAllocationSize: 32’768, EndOfFile: 68’180, NumberOfLinks: 3, DeletePending: False, Directory: False
109113:48:28.0122561MsMpEng.exe3220CreateFileMappingC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catFILE LOCKED WITH ONLY READERSSyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE
109213:48:28.0122637MsMpEng.exe3220QueryStandardInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catSUCCESSAllocationSize: 32’768, EndOfFile: 68’180, NumberOfLinks: 3, DeletePending: False, Directory: False
109313:48:28.0122760MsMpEng.exe3220CreateFileMapping\Device\HarddiskVolume4ꗔSUCCESSSyncType: SyncTypeOther
109413:48:28.0123650MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
109513:48:28.0123759MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catBUFFER OVERFLOWCreationTime: 30.09.2025 16:57:54, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.09.2025 16:45:09, ChangeTime: 30.09.2025 17:06:31, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 68’180
109613:48:28.0123909MsMpEng.exe3220CreateFileC:\Windows\System32\KernelBase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
109713:48:28.0124182MsMpEng.exe3220FileSystemControlC:\Windows\System32\KernelBase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
109813:48:28.0124275MsMpEng.exe3220FileSystemControlC:\Windows\System32\KernelBase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
109913:48:28.0124364MsMpEng.exe3220CloseFileC:\Windows\System32\KernelBase.dllSUCCESS
110013:48:28.0125050MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
110113:48:28.0125239MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catSUCCESSCreationTime: 06.09.2024 06:05:08, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 06.09.2024 05:59:20, ChangeTime: 12.08.2025 21:30:48, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A
110213:48:28.0125304MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catSUCCESS
110313:48:28.0126349MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catSUCCESSDesired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
110413:48:28.0126563MsMpEng.exe3220QueryStandardInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catSUCCESSAllocationSize: 40’960, EndOfFile: 87’970, NumberOfLinks: 3, DeletePending: False, Directory: False
110513:48:28.0126721MsMpEng.exe3220CreateFileMappingC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catFILE LOCKED WITH ONLY READERSSyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE
110613:48:28.0126812MsMpEng.exe3220QueryStandardInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catSUCCESSAllocationSize: 40’960, EndOfFile: 87’970, NumberOfLinks: 3, DeletePending: False, Directory: False
110713:48:28.0126940MsMpEng.exe3220CreateFileMapping\Device\HarddiskVolume4뎨SUCCESSSyncType: SyncTypeOther
110813:48:28.0128182MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
110913:48:28.0128270MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catBUFFER OVERFLOWCreationTime: 06.09.2024 06:05:08, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 06.09.2024 05:59:20, ChangeTime: 12.08.2025 21:30:48, FileAttributes: A, AllocationSize: 40’960, EndOfFile: 87’970
111013:48:28.0128677MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESS
111113:48:28.0129061MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.catSUCCESS
111213:48:28.0129452MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.catSUCCESS
111313:48:28.0130287MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESSDesired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
111413:48:28.0130647MsMpEng.exe3220FileSystemControlC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
111513:48:28.0131316MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESSDesired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: RH, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
111613:48:28.0131620MsMpEng.exe3220QueryStandardInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESSAllocationSize: 32’768, EndOfFile: 68’167, NumberOfLinks: 3, DeletePending: False, Directory: False
111713:48:28.0131707MsMpEng.exe3220QueryBasicInformationFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESSCreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, FileAttributes: A
111813:48:28.0131824MsMpEng.exe3220ReadFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESSOffset: 0, Length: 68’167, Priority: Normal
111913:48:28.0136797MsMpEng.exe3220CreateFileC:\Windows\System32\advapi32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
112013:48:28.0137181MsMpEng.exe3220FileSystemControlC:\Windows\System32\advapi32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
112113:48:28.0137288MsMpEng.exe3220FileSystemControlC:\Windows\System32\advapi32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
112213:48:28.0137374MsMpEng.exe3220CloseFileC:\Windows\System32\advapi32.dllSUCCESS
112313:48:28.0138794MsMpEng.exe3220CreateFileC:\Windows\System32\msvcrt.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
112413:48:28.0139273MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
112513:48:28.0139403MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
112613:48:28.0139707MsMpEng.exe3220CloseFileC:\Windows\System32\msvcrt.dllSUCCESS
112713:48:28.0141277MsMpEng.exe3220CreateFileC:\Windows\System32\sechost.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
112813:48:28.0141774MsMpEng.exe3220FileSystemControlC:\Windows\System32\sechost.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
112913:48:28.0141871MsMpEng.exe3220FileSystemControlC:\Windows\System32\sechost.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
113013:48:28.0142081MsMpEng.exe3220CloseFileC:\Windows\System32\sechost.dllSUCCESS
113113:48:28.0143059MsMpEng.exe3220CreateFileC:\Windows\System32\rpcrt4.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
113213:48:28.0144061MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESS
113313:48:28.0144222MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.catSUCCESS
113413:48:28.0144848MsMpEng.exe3220FileSystemControlC:\Windows\System32\rpcrt4.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
113513:48:28.0144973MsMpEng.exe3220FileSystemControlC:\Windows\System32\rpcrt4.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
113613:48:28.0145070MsMpEng.exe3220CloseFileC:\Windows\System32\rpcrt4.dllSUCCESS
113713:48:28.0147675MsMpEng.exe3220CreateFileC:\Windows\System32\user32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
113813:48:28.0147962MsMpEng.exe3220FileSystemControlC:\Windows\System32\user32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
113913:48:28.0148143MsMpEng.exe3220FileSystemControlC:\Windows\System32\user32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
114013:48:28.0148169MsMpEng.exe3220CreateFileC:\Windows\System32\en-US\grpconv.exe.muiSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
114113:48:28.0148217MsMpEng.exe3220CloseFileC:\Windows\System32\user32.dllSUCCESS
114213:48:28.0148382MsMpEng.exe3220FileSystemControlC:\Windows\System32\en-US\grpconv.exe.muiSUCCESSControl: FSCTL_READ_FILE_USN_DATA
114313:48:28.0148497MsMpEng.exe3220QueryIdInformationC:\Windows\System32\en-US\grpconv.exe.muiSUCCESS
114413:48:28.0148752MsMpEng.exe3220CloseFileC:\Windows\System32\en-US\grpconv.exe.muiSUCCESS
114513:48:28.0149734MsMpEng.exe3220CreateFileC:\Windows\System32\win32u.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
114613:48:28.0150797MsMpEng.exe3220FileSystemControlC:\Windows\System32\win32u.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
114713:48:28.0150940MsMpEng.exe3220FileSystemControlC:\Windows\System32\win32u.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
114813:48:28.0151036MsMpEng.exe3220CloseFileC:\Windows\System32\win32u.dllSUCCESS
114913:48:28.0154734MsMpEng.exe3220CreateFileC:\Windows\System32\gdi32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
115013:48:28.0155249MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
115113:48:28.0155353MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
115213:48:28.0155443MsMpEng.exe3220CloseFileC:\Windows\System32\gdi32.dllSUCCESS
115313:48:28.0156942MsMpEng.exe3220CreateFileC:\Windows\System32\gdi32full.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
115413:48:28.0157157MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32full.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
115513:48:28.0157231MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32full.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
115613:48:28.0157306MsMpEng.exe3220CloseFileC:\Windows\System32\gdi32full.dllSUCCESS
115713:48:28.0158285MsMpEng.exe3220CreateFileC:\Windows\System32\msvcp_win.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
115813:48:28.0158469MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp_win.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
115913:48:28.0158535MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp_win.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
116013:48:28.0158597MsMpEng.exe3220CloseFileC:\Windows\System32\msvcp_win.dllSUCCESS
116113:48:28.0160074MsMpEng.exe3220CreateFileC:\Windows\System32\ucrtbase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
116213:48:28.0160319MsMpEng.exe3220FileSystemControlC:\Windows\System32\ucrtbase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
116313:48:28.0160399MsMpEng.exe3220FileSystemControlC:\Windows\System32\ucrtbase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
116413:48:28.0168866MsMpEng.exe3220CloseFileC:\Windows\System32\ucrtbase.dllSUCCESS
116513:48:28.0174862MsMpEng.exe3220CreateFileC:\Windows\System32\shell32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
116613:48:28.0176858MsMpEng.exe3220FileSystemControlC:\Windows\System32\shell32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
116713:48:28.0177148MsMpEng.exe3220FileSystemControlC:\Windows\System32\shell32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
116813:48:28.0177265MsMpEng.exe3220CloseFileC:\Windows\System32\shell32.dllSUCCESS
116913:48:28.0182979MsMpEng.exe3220CreateFileC:\Windows\System32\WinTypes.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
117013:48:28.0183767MsMpEng.exe3220FileSystemControlC:\Windows\System32\WinTypes.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
117113:48:28.0183953MsMpEng.exe3220FileSystemControlC:\Windows\System32\WinTypes.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
117213:48:28.0184058MsMpEng.exe3220CloseFileC:\Windows\System32\WinTypes.dllSUCCESS
117313:48:28.0198161MsMpEng.exe3220CreateFileC:\Windows\System32\imm32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
117413:48:28.0198546MsMpEng.exe3220FileSystemControlC:\Windows\System32\imm32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
117513:48:28.0198636MsMpEng.exe3220FileSystemControlC:\Windows\System32\imm32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
117613:48:28.0198712MsMpEng.exe3220CloseFileC:\Windows\System32\imm32.dllSUCCESS
117713:48:28.0199743MsMpEng.exe3220CreateFileC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
117813:48:28.0199956MsMpEng.exe3220FileSystemControlC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
117913:48:28.0200038MsMpEng.exe3220FileSystemControlC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
118013:48:28.0200194MsMpEng.exe3220CloseFileC:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dllSUCCESS
118113:48:28.0201140MsMpEng.exe3220CreateFileC:\Windows\System32\combase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
118213:48:28.0202701MsMpEng.exe3220FileSystemControlC:\Windows\System32\combase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
118313:48:28.0202843MsMpEng.exe3220FileSystemControlC:\Windows\System32\combase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
118413:48:28.0203061MsMpEng.exe3220CloseFileC:\Windows\System32\combase.dllSUCCESS
118513:48:28.0204664MsMpEng.exe3220CreateFileC:\Windows\System32\shlwapi.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
118613:48:28.0205163MsMpEng.exe3220FileSystemControlC:\Windows\System32\shlwapi.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
118713:48:28.0205283MsMpEng.exe3220FileSystemControlC:\Windows\System32\shlwapi.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
118813:48:28.0205483MsMpEng.exe3220CloseFileC:\Windows\System32\shlwapi.dllSUCCESS
118913:48:28.0254379MsMpEng.exe3220CreateFileC:\Windows\System32\kernel.appcore.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
119013:48:28.0254602MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
119113:48:28.0254695MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
119213:48:28.0254771MsMpEng.exe3220CloseFileC:\Windows\System32\kernel.appcore.dllSUCCESS
119313:48:28.0257540MsMpEng.exe3220CreateFileC:\Windows\System32\bcryptprimitives.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
119413:48:28.0257761MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcryptprimitives.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
119513:48:28.0258005MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcryptprimitives.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
119613:48:28.0258105MsMpEng.exe3220CloseFileC:\Windows\System32\bcryptprimitives.dllSUCCESS
119713:48:28.0270441MsMpEng.exe3220CreateFileC:\Windows\System32\uxtheme.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
119813:48:28.0270816MsMpEng.exe3220FileSystemControlC:\Windows\System32\uxtheme.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
119913:48:28.0270936MsMpEng.exe3220FileSystemControlC:\Windows\System32\uxtheme.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
120013:48:28.0271013MsMpEng.exe3220CloseFileC:\Windows\System32\uxtheme.dllSUCCESS
120113:48:28.0286892MsMpEng.exe3220CreateFileC:\Windows\System32\ole32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
120213:48:28.0287268MsMpEng.exe3220FileSystemControlC:\Windows\System32\ole32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
120313:48:28.0287378MsMpEng.exe3220FileSystemControlC:\Windows\System32\ole32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
120413:48:28.0287457MsMpEng.exe3220CloseFileC:\Windows\System32\ole32.dllSUCCESS
120513:48:28.0340751MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
120613:48:28.0341071MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
120713:48:28.0346317MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
120813:48:28.0346543MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
120913:48:28.3342979MsMpEng.exe3220CreateFileC:\Windows\System32\runonce.exeSUCCESSDesired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
121013:48:28.3344175MsMpEng.exe3220FileSystemControlC:\Windows\System32\runonce.exeOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
121113:48:28.3345044MsMpEng.exe3220CreateFileC:\Windows\System32\runonce.exeSUCCESSDesired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
121213:48:28.3345523MsMpEng.exe3220QueryEAFileC:\Windows\System32\runonce.exeBUFFER OVERFLOW
121313:48:28.3345903MsMpEng.exe3220QueryEAFileC:\Windows\System32\runonce.exeSUCCESS
121413:48:28.3346020MsMpEng.exe3220FileSystemControlC:\Windows\System32\runonce.exeSUCCESSControl: FSCTL_QUERY_USN_JOURNAL
121513:48:28.3346147MsMpEng.exe3220CloseFileC:\Windows\System32\runonce.exeSUCCESS
121613:48:28.3346358MsMpEng.exe3220CloseFileC:\Windows\System32\runonce.exeSUCCESS
121713:48:28.3563838MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
121813:48:28.3564103MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
121913:48:28.3898769MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
122013:48:28.3899185MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
122113:48:28.3899397MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
122213:48:28.3899493MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
122313:48:28.3900002MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
122413:48:28.3900367MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
122513:48:28.3900483MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
122613:48:28.3900732MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
122713:48:28.3901603MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
122813:48:28.3901784MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
122913:48:28.3901853MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
123013:48:28.3902050MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
123113:48:28.3902102MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
123213:48:28.3902190MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
123313:48:28.3902267MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
123413:48:28.3902383MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
123513:48:28.3903599MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
123613:48:28.3903847MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
123713:48:28.3903918MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
123813:48:28.3903994MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
123913:48:28.3904205MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
124013:48:28.3904454MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
124113:48:28.3904563MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
124213:48:28.3904729MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
124313:48:28.3905725MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
124413:48:28.3905983MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
124513:48:28.3906072MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
124613:48:28.3907981MsMpEng.exe3220CreateFileC:\Windows\System32\wintrust.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
124713:48:28.3908339MsMpEng.exe3220FileSystemControlC:\Windows\System32\wintrust.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
124813:48:28.3908549MsMpEng.exe3220FileSystemControlC:\Windows\System32\wintrust.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
124913:48:28.3909303MsMpEng.exe3220CloseFileC:\Windows\System32\wintrust.dllSUCCESS
125013:48:28.3910627MsMpEng.exe3220CreateFileC:\Windows\System32\crypt32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
125113:48:28.3910981MsMpEng.exe3220FileSystemControlC:\Windows\System32\crypt32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
125213:48:28.3911167MsMpEng.exe3220FileSystemControlC:\Windows\System32\crypt32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
125313:48:28.3911292MsMpEng.exe3220CloseFileC:\Windows\System32\crypt32.dllSUCCESS
125413:48:28.3912624MsMpEng.exe3220CreateFileC:\Windows\System32\msasn1.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
125513:48:28.3912986MsMpEng.exe3220FileSystemControlC:\Windows\System32\msasn1.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
125613:48:28.3913117MsMpEng.exe3220FileSystemControlC:\Windows\System32\msasn1.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
125713:48:28.3913213MsMpEng.exe3220CloseFileC:\Windows\System32\msasn1.dllSUCCESS
125813:48:28.3914343MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
125913:48:28.3914514MsMpEng.exe3220FileSystemControlC:\Windows\System32\drivers\NeacSafe64.sysOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
126013:48:28.3914587MsMpEng.exe3220FileSystemControlC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
126113:48:28.3914651MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
126213:48:28.4062534MsMpEng.exe3220CreateFileC:\Windows\System32\wintrust.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
126313:48:28.4063170MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\wintrust.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
126413:48:28.4063250MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\wintrust.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:40, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:40, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 299’008, EndOfFile: 530’344
126513:48:28.4063657MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\wintrust.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win,
126613:48:28.4063736MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\wintrust.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:40, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:40, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 299’008, EndOfFile: 530’344
126713:48:28.4064095MsMpEng.exe3220FileSystemControlC:\Windows\System32\wintrust.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
126813:48:28.4064335MsMpEng.exe3220QueryIdInformationC:\Windows\System32\wintrust.dllSUCCESS
126913:48:28.4065552MsMpEng.exe3220CloseFileC:\Windows\System32\wintrust.dllSUCCESS
127013:48:28.4070978MsMpEng.exe3220CreateFileC:\Windows\System32\crypt32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
127113:48:28.4071431MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\crypt32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅄ
127213:48:28.4071665MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\crypt32.dllBUFFER OVERFLOWCreationTime: 30.08.2025 10:09:13, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.08.2025 10:09:13, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 909’312, EndOfFile: 1’534’408
127313:48:28.4071832MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\crypt32.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
127413:48:28.4071900MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\crypt32.dllBUFFER OVERFLOWCreationTime: 30.08.2025 10:09:13, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.08.2025 10:09:13, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 909’312, EndOfFile: 1’534’408
127513:48:28.4072064MsMpEng.exe3220FileSystemControlC:\Windows\System32\crypt32.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
127613:48:28.4072169MsMpEng.exe3220QueryIdInformationC:\Windows\System32\crypt32.dllSUCCESS
127713:48:28.4072333MsMpEng.exe3220CloseFileC:\Windows\System32\crypt32.dllSUCCESS
127813:48:28.4073460MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
127913:48:28.4074062MsMpEng.exe3220CreateFileC:\Windows\System32\msasn1.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
128013:48:28.4074363MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\msasn1.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
128113:48:28.4074449MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\msasn1.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:53:57, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 40’960, EndOfFile: 88’248
128213:48:28.4074530MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\msasn1.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅄ
128313:48:28.4074658MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\msasn1.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:53:57, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 40’960, EndOfFile: 88’248
128413:48:28.4074768MsMpEng.exe3220FileSystemControlC:\Windows\System32\msasn1.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
128513:48:28.4074841MsMpEng.exe3220QueryIdInformationC:\Windows\System32\msasn1.dllSUCCESS
128613:48:28.4074966MsMpEng.exe3220CloseFileC:\Windows\System32\msasn1.dllSUCCESS
128713:48:28.4075532MsMpEng.exe3220RegOpenKeyHKLM\SYSTEM\CurrentControlSet\Control\Session Manager\EnvironmentREPARSEDesired Access: Read
128813:48:28.4076521MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
128913:48:28.4076751MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
129013:48:28.4076830MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWCreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232
129113:48:28.4076908MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
129213:48:28.4076964MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWCreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232
129313:48:28.4077111MsMpEng.exe3220FileSystemControlC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSControl: FSCTL_READ_FILE_USN_DATA
129413:48:28.4077213MsMpEng.exe3220RegOpenKeyHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSDesired Access: Read
129513:48:28.4077252MsMpEng.exe3220QueryIdInformationC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
129613:48:28.4077370MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
129713:48:28.4078235MsMpEng.exe3220RegQueryKeyHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSQuery: Cached, SubKeys: 0, Values: 15
129813:48:28.4078596MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
129913:48:28.4078989MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅄ
130013:48:28.4079086MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWCreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232
130113:48:28.4079167MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
130213:48:28.4079216MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWCreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232
130313:48:28.4079287MsMpEng.exe3220FileSystemControlC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSControl: FSCTL_READ_FILE_USN_DATA
130413:48:28.4079379MsMpEng.exe3220QueryIdInformationC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
130513:48:28.4079578MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
130613:48:28.4079653MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 0, Type: REG_EXPAND_SZ
130713:48:28.4080685MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
130813:48:28.4081275MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
130913:48:28.4081348MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWCreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232
131013:48:28.4081438MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
131113:48:28.4081492MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWCreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232
131213:48:28.4081565MsMpEng.exe3220FileSystemControlC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSControl: FSCTL_READ_FILE_USN_DATA
131313:48:28.4081602MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\ComSpecSUCCESSType: REG_EXPAND_SZ, Length: 60, Data: %SystemRoot%\system32\cmd.exe
131413:48:28.4081655MsMpEng.exe3220QueryIdInformationC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
131513:48:28.4081871MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
131613:48:28.4082884MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
131713:48:28.4083152MsMpEng.exe3220FileSystemControlC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSControl: FSCTL_READ_FILE_USN_DATA
131813:48:28.4083252MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
131913:48:28.4084074MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
132013:48:28.4084385MsMpEng.exe3220FileSystemControlC:\Windows\System32\drivers\NeacSafe64.sysOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
132113:48:28.4085031MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
132213:48:28.4085268MsMpEng.exe3220QueryEAFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
132313:48:28.4085447MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
132413:48:28.4086514MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
132513:48:28.4087427MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 1, Type: REG_SZ
132613:48:28.4089002MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\DriverDataSUCCESSType: REG_SZ, Length: 78, Data: C:\Windows\System32\Drivers\DriverData
132713:48:28.4090547MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 2, Type: REG_SZ
132813:48:28.4091814MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\OSSUCCESSType: REG_SZ, Length: 22, Data: Windows_NT
132913:48:28.4093401MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 3, Type: REG_EXPAND_SZ
133013:48:28.4095410MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\PathBUFFER OVERFLOWLength: 144
133113:48:28.4095466MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
133213:48:28.4096645MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\PathSUCCESSType: REG_EXPAND_SZ, Length: 514, Data:
133313:48:28.4097914MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 4, Type: REG_SZ
133413:48:28.4099007MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\PATHEXTSUCCESSType: REG_SZ, Length: 108, Data: .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
133513:48:28.4099163MsMpEng.exe3220FileSystemControlC:\Windows\System32\drivers\NeacSafe64.sysOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
133613:48:28.4100824MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 5, Type: REG_SZ
133713:48:28.4101942MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_ARCHITECTURESUCCESSType: REG_SZ, Length: 12, Data: AMD64
133813:48:28.4103225MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 6, Type: REG_EXPAND_SZ
133913:48:28.4104192MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\PSModulePathBUFFER OVERFLOWLength: 144
134013:48:28.4106832MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\PSModulePathSUCCESSType: REG_EXPAND_SZ, Length: 188, Data:
134113:48:28.4108727MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 7, Type: REG_EXPAND_SZ
134213:48:28.4111180MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\TEMPSUCCESSType: REG_EXPAND_SZ, Length: 36, Data: %SystemRoot%\TEMP
134313:48:28.4114699MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 8, Type: REG_EXPAND_SZ
134413:48:28.4119680MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\TMPSUCCESSType: REG_EXPAND_SZ, Length: 36, Data: %SystemRoot%\TEMP
134513:48:28.4121491MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 9, Type: REG_SZ
134613:48:28.4122589MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\USERNAMESUCCESSType: REG_SZ, Length: 14, Data: SYSTEM
134713:48:28.4123776MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 10, Type: REG_EXPAND_SZ
134813:48:28.4124750MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\windirSUCCESSType: REG_EXPAND_SZ, Length: 26, Data: %SystemRoot%
134913:48:28.4126314MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 11, Type: REG_SZ
135013:48:28.4127466MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\NUMBER_OF_PROCESSORSSUCCESSType: REG_SZ, Length: 4, Data: 4
135113:48:28.4129272MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 12, Type: REG_SZ
135213:48:28.4130339MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_LEVELSUCCESSType: REG_SZ, Length: 6, Data: 25
135313:48:28.4131439MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 13, Type: REG_SZ
135413:48:28.4132525MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_IDENTIFIERSUCCESSType: REG_SZ, Length: 100, Data: AMD64 Family 25 Model 33 Stepping 0, AuthenticAMD
135513:48:28.4133289MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESSIndex: 14, Type: REG_SZ
135613:48:28.4134232MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_REVISIONSUCCESSType: REG_SZ, Length: 10, Data: 2100
135713:48:28.4135187MsMpEng.exe3220RegCloseKeyHKLM\System\CurrentControlSet\Control\Session Manager\EnvironmentSUCCESS
135813:48:28.4136168MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
135913:48:28.4144746MsMpEng.exe3220RegOpenKeyHKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SFCREPARSEDesired Access: Read
136013:48:28.4145954MsMpEng.exe3220RegOpenKeyHKLM\System\CurrentControlSet\Control\Session Manager\SFCNAME NOT FOUNDDesired Access: Read
136113:48:28.4147199MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
136213:48:28.4148243MsMpEng.exe3220RegOpenKeyHKLM\Software\Microsoft\Windows\CurrentVersionSUCCESSDesired Access: Read
136313:48:28.4149953MsMpEng.exe3220RegQueryKeyHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESSQuery: Cached, SubKeys: 167, Values: 11
136413:48:28.4152459MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESSIndex: 0, Type: REG_SZ
136513:48:28.4154152MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDirSUCCESSType: REG_SZ, Length: 34, Data: C:\Program Files
136613:48:28.4156536MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESSIndex: 1, Type: REG_SZ
136713:48:28.4159412MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDirSUCCESSType: REG_SZ, Length: 60, Data: C:\Program Files\Common Files
136813:48:28.4161412MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
136913:48:28.4161750MsMpEng.exe3220QueryEAFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
137013:48:28.4161887MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
137113:48:28.4162088MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
137213:48:28.4163839MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
137313:48:28.4164077MsMpEng.exe3220FileSystemControlC:\Windows\System32\drivers\NeacSafe64.sysOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
137413:48:28.4164790MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESSIndex: 2, Type: REG_SZ
137513:48:28.4166301MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)SUCCESSType: REG_SZ, Length: 46, Data: C:\Program Files (x86)
137613:48:28.4166895MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
137713:48:28.4167274MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESSIndex: 3, Type: REG_SZ
137813:48:28.4168452MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)SUCCESSType: REG_SZ, Length: 72, Data: C:\Program Files (x86)\Common Files
137913:48:28.4170713MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESSIndex: 4, Type: REG_SZ
138013:48:28.4172534MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432DirSUCCESSType: REG_SZ, Length: 60, Data: C:\Program Files\Common Files
138113:48:28.4174126MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESSIndex: 5, Type: REG_EXPAND_SZ
138213:48:28.4176792MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DevicePathSUCCESSType: REG_EXPAND_SZ, Length: 34, Data: %SystemRoot%\inf
138313:48:28.4178130MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESSIndex: 6, Type: REG_EXPAND_SZ
138413:48:28.4179072MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\MediaPathUnexpandedSUCCESSType: REG_EXPAND_SZ, Length: 38, Data: %SystemRoot%\Media
138513:48:28.4179942MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESSIndex: 7, Type: REG_EXPAND_SZ
138613:48:28.4181129MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesPathSUCCESSType: REG_EXPAND_SZ, Length: 30, Data: %ProgramFiles%
138713:48:28.4182246MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESSIndex: 8, Type: REG_SZ
138813:48:28.4183162MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432DirSUCCESSType: REG_SZ, Length: 34, Data: C:\Program Files
138913:48:28.4184081MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESSIndex: 9, Type: REG_SZ
139013:48:28.4185178MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SM_ConfigureProgramsNameSUCCESSType: REG_SZ, Length: 64, Data: Set Program Access and Defaults
139113:48:28.4186417MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESSIndex: 10, Type: REG_SZ
139213:48:28.4187391MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SM_GamesNameSUCCESSType: REG_SZ, Length: 12, Data: Games
139313:48:28.4189601MsMpEng.exe3220RegCloseKeyHKLM\SOFTWARE\Microsoft\Windows\CurrentVersionSUCCESS
139413:48:28.4190797MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
139513:48:28.4191727MsMpEng.exe3220RegOpenKeyHKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSDesired Access: Read
139613:48:28.4192705MsMpEng.exe3220RegQueryKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSQuery: Cached, SubKeys: 4, Values: 4
139713:48:28.4193577MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSIndex: 0, Type: REG_EXPAND_SZ
139813:48:28.4194418MsMpEng.exe3220QueryBasicInformationFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSCreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A
139913:48:28.4194487MsMpEng.exe3220QueryStandardInformationFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSAllocationSize: 2’519’040, EndOfFile: 2’518’232, NumberOfLinks: 1, DeletePending: False, Directory: False
140013:48:28.4195080MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 0, Length: 4’096, Priority: Normal
140113:48:28.4197308MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 2’510’848, Length: 7’384, Priority: Normal
140213:48:28.4197999MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 2’506’752, Length: 4’096, Priority: Normal
140313:48:28.4200447MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 4’096, Length: 520’192, Priority: Normal
140413:48:28.4213650MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\DefaultSUCCESSType: REG_EXPAND_SZ, Length: 56, Data: %SystemDrive%\Users\Default
140513:48:28.4214361MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSIndex: 1, Type: REG_EXPAND_SZ
140613:48:28.4215221MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProfilesDirectorySUCCESSType: REG_EXPAND_SZ, Length: 40, Data: %SystemDrive%\Users
140713:48:28.4216075MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSIndex: 2, Type: REG_EXPAND_SZ
140813:48:28.4216941MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramDataSUCCESSType: REG_EXPAND_SZ, Length: 52, Data: %SystemDrive%\ProgramData
140913:48:28.4217760MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSIndex: 3, Type: REG_EXPAND_SZ
141013:48:28.4218530MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\PublicSUCCESSType: REG_EXPAND_SZ, Length: 54, Data: %SystemDrive%\Users\Public
141113:48:28.4219514MsMpEng.exe3220RegCloseKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESS
141213:48:28.4221313MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
141313:48:28.4222249MsMpEng.exe3220RegCreateKeyHKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSDesired Access: Read, Disposition: REG_OPENED_EXISTING_KEY
141413:48:28.4223180MsMpEng.exe3220RegQueryKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSQuery: Cached, SubKeys: 4, Values: 4
141513:48:28.4224012MsMpEng.exe3220RegEnumKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSIndex: 0, Name: S-1-5-18
141613:48:28.4224820MsMpEng.exe3220RegQueryKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSQuery: HandleTags, HandleTags: 0x0
141713:48:28.4225533MsMpEng.exe3220RegOpenKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18SUCCESSDesired Access: Read
141813:48:28.4226493MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePathSUCCESSType: REG_EXPAND_SZ, Length: 86, Data: %systemroot%\system32\config\systemprofile
141913:48:28.4228042MsMpEng.exe3220CreateFileC:\Windows\System32\config\systemprofile\ntuser.datNAME NOT FOUNDDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
142013:48:28.4228791MsMpEng.exe3220CreateFileC:\Windows\System32\config\systemprofile\ntuser.datNAME NOT FOUNDDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
142113:48:28.4229713MsMpEng.exe3220CreateFileC:\Windows\System32\config\systemprofile\ntuser.datNAME NOT FOUNDDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
142213:48:28.4230427MsMpEng.exe3220CreateFileC:\Windows\System32\config\systemprofileSUCCESSDesired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
142313:48:28.4230629MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\config\systemprofileBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
142413:48:28.4230704MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\config\systemprofileBUFFER OVERFLOWCreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D, AllocationSize: 0, EndOfFile: 0
142513:48:28.4231071MsMpEng.exe3220QueryDirectoryC:\Windows\System32\config\systemprofile\ntuser.datNO SUCH FILEFileInformationClass: FileIdFullDirectoryInformation, Filter: ntuser.dat
142613:48:28.4231256MsMpEng.exe3220CloseFileC:\Windows\System32\config\systemprofileSUCCESS
142713:48:28.4232891MsMpEng.exe3220CreateFileC:\Windows\System32\config\systemprofile\AppData\Local\VirtualStoreNAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
142813:48:28.4233149MsMpEng.exe3220RegCloseKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18SUCCESS
142913:48:28.4243416MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 524’288, Length: 524’288, Priority: Normal
143013:48:28.4244103MsMpEng.exe3220RegEnumKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSIndex: 1, Name: S-1-5-19
143113:48:28.4249018MsMpEng.exe3220RegQueryKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSQuery: HandleTags, HandleTags: 0x0
143213:48:28.4250263MsMpEng.exe3220RegOpenKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19SUCCESSDesired Access: Read
143313:48:28.4251111MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePathSUCCESSType: REG_EXPAND_SZ, Length: 84, Data: %systemroot%\ServiceProfiles\LocalService
143413:48:28.4253192MsMpEng.exe3220CreateFileC:\Windows\ServiceProfiles\LocalService\NTUSER.DATSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
143513:48:28.4253529MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Windows\ServiceProfiles\LocalService\NTUSER.DATSUCCESSCreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A
143613:48:28.4253621MsMpEng.exe3220CloseFileC:\Windows\ServiceProfiles\LocalService\NTUSER.DATSUCCESS
143713:48:28.4254391MsMpEng.exe3220CreateFileC:\Windows\ServiceProfiles\LocalService\NTUSER.DATSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
143813:48:28.4254585MsMpEng.exe3220QueryBasicInformationFileC:\Windows\ServiceProfiles\LocalService\NTUSER.DATSUCCESSCreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, FileAttributes: A
143913:48:28.4254748MsMpEng.exe3220CloseFileC:\Windows\ServiceProfiles\LocalService\NTUSER.DATSUCCESS
144013:48:28.4256222MsMpEng.exe3220CreateFileC:\Windows\ServiceProfiles\LocalService\AppData\Local\VirtualStoreNAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
144113:48:28.4256454MsMpEng.exe3220RegCloseKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19SUCCESS
144213:48:28.4257623MsMpEng.exe3220RegEnumKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSIndex: 2, Name: S-1-5-20
144313:48:28.4258432MsMpEng.exe3220RegQueryKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSQuery: HandleTags, HandleTags: 0x0
144413:48:28.4259287MsMpEng.exe3220RegOpenKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20SUCCESSDesired Access: Read
144513:48:28.4260427MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePathSUCCESSType: REG_EXPAND_SZ, Length: 88, Data: %systemroot%\ServiceProfiles\NetworkService
144613:48:28.4263013MsMpEng.exe3220CreateFileC:\Windows\ServiceProfiles\NetworkService\NTUSER.DATSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
144713:48:28.4263369MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Windows\ServiceProfiles\NetworkService\NTUSER.DATSUCCESSCreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A
144813:48:28.4263451MsMpEng.exe3220CloseFileC:\Windows\ServiceProfiles\NetworkService\NTUSER.DATSUCCESS
144913:48:28.4264220MsMpEng.exe3220CreateFileC:\Windows\ServiceProfiles\NetworkService\NTUSER.DATSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
145013:48:28.4264481MsMpEng.exe3220QueryBasicInformationFileC:\Windows\ServiceProfiles\NetworkService\NTUSER.DATSUCCESSCreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, FileAttributes: A
145113:48:28.4264585MsMpEng.exe3220CloseFileC:\Windows\ServiceProfiles\NetworkService\NTUSER.DATSUCCESS
145213:48:28.4265934MsMpEng.exe3220CreateFileC:\Windows\ServiceProfiles\NetworkService\AppData\Local\VirtualStoreNAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
145313:48:28.4266165MsMpEng.exe3220RegCloseKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20SUCCESS
145413:48:28.4266730MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 1’048’576, Length: 524’288, Priority: Normal
145513:48:28.4268823MsMpEng.exe3220RegEnumKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSIndex: 3, Name: S-1-5-21-4172013786-3171869251-2938521833-1000
145613:48:28.4269624MsMpEng.exe3220RegQueryKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESSQuery: HandleTags, HandleTags: 0x0
145713:48:28.4270477MsMpEng.exe3220RegOpenKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4172013786-3171869251-2938521833-1000SUCCESSDesired Access: Read
145813:48:28.4271583MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4172013786-3171869251-2938521833-1000\ProfileImagePathSUCCESSType: REG_EXPAND_SZ, Length: 32, Data: C:\Users\hacker
145913:48:28.4273472MsMpEng.exe3220CreateFileC:\Users\hacker\NTUSER.DATSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
146013:48:28.4273808MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Users\hacker\NTUSER.DATSUCCESSCreationTime: 12.08.2025 19:41:55, LastAccessTime: 13.10.2025 13:30:45, LastWriteTime: 13.10.2025 13:30:45, ChangeTime: 12.08.2025 19:41:55, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: HANCI
146113:48:28.4273875MsMpEng.exe3220CloseFileC:\Users\hacker\NTUSER.DATSUCCESS
146213:48:28.4275274MsMpEng.exe3220CreateFileC:\Users\hacker\NTUSER.DATSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
146313:48:28.4275571MsMpEng.exe3220QueryBasicInformationFileC:\Users\hacker\NTUSER.DATSUCCESSCreationTime: 12.08.2025 19:41:55, LastAccessTime: 13.10.2025 13:30:45, LastWriteTime: 13.10.2025 13:30:45, ChangeTime: 12.08.2025 19:41:55, FileAttributes: HANCI
146413:48:28.4275853MsMpEng.exe3220CloseFileC:\Users\hacker\NTUSER.DATSUCCESS
146513:48:28.4277164MsMpEng.exe3220CreateFileC:\Users\hacker\AppData\Local\VirtualStoreSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
146613:48:28.4277425MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Users\hacker\AppData\Local\VirtualStoreSUCCESSCreationTime: 12.08.2025 19:42:01, LastAccessTime: 13.10.2025 13:32:41, LastWriteTime: 12.08.2025 19:42:01, ChangeTime: 12.08.2025 19:42:01, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: D
146713:48:28.4277490MsMpEng.exe3220CloseFileC:\Users\hacker\AppData\Local\VirtualStoreSUCCESS
146813:48:28.4278028MsMpEng.exe3220RegCloseKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4172013786-3171869251-2938521833-1000SUCCESS
146913:48:28.4278821MsMpEng.exe3220RegCloseKeyHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListSUCCESS
147013:48:28.4279826MsMpEng.exe3220RegQueryKeyHKUSUCCESSQuery: HandleTags, HandleTags: 0x0
147113:48:28.4280614MsMpEng.exe3220RegOpenKeyHKU\S-1-5-18REPARSEDesired Access: Read
147213:48:28.4281164MsMpEng.exe3220RegOpenKeyHKU\.DEFAULTSUCCESSDesired Access: Read
147313:48:28.4282185MsMpEng.exe3220RegCloseKeyHKU\.DEFAULTSUCCESS
147413:48:28.4282944MsMpEng.exe3220RegQueryKeyHKUSUCCESSQuery: HandleTags, HandleTags: 0x0
147513:48:28.4283872MsMpEng.exe3220RegOpenKeyHKU\S-1-5-18REPARSEDesired Access: Read
147613:48:28.4285679MsMpEng.exe3220RegOpenKeyHKU\.DEFAULTSUCCESSDesired Access: Read
147713:48:28.4286557MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
147813:48:28.4287260MsMpEng.exe3220RegOpenKeyHKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSDesired Access: Read
147913:48:28.4287863MsMpEng.exe3220RegQueryKeyHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSQuery: Cached, SubKeys: 0, Values: 12
148013:48:28.4288690MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 0, Type: REG_SZ
148113:48:28.4289558MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Administrative ToolsBUFFER OVERFLOWLength: 144
148213:48:28.4290272MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Administrative ToolsSUCCESSType: REG_SZ, Length: 148, Data: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
148313:48:28.4290763MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 1, Type: REG_SZ
148413:48:28.4291735MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppDataSUCCESSType: REG_SZ, Length: 30, Data: C:\ProgramData
148513:48:28.4292670MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 2, Type: REG_SZ
148613:48:28.4293966MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common DesktopSUCCESSType: REG_SZ, Length: 48, Data: C:\Users\Public\Desktop
148713:48:28.4295015MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 3, Type: REG_SZ
148813:48:28.4295811MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common DocumentsSUCCESSType: REG_SZ, Length: 52, Data: C:\Users\Public\Documents
148913:48:28.4297692MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 4, Type: REG_SZ
149013:48:28.4299565MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common ProgramsSUCCESSType: REG_SZ, Length: 106, Data: C:\ProgramData\Microsoft\Windows\Start Menu\Programs
149113:48:28.4300556MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 5, Type: REG_SZ
149213:48:28.4301819MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Start MenuSUCCESSType: REG_SZ, Length: 88, Data: C:\ProgramData\Microsoft\Windows\Start Menu
149313:48:28.4302873MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 6, Type: REG_SZ
149413:48:28.4303502MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common StartupSUCCESSType: REG_SZ, Length: 122, Data: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
149513:48:28.4304065MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 7, Type: REG_SZ
149613:48:28.4304453MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common TemplatesSUCCESSType: REG_SZ, Length: 86, Data: C:\ProgramData\Microsoft\Windows\Templates
149713:48:28.4305291MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 8, Type: REG_SZ
149813:48:28.4305746MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonMusicSUCCESSType: REG_SZ, Length: 44, Data: C:\Users\Public\Music
149913:48:28.4306404MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 9, Type: REG_SZ
150013:48:28.4306780MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonPicturesSUCCESSType: REG_SZ, Length: 50, Data: C:\Users\Public\Pictures
150113:48:28.4307358MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 10, Type: REG_SZ
150213:48:28.4307971MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonVideoSUCCESSType: REG_SZ, Length: 46, Data: C:\Users\Public\Videos
150313:48:28.4308607MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 11, Type: REG_SZ
150413:48:28.4309026MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\OEM LinksSUCCESSType: REG_SZ, Length: 50, Data: C:\ProgramData\OEM\Links
150513:48:28.4309918MsMpEng.exe3220RegCloseKeyHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESS
150613:48:28.4310712MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
150713:48:28.4311488MsMpEng.exe3220RegOpenKeyHKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSDesired Access: Read
150813:48:28.4312410MsMpEng.exe3220RegQueryKeyHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSQuery: Cached, SubKeys: 1, Values: 11
150913:48:28.4313617MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 0, Type: REG_EXPAND_SZ
151013:48:28.4314059MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common AppDataSUCCESSType: REG_EXPAND_SZ, Length: 28, Data: %ProgramData%
151113:48:28.4314964MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 1, Type: REG_EXPAND_SZ
151213:48:28.4315793MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common DesktopSUCCESSType: REG_EXPAND_SZ, Length: 34, Data: %PUBLIC%\Desktop
151313:48:28.4316446MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 2, Type: REG_EXPAND_SZ
151413:48:28.4316960MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common DocumentsSUCCESSType: REG_EXPAND_SZ, Length: 38, Data: %PUBLIC%\Documents
151513:48:28.4317255MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 3, Type: REG_EXPAND_SZ
151613:48:28.4317660MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common ProgramsSUCCESSType: REG_EXPAND_SZ, Length: 104, Data: %ProgramData%\Microsoft\Windows\Start Menu\Programs
151713:48:28.4318276MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 4, Type: REG_EXPAND_SZ
151813:48:28.4318622MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Start MenuSUCCESSType: REG_EXPAND_SZ, Length: 86, Data: %ProgramData%\Microsoft\Windows\Start Menu
151913:48:28.4319047MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 5, Type: REG_EXPAND_SZ
152013:48:28.4319574MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common StartupSUCCESSType: REG_EXPAND_SZ, Length: 120, Data: %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup
152113:48:28.4320504MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 6, Type: REG_EXPAND_SZ
152213:48:28.4321108MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common TemplatesSUCCESSType: REG_EXPAND_SZ, Length: 84, Data: %ProgramData%\Microsoft\Windows\Templates
152313:48:28.4321768MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 7, Type: REG_EXPAND_SZ
152413:48:28.4322428MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonMusicSUCCESSType: REG_EXPAND_SZ, Length: 30, Data: %PUBLIC%\Music
152513:48:28.4323192MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 8, Type: REG_EXPAND_SZ
152613:48:28.4323704MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonPicturesSUCCESSType: REG_EXPAND_SZ, Length: 36, Data: %PUBLIC%\Pictures
152713:48:28.4324145MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 9, Type: REG_EXPAND_SZ
152813:48:28.4324526MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonVideoSUCCESSType: REG_EXPAND_SZ, Length: 32, Data: %PUBLIC%\Videos
152913:48:28.4325872MsMpEng.exe3220RegEnumValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 10, Type: REG_EXPAND_SZ
153013:48:28.4326543MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}SUCCESSType: REG_EXPAND_SZ, Length: 38, Data: %PUBLIC%\Downloads
153113:48:28.4327177MsMpEng.exe3220RegCloseKeyHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESS
153213:48:28.4329686MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
153313:48:28.4329878MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A
153413:48:28.4329947MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
153513:48:28.4330808MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
153613:48:28.4331008MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
153713:48:28.4331079MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
153813:48:28.4331154MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
153913:48:28.4331211MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
154013:48:28.4331609MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
154113:48:28.4331753MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
154213:48:28.4332059MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
154313:48:28.4332784MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
154413:48:28.4332948MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
154513:48:28.4333103MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
154613:48:28.4333380MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
154713:48:28.4333455MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
154813:48:28.4333560MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
154913:48:28.4333654MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
155013:48:28.4333878MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
155113:48:28.4334828MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
155213:48:28.4335090MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
155313:48:28.4335188MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
155413:48:28.4335268MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
155513:48:28.4335337MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
155613:48:28.4335411MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
155713:48:28.4336662MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
155813:48:28.4336931MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
155913:48:28.4337882MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
156013:48:28.4338155MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
156113:48:28.4338267MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
156213:48:28.4339536MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
156313:48:28.4339669MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A
156413:48:28.4339729MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
156513:48:28.4341558MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
156613:48:28.4341883MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
156713:48:28.4342808MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
156813:48:28.4343140MsMpEng.exe3220QueryBasicInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A
156913:48:28.4343208MsMpEng.exe3220QueryStandardInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSAllocationSize: 380’928, EndOfFile: 378’880, NumberOfLinks: 1, DeletePending: False, Directory: False
157013:48:28.4345916MsMpEng.exe3220CreateFileC:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\4F992D724B6D33EA543475A51B3D00E9NAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
157113:48:28.4346264MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 0, Length: 4’096, Priority: Normal
157213:48:28.4348375MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 372’736, Length: 6’144, Priority: Normal
157313:48:28.4348629MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 376’832, Length: 2’048, I/O Flags: Non-cached, Paging I/O, Priority: Normal
157413:48:28.4383576MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 1’572’864, Length: 524’288, Priority: Normal
157513:48:28.4403465MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 2’097’152, Length: 421’080, Priority: Normal
157613:48:28.4424770MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
157713:48:28.4425339MsMpEng.exe3220QueryEAFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
157813:48:28.4430154MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 0, Length: 4’096, Priority: Normal
157913:48:28.4436904MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 4’096, Length: 262’144, Priority: Normal
158013:48:28.4445385MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 266’240, Length: 258’048, Priority: Normal
158113:48:28.4449553MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 524’288, Length: 4’096, Priority: Normal
158213:48:28.4462681MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 528’384, Length: 262’144, Priority: Normal
158313:48:28.4490840MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 790’528, Length: 258’048, Priority: Normal
158413:48:28.4494464MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 1’048’576, Length: 4’096, Priority: Normal
158513:48:28.4515156MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 1’052’672, Length: 262’144, Priority: Normal
158613:48:28.4534980MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 1’314’816, Length: 258’048, Priority: Normal
158713:48:28.4548680MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 1’572’864, Length: 4’096, Priority: Normal
158813:48:28.4712170MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 1’576’960, Length: 262’144, Priority: Normal
158913:48:28.4717004MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 270’336, Length: 4’096, Priority: Normal
159013:48:28.4717113MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 270’336, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
159113:48:28.4754079MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 1’839’104, Length: 258’048, Priority: Normal
159213:48:28.4755787MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 2’097’152, Length: 4’096, Priority: Normal
159313:48:28.4756729MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 274’432, Length: 4’096, Priority: Normal
159413:48:28.4757056MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 274’432, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
159513:48:28.4782713MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 81’920, Length: 4’096, Priority: Normal
159613:48:28.4782805MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 81’920, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
159713:48:28.4799448MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 299’008, Length: 4’096, Priority: Normal
159813:48:28.4800188MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 266’240, Length: 8’192, Priority: Normal
159913:48:28.4800254MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 266’240, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
160013:48:28.4803941MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 184’320, Length: 8’192, Priority: Normal
160113:48:28.4805170MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 184’320, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal
160213:48:28.4811251MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 86’016, Length: 4’096, Priority: Normal
160313:48:28.4811442MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 86’016, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
160413:48:28.4814332MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 2’101’248, Length: 262’144, Priority: Normal
160513:48:28.4814413MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 258’048, Length: 8’192, Priority: Normal
160613:48:28.4814503MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 258’048, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal
160713:48:28.4829081MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 4’096, Length: 4’096, Priority: Normal
160813:48:28.4829172MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 4’096, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
160913:48:28.4844314MsMpEng.exe3220ReadFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSOffset: 2’363’392, Length: 147’456, Priority: Normal
161013:48:28.4847561MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 192’512, Length: 4’096, Priority: Normal
161113:48:28.4847635MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 192’512, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
161213:48:28.4907578MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 278’528, Length: 4’096, Priority: Normal
161313:48:28.4907659MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 278’528, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
161413:48:28.4909934MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 282’624, Length: 4’096, Priority: Normal
161513:48:28.4910086MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 282’624, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
161613:48:28.4914409MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 303’104, Length: 4’096, Priority: Normal
161713:48:28.4914889MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 307’200, Length: 8’192, Priority: Normal
161813:48:28.4914958MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 311’296, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
161913:48:28.4917225MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
162013:48:28.4997512MsMpEng.exe3220CreateFileC:\Windows\System32\grpconv.exeSUCCESSDesired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
162113:48:28.5004346MsMpEng.exe3220FileSystemControlC:\Windows\System32\grpconv.exeOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
162213:48:28.5005107MsMpEng.exe3220CreateFileC:\Windows\System32\grpconv.exeSUCCESSDesired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
162313:48:28.5005522MsMpEng.exe3220QueryEAFileC:\Windows\System32\grpconv.exeBUFFER OVERFLOW
162413:48:28.5005841MsMpEng.exe3220QueryEAFileC:\Windows\System32\grpconv.exeSUCCESS
162513:48:28.5005935MsMpEng.exe3220FileSystemControlC:\Windows\System32\grpconv.exeSUCCESSControl: FSCTL_QUERY_USN_JOURNAL
162613:48:28.5006036MsMpEng.exe3220CloseFileC:\Windows\System32\grpconv.exeSUCCESS
162713:48:28.5006223MsMpEng.exe3220CloseFileC:\Windows\System32\grpconv.exeSUCCESS
162813:48:28.5010695MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 286’720, Length: 12’288, Priority: Normal
162913:48:28.5010797MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 286’720, Length: 12’288, I/O Flags: Non-cached, Paging I/O, Priority: Normal
163013:48:28.5011187MsMpEng.exe3220QueryStreamInformationFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
163113:48:28.5011355MsMpEng.exe3220QueryEAFileC:\Windows\System32\drivers\NeacSafe64.sysNO EAS ON FILE
163213:48:28.5012298MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
163313:48:28.5012525MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
163413:48:28.5012596MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWCreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232
163513:48:28.5012676MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
163613:48:28.5012816MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\drivers\NeacSafe64.sysBUFFER OVERFLOWCreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232
163713:48:28.5012920MsMpEng.exe3220FileSystemControlC:\Windows\System32\drivers\NeacSafe64.sysSUCCESSControl: FSCTL_READ_FILE_USN_DATA
163813:48:28.5013032MsMpEng.exe3220QueryIdInformationC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
163913:48:28.5014134MsMpEng.exe3220QueryStreamInformationFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
164013:48:28.5014255MsMpEng.exe3220QueryIdInformationC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
164113:48:28.5015104MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
164213:48:28.5015555MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
164313:48:28.5015875MsMpEng.exe3220CloseFileC:\Windows\System32\drivers\NeacSafe64.sysSUCCESS
164413:48:28.5023434MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 90’112, Length: 16’384, Priority: Normal
164513:48:28.5023527MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 90’112, Length: 16’384, I/O Flags: Non-cached, Paging I/O, Priority: Normal
164613:48:28.5050418MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 180’224, Length: 4’096, Priority: Normal
164713:48:28.5050503MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 180’224, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
164813:48:28.5154011MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 122’880, Length: 8’192, Priority: Normal
164913:48:28.5154100MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 122’880, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal
165013:48:28.5157404MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 131’072, Length: 4’096, Priority: Normal
165113:48:28.5157490MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 131’072, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
165213:48:28.5216395MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 151’552, Length: 8’192, Priority: Normal
165313:48:28.5216482MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 151’552, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal
165413:48:28.5220309MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 159’744, Length: 4’096, Priority: Normal
165513:48:28.5220402MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 159’744, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
165613:48:28.5224797MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 118’784, Length: 8’192, Priority: Normal
165713:48:28.5224958MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 118’784, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
165813:48:28.5229576MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 135’168, Length: 8’192, Priority: Normal
165913:48:28.5229661MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 135’168, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal
166013:48:28.5233907MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 196’608, Length: 4’096, Priority: Normal
166113:48:28.5233984MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 196’608, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
166213:48:28.5816734MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 147’456, Length: 8’192, Priority: Normal
166313:48:28.5817915MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 147’456, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
166413:48:28.5859428MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
166513:48:28.5859767MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
166613:48:28.5861841MsMpEng.exe3220CreateFileC:\Windows\System32\dllhost.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
166713:48:28.5862274MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\dllhost.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
166813:48:28.5862526MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\dllhost.exeBUFFER OVERFLOWCreationTime: 06.09.2024 06:02:01, LastAccessTime: 13.10.2025 13:47:55, LastWriteTime: 06.09.2024 06:02:01, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 16’384, EndOfFile: 50’504
166913:48:28.5862732MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\dllhost.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
167013:48:28.5862836MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\dllhost.exeBUFFER OVERFLOWCreationTime: 06.09.2024 06:02:01, LastAccessTime: 13.10.2025 13:47:55, LastWriteTime: 06.09.2024 06:02:01, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 16’384, EndOfFile: 50’504
167113:48:28.5863043MsMpEng.exe3220FileSystemControlC:\Windows\System32\dllhost.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
167213:48:28.5863134MsMpEng.exe3220QueryIdInformationC:\Windows\System32\dllhost.exeSUCCESS
167313:48:28.5863462MsMpEng.exe3220CloseFileC:\Windows\System32\dllhost.exeSUCCESS
167413:48:28.5900437MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 143’360, Length: 8’192, Priority: Normal
167513:48:28.5900552MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 143’360, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
167613:48:28.5920450MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 176’128, Length: 8’192, Priority: Normal
167713:48:28.5920547MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 176’128, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
167813:48:28.5947811MsMpEng.exe3220CreateFileC:\Windows\System32\dllhost.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
167913:48:28.5948617MsMpEng.exe3220FileSystemControlC:\Windows\System32\dllhost.exeOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
168013:48:28.5948958MsMpEng.exe3220FileSystemControlC:\Windows\System32\dllhost.exeSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
168113:48:28.5949062MsMpEng.exe3220CloseFileC:\Windows\System32\dllhost.exeSUCCESS
168213:48:28.5950322MsMpEng.exe3220CreateFileC:\Windows\System32\ntdll.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
168313:48:28.5950735MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntdll.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
168413:48:28.5950857MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntdll.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
168513:48:28.5950943MsMpEng.exe3220CloseFileC:\Windows\System32\ntdll.dllSUCCESS
168613:48:28.5981343MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 167’936, Length: 8’192, Priority: Normal
168713:48:28.5981508MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 167’936, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal
168813:48:28.6070772MsMpEng.exe3220CreateFileC:\Windows\System32\kernel32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
168913:48:28.6071160MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
169013:48:28.6071286MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
169113:48:28.6071369MsMpEng.exe3220CloseFileC:\Windows\System32\kernel32.dllSUCCESS
169213:48:28.6121278MsMpEng.exe3220CreateFileC:\Windows\System32\KernelBase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
169313:48:28.6122298MsMpEng.exe3220FileSystemControlC:\Windows\System32\KernelBase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
169413:48:28.6122424MsMpEng.exe3220FileSystemControlC:\Windows\System32\KernelBase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
169513:48:28.6123531MsMpEng.exe3220CloseFileC:\Windows\System32\KernelBase.dllSUCCESS
169613:48:28.6129480MsMpEng.exe3220CreateFileC:\Windows\System32\ucrtbase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
169713:48:28.6129924MsMpEng.exe3220FileSystemControlC:\Windows\System32\ucrtbase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
169813:48:28.6130017MsMpEng.exe3220FileSystemControlC:\Windows\System32\ucrtbase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
169913:48:28.6130097MsMpEng.exe3220CloseFileC:\Windows\System32\ucrtbase.dllSUCCESS
170013:48:28.6132184MsMpEng.exe3220CreateFileC:\Windows\System32\combase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
170113:48:28.6132582MsMpEng.exe3220FileSystemControlC:\Windows\System32\combase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
170213:48:28.6132671MsMpEng.exe3220FileSystemControlC:\Windows\System32\combase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
170313:48:28.6132841MsMpEng.exe3220CloseFileC:\Windows\System32\combase.dllSUCCESS
170413:48:28.6136157MsMpEng.exe3220CreateFileC:\Windows\System32\rpcrt4.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
170513:48:28.6136602MsMpEng.exe3220FileSystemControlC:\Windows\System32\rpcrt4.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
170613:48:28.6136698MsMpEng.exe3220FileSystemControlC:\Windows\System32\rpcrt4.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
170713:48:28.6136777MsMpEng.exe3220CloseFileC:\Windows\System32\rpcrt4.dllSUCCESS
170813:48:28.6189603MsMpEng.exe3220CreateFileC:\Windows\System32\kernel.appcore.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
170913:48:28.6189920MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
171013:48:28.6190007MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
171113:48:28.6190193MsMpEng.exe3220CloseFileC:\Windows\System32\kernel.appcore.dllSUCCESS
171213:48:28.6193094MsMpEng.exe3220CreateFileC:\Windows\System32\msvcrt.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
171313:48:28.6193913MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
171413:48:28.6194041MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
171513:48:28.6194224MsMpEng.exe3220CloseFileC:\Windows\System32\msvcrt.dllSUCCESS
171613:48:28.6200416MsMpEng.exe3220CreateFileC:\Windows\System32\bcryptprimitives.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
171713:48:28.6200739MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcryptprimitives.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
171813:48:28.6200819MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcryptprimitives.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
171913:48:28.6200891MsMpEng.exe3220CloseFileC:\Windows\System32\bcryptprimitives.dllSUCCESS
172013:48:28.6212853MsMpEng.exe3220CreateFileC:\Windows\System32\clbcatq.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
172113:48:28.6213403MsMpEng.exe3220FileSystemControlC:\Windows\System32\clbcatq.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
172213:48:28.6213520MsMpEng.exe3220FileSystemControlC:\Windows\System32\clbcatq.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
172313:48:28.6213599MsMpEng.exe3220CloseFileC:\Windows\System32\clbcatq.dllSUCCESS
172413:48:28.6218875MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 8’192, Length: 4’096, Priority: Normal
172513:48:28.6219066MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 8’192, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
172613:48:28.6245301MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 49’152, Length: 8’192, Priority: Normal
172713:48:28.6245410MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 49’152, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal
172813:48:28.6250414MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 12’288, Length: 16’384, Priority: Normal
172913:48:28.6250541MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 12’288, Length: 16’384, I/O Flags: Non-cached, Paging I/O, Priority: Normal
173013:48:28.6256793MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 106’496, Length: 4’096, Priority: Normal
173113:48:28.6256954MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 106’496, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
173213:48:28.6300488MsMpEng.exe3220CreateFileC:\Windows\System32\sechost.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
173313:48:28.6300824MsMpEng.exe3220FileSystemControlC:\Windows\System32\sechost.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
173413:48:28.6300998MsMpEng.exe3220FileSystemControlC:\Windows\System32\sechost.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
173513:48:28.6301108MsMpEng.exe3220CloseFileC:\Windows\System32\sechost.dllSUCCESS
173613:48:28.6358922MsMpEng.exe3220CreateFileC:\Windows\System32\user32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
173713:48:28.6359349MsMpEng.exe3220FileSystemControlC:\Windows\System32\user32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
173813:48:28.6359469MsMpEng.exe3220FileSystemControlC:\Windows\System32\user32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
173913:48:28.6359549MsMpEng.exe3220CloseFileC:\Windows\System32\user32.dllSUCCESS
174013:48:28.6363891MsMpEng.exe3220CreateFileC:\Windows\System32\msvcp_win.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
174113:48:28.6364245MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp_win.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
174213:48:28.6364335MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp_win.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
174313:48:28.6364409MsMpEng.exe3220CloseFileC:\Windows\System32\msvcp_win.dllSUCCESS
174413:48:28.6366093MsMpEng.exe3220CreateFileC:\Windows\System32\win32u.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
174513:48:28.6366539MsMpEng.exe3220FileSystemControlC:\Windows\System32\win32u.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
174613:48:28.6366632MsMpEng.exe3220FileSystemControlC:\Windows\System32\win32u.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
174713:48:28.6366716MsMpEng.exe3220CloseFileC:\Windows\System32\win32u.dllSUCCESS
174813:48:28.6369623MsMpEng.exe3220CreateFileC:\Windows\System32\gdi32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
174913:48:28.6370018MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
175013:48:28.6370107MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
175113:48:28.6370179MsMpEng.exe3220CloseFileC:\Windows\System32\gdi32.dllSUCCESS
175213:48:28.6371212MsMpEng.exe3220CreateFileC:\Windows\System32\gdi32full.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
175313:48:28.6371417MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32full.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
175413:48:28.6371494MsMpEng.exe3220FileSystemControlC:\Windows\System32\gdi32full.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
175513:48:28.6371563MsMpEng.exe3220CloseFileC:\Windows\System32\gdi32full.dllSUCCESS
175613:48:28.6413040MsMpEng.exe3220CreateFileC:\Windows\System32\imm32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
175713:48:28.6413435MsMpEng.exe3220FileSystemControlC:\Windows\System32\imm32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
175813:48:28.6413543MsMpEng.exe3220FileSystemControlC:\Windows\System32\imm32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
175913:48:28.6413623MsMpEng.exe3220CloseFileC:\Windows\System32\imm32.dllSUCCESS
176013:48:28.6433909MsMpEng.exe3220CreateFileC:\Windows\System32\uxtheme.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
176113:48:28.6434593MsMpEng.exe3220FileSystemControlC:\Windows\System32\uxtheme.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
176213:48:28.6434799MsMpEng.exe3220FileSystemControlC:\Windows\System32\uxtheme.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
176313:48:28.6435026MsMpEng.exe3220CloseFileC:\Windows\System32\uxtheme.dllSUCCESS
176413:48:28.6563799MsMpEng.exe3220CreateFileC:\Windows\System32\thumbcache.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
176513:48:28.6564041MsMpEng.exe3220FileSystemControlC:\Windows\System32\thumbcache.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
176613:48:28.6564125MsMpEng.exe3220FileSystemControlC:\Windows\System32\thumbcache.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
176713:48:28.6564202MsMpEng.exe3220CloseFileC:\Windows\System32\thumbcache.dllSUCCESS
176813:48:28.6566489MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
176913:48:28.6566744MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
177013:48:28.6567824MsMpEng.exe3220CreateFileC:\Windows\System32\thumbcache.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
177113:48:28.6568138MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\thumbcache.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅾ
177213:48:28.6568215MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\thumbcache.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:26, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:26, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 249’856, EndOfFile: 460’176
177313:48:28.6568301MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\thumbcache.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅾ
177413:48:28.6568355MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\thumbcache.dllBUFFER OVERFLOWCreationTime: 30.09.2025 13:54:26, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:26, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 249’856, EndOfFile: 460’176
177513:48:28.6568436MsMpEng.exe3220FileSystemControlC:\Windows\System32\thumbcache.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
177613:48:28.6568586MsMpEng.exe3220QueryIdInformationC:\Windows\System32\thumbcache.dllSUCCESS
177713:48:28.6568792MsMpEng.exe3220CloseFileC:\Windows\System32\thumbcache.dllSUCCESS
177813:48:28.6625567MsMpEng.exe3220CreateFileC:\Windows\System32\propsys.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
177913:48:28.6626091MsMpEng.exe3220FileSystemControlC:\Windows\System32\propsys.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
178013:48:28.6626200MsMpEng.exe3220FileSystemControlC:\Windows\System32\propsys.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
178113:48:28.6626280MsMpEng.exe3220CloseFileC:\Windows\System32\propsys.dllSUCCESS
178213:48:28.6659004MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
178313:48:28.6659286MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
178413:48:28.6842378MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
178513:48:28.6842833MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
178613:48:28.6842958MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
178713:48:28.6843267MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
178813:48:28.6844439MsMpEng.exe3220CreateFileC:\Windows\System32\ntdll.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
178913:48:28.6844901MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntdll.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
179013:48:28.6845007MsMpEng.exe3220FileSystemControlC:\Windows\System32\ntdll.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
179113:48:28.6866075MsMpEng.exe3220CloseFileC:\Windows\System32\ntdll.dllSUCCESS
179213:48:28.6898340MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
179313:48:28.6898609MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
179413:48:28.6909623MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
179513:48:28.6909946MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
179613:48:28.6910272MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
179713:48:28.6910507MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 675’736, Length: 4’096
179813:48:28.6910773MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
179913:48:28.6910890MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
180013:48:28.6995947MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 77’824, Length: 8’192, Priority: Normal
180113:48:28.6996076MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 77’824, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal
180213:48:28.7001719MsMpEng.exe3220CreateFileC:\Windows\System32\kernel32.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
180313:48:28.7002146MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel32.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
180413:48:28.7002287MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel32.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
180513:48:28.7002369MsMpEng.exe3220CloseFileC:\Windows\System32\kernel32.dllSUCCESS
180613:48:28.7003416MsMpEng.exe3220CreateFileC:\Windows\System32\KernelBase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
180713:48:28.7003644MsMpEng.exe3220FileSystemControlC:\Windows\System32\KernelBase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
180813:48:28.7003721MsMpEng.exe3220FileSystemControlC:\Windows\System32\KernelBase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
180913:48:28.7003787MsMpEng.exe3220CloseFileC:\Windows\System32\KernelBase.dllSUCCESS
181013:48:28.7036676MsMpEng.exe3220CreateFileC:\Windows\System32\ucrtbase.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
181113:48:28.7037841MsMpEng.exe3220FileSystemControlC:\Windows\System32\ucrtbase.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
181213:48:28.7038049MsMpEng.exe3220FileSystemControlC:\Windows\System32\ucrtbase.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
181313:48:28.7038133MsMpEng.exe3220CloseFileC:\Windows\System32\ucrtbase.dllSUCCESS
181413:48:28.7075571MsMpEng.exe3220CreateFileC:\Windows\System32\msvcp140.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
181513:48:28.7076064MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp140.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
181613:48:28.7076191MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp140.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
181713:48:28.7076271MsMpEng.exe3220CloseFileC:\Windows\System32\msvcp140.dllSUCCESS
181813:48:28.7078366MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
181913:48:28.7078541MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
182013:48:28.7080516MsMpEng.exe3220CreateFileC:\Windows\System32\msvcp140.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
182113:48:28.7080833MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\msvcp140.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
182213:48:28.7080951MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\msvcp140.dllBUFFER OVERFLOWCreationTime: 11.06.2025 05:21:56, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:56, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 561’152, EndOfFile: 557’728
182313:48:28.7081031MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\msvcp140.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
182413:48:28.7081083MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\msvcp140.dllBUFFER OVERFLOWCreationTime: 11.06.2025 05:21:56, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:56, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 561’152, EndOfFile: 557’728
182513:48:28.7081175MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcp140.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
182613:48:28.7081348MsMpEng.exe3220QueryIdInformationC:\Windows\System32\msvcp140.dllSUCCESS
182713:48:28.7081504MsMpEng.exe3220CloseFileC:\Windows\System32\msvcp140.dllSUCCESS
182813:48:28.7084358MsMpEng.exe3220CreateFileC:\Windows\System32\vcruntime140.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
182913:48:28.7084673MsMpEng.exe3220FileSystemControlC:\Windows\System32\vcruntime140.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
183013:48:28.7084759MsMpEng.exe3220FileSystemControlC:\Windows\System32\vcruntime140.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
183113:48:28.7084831MsMpEng.exe3220CloseFileC:\Windows\System32\vcruntime140.dllSUCCESS
183213:48:28.7086279MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
183313:48:28.7086543MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
183413:48:28.7089639MsMpEng.exe3220CreateFileC:\Windows\System32\vcruntime140.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
183513:48:28.7089869MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\vcruntime140.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
183613:48:28.7090026MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\vcruntime140.dllBUFFER OVERFLOWCreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:04:34, FileAttributes: A, AllocationSize: 126’976, EndOfFile: 124’544
183713:48:28.7090163MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\vcruntime140.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
183813:48:28.7090222MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\vcruntime140.dllBUFFER OVERFLOWCreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:04:34, FileAttributes: A, AllocationSize: 126’976, EndOfFile: 124’544
183913:48:28.7090296MsMpEng.exe3220FileSystemControlC:\Windows\System32\vcruntime140.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
184013:48:28.7090383MsMpEng.exe3220QueryIdInformationC:\Windows\System32\vcruntime140.dllSUCCESS
184113:48:28.7090514MsMpEng.exe3220CloseFileC:\Windows\System32\vcruntime140.dllSUCCESS
184213:48:28.7093326MsMpEng.exe3220CreateFileC:\Windows\System32\vcruntime140_1.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
184313:48:28.7093662MsMpEng.exe3220FileSystemControlC:\Windows\System32\vcruntime140_1.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
184413:48:28.7093815MsMpEng.exe3220FileSystemControlC:\Windows\System32\vcruntime140_1.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
184513:48:28.7093894MsMpEng.exe3220CloseFileC:\Windows\System32\vcruntime140_1.dllSUCCESS
184613:48:28.7095300MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
184713:48:28.7095431MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
184813:48:28.7096549MsMpEng.exe3220CreateFileC:\Windows\System32\vcruntime140_1.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
184913:48:28.7097119MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\vcruntime140_1.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
185013:48:28.7097224MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\vcruntime140_1.dllBUFFER OVERFLOWCreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 49’792
185113:48:28.7097395MsMpEng.exe3220QueryInformationVolumeC:\Windows\System32\vcruntime140_1.dllBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
185213:48:28.7097472MsMpEng.exe3220QueryAllInformationFileC:\Windows\System32\vcruntime140_1.dllBUFFER OVERFLOWCreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 49’792
185313:48:28.7097553MsMpEng.exe3220FileSystemControlC:\Windows\System32\vcruntime140_1.dllSUCCESSControl: FSCTL_READ_FILE_USN_DATA
185413:48:28.7097652MsMpEng.exe3220QueryIdInformationC:\Windows\System32\vcruntime140_1.dllSUCCESS
185513:48:28.7097785MsMpEng.exe3220CloseFileC:\Windows\System32\vcruntime140_1.dllSUCCESS
185613:48:28.7132480MsMpEng.exe3220Thread CreateSUCCESSThread ID: 7424
185713:48:28.7136831MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
185813:48:28.7137169MsMpEng.exe3220QueryBasicInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESSCreationTime: 10.10.2025 15:34:53, LastAccessTime: 13.10.2025 13:27:12, LastWriteTime: 13.10.2025 11:45:59, ChangeTime: 13.10.2025 11:45:59, FileAttributes: A
185913:48:28.7137235MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESS
186013:48:28.7137960MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESSDesired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
186113:48:28.7138149MsMpEng.exe3220CreateFileMappingC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllFILE LOCKED WITH ONLY READERSSyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE
186213:48:28.7139295MsMpEng.exe3220QueryEAFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESS
186313:48:28.7139676MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESSOffset: 46’080, Length: 12’288, I/O Flags: Non-cached, Paging I/O, Priority: Normal
186413:48:28.7140155MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESSOffset: 153’088, Length: 45’056, I/O Flags: Non-cached, Paging I/O, Priority: Normal
186513:48:28.7146151MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
186613:48:28.7146334MsMpEng.exe3220QueryBasicInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSCreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A
186713:48:28.7146598MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
186813:48:28.7149542MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
186913:48:28.7149905MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
187013:48:28.7149994MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWCreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184
187113:48:28.7150074MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
187213:48:28.7150132MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWCreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184
187313:48:28.7150305MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
187413:48:28.7150408MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
187513:48:28.7150544MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
187613:48:28.7151310MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
187713:48:28.7151659MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
187813:48:28.7151768MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWCreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184
187913:48:28.7151861MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
188013:48:28.7151914MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWCreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184
188113:48:28.7151998MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
188213:48:28.7152173MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
188313:48:28.7152292MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
188413:48:28.7153061MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
188513:48:28.7153490MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
188613:48:28.7153616MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWCreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184
188713:48:28.7153696MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
188813:48:28.7153752MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWCreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184
188913:48:28.7153961MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
189013:48:28.7154069MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
189113:48:28.7154236MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
189213:48:28.7155815MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
189313:48:28.7156119MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
189413:48:28.7156222MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
189513:48:28.7156390MsMpEng.exe3220QueryStandardInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESSAllocationSize: 241’664, EndOfFile: 240’128, NumberOfLinks: 1, DeletePending: False, Directory: False
189613:48:28.7156578MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllINVALID DEVICE REQUESTControl: 0x90390 (Device:0x9 Function:228 Method: 0)
189713:48:28.7156678MsMpEng.exe3220QueryAttributeInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESSFileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS
189813:48:28.7161664MsMpEng.exe3220QueryEAFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESS
189913:48:28.7163940MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
190013:48:28.7164226MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
190113:48:28.7164830MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWCreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184
190213:48:28.7165135MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
190313:48:28.7165240MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeBUFFER OVERFLOWCreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184
190413:48:28.7165336MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
190513:48:28.7165420MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
190613:48:28.7166074MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
190713:48:28.7193027MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ
190813:48:28.7193162MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
190913:48:28.7193270MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
191013:48:28.7194074MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
191113:48:28.7194339MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 222’536, Length: 4’096
191213:48:28.7194587MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 86’576, Length: 4’096
191313:48:28.7194836MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 700’456, Length: 4’096
191413:48:28.7195263MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
191513:48:28.7196113MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 28’672, Length: 350’208, Priority: Normal
191613:48:28.7196377MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 28’672, Length: 344’064, I/O Flags: Non-cached, Paging I/O, Priority: Normal
191713:48:28.7205235MsMpEng.exe3220RegOpenKeyHKLM\Software\Microsoft\Windows\CurrentVersion\SetupSUCCESSDesired Access: Read
191813:48:28.7205392MsMpEng.exe3220RegQueryValueHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\MinimizeFootprintNAME NOT FOUNDLength: 20
191913:48:28.7205696MsMpEng.exe3220RegCloseKeyHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SetupSUCCESS
192013:48:28.7205905MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllINVALID DEVICE REQUESTControl: 0x90390 (Device:0x9 Function:228 Method: 0)
192113:48:28.7206014MsMpEng.exe3220QueryAttributeInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESSFileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS
192213:48:28.7212630MsMpEng.exe3220QueryStandardInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESSAllocationSize: 241’664, EndOfFile: 240’128, NumberOfLinks: 1, DeletePending: False, Directory: False
192313:48:28.7213481MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllINVALID DEVICE REQUESTControl: 0x90390 (Device:0x9 Function:228 Method: 0)
192413:48:28.7213990MsMpEng.exe3220QueryAttributeInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESSFileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS
192513:48:28.7218911MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
192613:48:28.7218980MsMpEng.exe3220QueryEAFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESS
192713:48:28.7230054MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllINVALID DEVICE REQUESTControl: 0x90390 (Device:0x9 Function:228 Method: 0)
192813:48:28.7230162MsMpEng.exe3220QueryAttributeInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESSFileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS
192913:48:28.7238717MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dllSUCCESS
193013:48:28.7239752MsMpEng.exe3220Thread ExitSUCCESSThread ID: 7424, User Time: 0.0000000, Kernel Time: 0.0000000
193113:48:28.7241532MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
193213:48:28.7241967MsMpEng.exe3220QueryBasicInformationFileC:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESSCreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D
193313:48:28.7242057MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESS
193413:48:28.7243988MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
193513:48:28.7244757MsMpEng.exe3220QueryBasicInformationFileC:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESSCreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI
193613:48:28.7244921MsMpEng.exe3220CloseFileC:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESS
193713:48:28.7247909MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2SUCCESSDesired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
193813:48:28.7248278MsMpEng.exe3220QueryDirectoryC:\Windows\System32\catroot2\{????????????????????????????????????}SUCCESSFileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}
193913:48:28.7250488MsMpEng.exe3220CreateFileC:\Windows\System32\CatRootNAME COLLISIONDesired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
194013:48:28.7252960MsMpEng.exe3220CreateFileC:\Windows\System32\CatRootSUCCESSDesired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
194113:48:28.7253216MsMpEng.exe3220QuerySecurityFileC:\Windows\System32\CatRootSUCCESSInformation: DACL
194213:48:28.7253306MsMpEng.exe3220CloseFileC:\Windows\System32\CatRootSUCCESS
194313:48:28.7254538MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2NAME COLLISIONDesired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
194413:48:28.7258632MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2SUCCESSDesired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
194513:48:28.7258887MsMpEng.exe3220QuerySecurityFileC:\Windows\System32\catroot2SUCCESSInformation: DACL
194613:48:28.7258979MsMpEng.exe3220CloseFileC:\Windows\System32\catroot2SUCCESS
194713:48:28.7259076MsMpEng.exe3220CreateFileC:\Windows\System32\kernel.appcore.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
194813:48:28.7259496MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
194913:48:28.7259638MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
195013:48:28.7259728MsMpEng.exe3220CloseFileC:\Windows\System32\kernel.appcore.dllSUCCESS
195113:48:28.7260887MsMpEng.exe3220CreateFileC:\Windows\System32\msvcrt.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
195213:48:28.7261202MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
195313:48:28.7261376MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
195413:48:28.7261461MsMpEng.exe3220CloseFileC:\Windows\System32\msvcrt.dllSUCCESS
195513:48:28.7266267MsMpEng.exe3220QueryDirectoryC:\Windows\System32\catroot2SUCCESSFileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}
195613:48:28.7267873MsMpEng.exe3220CreateFileC:\Windows\System32\CatRootNAME COLLISIONDesired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
195713:48:28.7268679MsMpEng.exe3220CreateFileC:\Windows\System32\CatRootSUCCESSDesired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
195813:48:28.7268898MsMpEng.exe3220QuerySecurityFileC:\Windows\System32\CatRootSUCCESSInformation: DACL
195913:48:28.7268982MsMpEng.exe3220CloseFileC:\Windows\System32\CatRootSUCCESS
196013:48:28.7270382MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2NAME COLLISIONDesired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
196113:48:28.7272135MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2SUCCESSDesired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
196213:48:28.7272541MsMpEng.exe3220QuerySecurityFileC:\Windows\System32\catroot2SUCCESSInformation: DACL
196313:48:28.7272669MsMpEng.exe3220CloseFileC:\Windows\System32\catroot2SUCCESS
196413:48:28.7281850MsMpEng.exe3220QueryDirectoryC:\Windows\System32\catroot2NO MORE FILESFileInformationClass: FileBothDirectoryInformation
196513:48:28.7282154MsMpEng.exe3220CloseFileC:\Windows\System32\catroot2SUCCESS
196613:48:28.7283620MsMpEng.exe3220CreateFileC:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
196713:48:28.7283798MsMpEng.exe3220QueryBasicInformationFileC:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESSCreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D
196813:48:28.7283967MsMpEng.exe3220CloseFileC:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESS
196913:48:28.7285158MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
197013:48:28.7285332MsMpEng.exe3220QueryBasicInformationFileC:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESSCreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI
197113:48:28.7285405MsMpEng.exe3220CloseFileC:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}SUCCESS
197213:48:28.7286659MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2SUCCESSDesired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
197313:48:28.7287031MsMpEng.exe3220QueryDirectoryC:\Windows\System32\catroot2\{????????????????????????????????????}SUCCESSFileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}
197413:48:28.7288092MsMpEng.exe3220CreateFileC:\Windows\System32\CatRootNAME COLLISIONDesired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
197513:48:28.7289418MsMpEng.exe3220CreateFileC:\Windows\System32\CatRootSUCCESSDesired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
197613:48:28.7289649MsMpEng.exe3220QuerySecurityFileC:\Windows\System32\CatRootSUCCESSInformation: DACL
197713:48:28.7289830MsMpEng.exe3220CloseFileC:\Windows\System32\CatRootSUCCESS
197813:48:28.7290740MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2NAME COLLISIONDesired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
197913:48:28.7294544MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2SUCCESSDesired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
198013:48:28.7294795MsMpEng.exe3220QuerySecurityFileC:\Windows\System32\catroot2SUCCESSInformation: DACL
198113:48:28.7295194MsMpEng.exe3220CloseFileC:\Windows\System32\catroot2SUCCESS
198213:48:28.7297893MsMpEng.exe3220QueryDirectoryC:\Windows\System32\catroot2SUCCESSFileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}
198313:48:28.7299503MsMpEng.exe3220CreateFileC:\Windows\System32\CatRootNAME COLLISIONDesired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
198413:48:28.7300319MsMpEng.exe3220CreateFileC:\Windows\System32\CatRootSUCCESSDesired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
198513:48:28.7300500MsMpEng.exe3220QuerySecurityFileC:\Windows\System32\CatRootSUCCESSInformation: DACL
198613:48:28.7300712MsMpEng.exe3220CloseFileC:\Windows\System32\CatRootSUCCESS
198713:48:28.7302044MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2NAME COLLISIONDesired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
198813:48:28.7303356MsMpEng.exe3220CreateFileC:\Windows\System32\catroot2SUCCESSDesired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
198913:48:28.7303686MsMpEng.exe3220QuerySecurityFileC:\Windows\System32\catroot2SUCCESSInformation: DACL
199013:48:28.7303775MsMpEng.exe3220CloseFileC:\Windows\System32\catroot2SUCCESS
199113:48:28.7315119MsMpEng.exe3220QueryDirectoryC:\Windows\System32\catroot2NO MORE FILESFileInformationClass: FileBothDirectoryInformation
199213:48:28.7315303MsMpEng.exe3220CloseFileC:\Windows\System32\catroot2SUCCESS
199313:48:28.7316001MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
199413:48:28.7317051MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
199513:48:28.7317283MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 45’376, Length: 4’096
199613:48:28.7317708MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
199713:48:28.7318043MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
199813:48:28.7318144MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 181’336, Length: 4’096
199913:48:28.7318359MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
200013:48:28.7318589MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
200113:48:28.7318657MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: True, Offset: 120, Length: 1, Fail Immediately: True
200213:48:28.7319331MsMpEng.exe3220WriteFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 856’992, Length: 24
200313:48:28.7319481MsMpEng.exe3220WriteFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 857’016, Length: 4’096
200413:48:28.7319793MsMpEng.exe3220WriteFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 861’112, Length: 24
200513:48:28.7319887MsMpEng.exe3220WriteFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 861’136, Length: 4’096
200613:48:28.7320071MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 120, Length: 1
200713:48:28.7320148MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
200813:48:28.7323135MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
200913:48:28.7323495MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
201013:48:28.7351906MsMpEng.exe3220QueryStreamInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
201113:48:28.7352136MsMpEng.exe3220QueryEAFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeNO EAS ON FILE
201213:48:28.7357756MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
201313:48:28.7357981MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
201413:48:28.7359235MsMpEng.exe3220RegCloseKeyHKU\.DEFAULTSUCCESS
201513:48:28.7360628MsMpEng.exe3220CreateFileC:\Windows\System32\drivers\SET9BED.tmpNAME NOT FOUNDDesired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
201613:48:28.7361289MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
201713:48:28.7361395MsMpEng.exe3220RegOpenKeyHKLM\SYSTEM\CurrentControlSet\Control\hivelistREPARSEDesired Access: Read
201813:48:28.7361504MsMpEng.exe3220RegOpenKeyHKLM\System\CurrentControlSet\Control\hivelistSUCCESSDesired Access: Read
201913:48:28.7361645MsMpEng.exe3220RegQueryKeyHKLM\System\CurrentControlSet\Control\hivelistSUCCESSQuery: Cached, SubKeys: 0, Values: 35
202013:48:28.7361817MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 0, Type: REG_SZ
202113:48:28.7361917MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\HARDWARESUCCESSType: REG_SZ, Length: 2, Data:
202213:48:28.7362029MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 1, Type: REG_SZ
202313:48:28.7362091MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SOFTWARESUCCESSType: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SOFTWARE
202413:48:28.7362173MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 2, Type: REG_SZ
202513:48:28.7362226MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SYSTEMSUCCESSType: REG_SZ, Length: 112, Data: \Device\HarddiskVolume4\Windows\System32\config\SYSTEM
202613:48:28.7362296MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 3, Type: REG_SZ
202713:48:28.7362428MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\BCD00000000SUCCESSType: REG_SZ, Length: 96, Data: \Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD
202813:48:28.7362550MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 4, Type: REG_SZ
202913:48:28.7362607MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\.DEFAULTSUCCESSType: REG_SZ, Length: 114, Data: \Device\HarddiskVolume4\Windows\System32\config\DEFAULT
203013:48:28.7362782MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 5, Type: REG_SZ
203113:48:28.7362838MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SECURITYSUCCESSType: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SECURITY
203213:48:28.7362914MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 6, Type: REG_SZ
203313:48:28.7363063MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SAMSUCCESSType: REG_SZ, Length: 106, Data: \Device\HarddiskVolume4\Windows\System32\config\SAM
203413:48:28.7363142MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 7, Type: REG_SZ
203513:48:28.7363197MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20BUFFER OVERFLOWLength: 144
203613:48:28.7363437MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20SUCCESSType: REG_SZ, Length: 150, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
203713:48:28.7363651MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 8, Type: REG_SZ
203813:48:28.7363736MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19BUFFER OVERFLOWLength: 144
203913:48:28.7363808MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19SUCCESSType: REG_SZ, Length: 146, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\LocalService\NTUSER.DAT
204013:48:28.7363907MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 9, Type: REG_SZ
204113:48:28.7363969MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000SUCCESSType: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT
204213:48:28.7364096MsMpEng.exe3220RegQueryKeyHKUSUCCESSQuery: HandleTags, HandleTags: 0x0
204313:48:28.7364235MsMpEng.exe3220RegOpenKeyHKCUSUCCESSDesired Access: Read
204413:48:28.7364379MsMpEng.exe3220RegCloseKeyHKLM\System\CurrentControlSet\Control\hivelistSUCCESS
204513:48:28.7364664MsMpEng.exe3220RegQueryKeyHKCUSUCCESSQuery: HandleTags, HandleTags: 0x0
204613:48:28.7364866MsMpEng.exe3220RegOpenKeyHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSDesired Access: Read
204713:48:28.7365361MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppDataSUCCESSType: REG_EXPAND_SZ, Length: 56, Data: %USERPROFILE%\AppData\Local
204813:48:28.7365535MsMpEng.exe3220RegCloseKeyHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESS
204913:48:28.7365765MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
205013:48:28.7365866MsMpEng.exe3220RegOpenKeyHKLM\SYSTEM\CurrentControlSet\Control\hivelistREPARSEDesired Access: Read
205113:48:28.7365964MsMpEng.exe3220RegOpenKeyHKLM\System\CurrentControlSet\Control\hivelistSUCCESSDesired Access: Read
205213:48:28.7366071MsMpEng.exe3220RegQueryKeyHKLM\System\CurrentControlSet\Control\hivelistSUCCESSQuery: Cached, SubKeys: 0, Values: 35
205313:48:28.7366182MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 0, Type: REG_SZ
205413:48:28.7366435MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\HARDWARESUCCESSType: REG_SZ, Length: 2, Data:
205513:48:28.7366549MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 1, Type: REG_SZ
205613:48:28.7366675MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SOFTWARESUCCESSType: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SOFTWARE
205713:48:28.7366792MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 2, Type: REG_SZ
205813:48:28.7366858MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SYSTEMSUCCESSType: REG_SZ, Length: 112, Data: \Device\HarddiskVolume4\Windows\System32\config\SYSTEM
205913:48:28.7366926MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 3, Type: REG_SZ
206013:48:28.7367133MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\BCD00000000SUCCESSType: REG_SZ, Length: 96, Data: \Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD
206113:48:28.7367285MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 4, Type: REG_SZ
206213:48:28.7367630MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\.DEFAULTSUCCESSType: REG_SZ, Length: 114, Data: \Device\HarddiskVolume4\Windows\System32\config\DEFAULT
206313:48:28.7368103MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 5, Type: REG_SZ
206413:48:28.7368282MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SECURITYSUCCESSType: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SECURITY
206513:48:28.7368407MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 6, Type: REG_SZ
206613:48:28.7368468MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SAMSUCCESSType: REG_SZ, Length: 106, Data: \Device\HarddiskVolume4\Windows\System32\config\SAM
206713:48:28.7368549MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 7, Type: REG_SZ
206813:48:28.7368603MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20BUFFER OVERFLOWLength: 144
206913:48:28.7368747MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20SUCCESSType: REG_SZ, Length: 150, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
207013:48:28.7368898MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 8, Type: REG_SZ
207113:48:28.7368959MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19BUFFER OVERFLOWLength: 144
207213:48:28.7369027MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19SUCCESSType: REG_SZ, Length: 146, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\LocalService\NTUSER.DAT
207313:48:28.7369121MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 9, Type: REG_SZ
207413:48:28.7369183MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000SUCCESSType: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT
207513:48:28.7369276MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistBUFFER OVERFLOWIndex: 10, Length: 144
207613:48:28.7369408MsMpEng.exe3220RegEnumValueHKLM\System\CurrentControlSet\Control\hivelistSUCCESSIndex: 10, Type: REG_SZ
207713:48:28.7370464MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_ClassesBUFFER OVERFLOWLength: 144
207813:48:28.7370642MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_ClassesSUCCESSType: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat
207913:48:28.7370973MsMpEng.exe3220RegQueryKeyHKUSUCCESSQuery: HandleTags, HandleTags: 0x0
208013:48:28.7371065MsMpEng.exe3220RegOpenKeyHKCU\Software\ClassesSUCCESSDesired Access: Read
208113:48:28.7371213MsMpEng.exe3220RegCloseKeyHKLM\System\CurrentControlSet\Control\hivelistSUCCESS
208213:48:28.7371423MsMpEng.exe3220RegQueryKeyHKCUSUCCESSQuery: HandleTags, HandleTags: 0x0
208313:48:28.7371523MsMpEng.exe3220RegOpenKeyHKCU\EnvironmentSUCCESSDesired Access: Read
208413:48:28.7371638MsMpEng.exe3220RegQueryKeyHKCU\EnvironmentSUCCESSQuery: Cached, SubKeys: 0, Values: 4
208513:48:28.7371713MsMpEng.exe3220RegEnumValueHKCU\EnvironmentSUCCESSIndex: 0, Type: REG_EXPAND_SZ
208613:48:28.7371785MsMpEng.exe3220RegQueryValueHKCU\Environment\PathBUFFER OVERFLOWLength: 144
208713:48:28.7371873MsMpEng.exe3220RegQueryValueHKCU\Environment\PathSUCCESSType: REG_EXPAND_SZ, Length: 156, Data:
208813:48:28.7372078MsMpEng.exe3220RegEnumValueHKCU\EnvironmentSUCCESSIndex: 1, Type: REG_EXPAND_SZ
208913:48:28.7372155MsMpEng.exe3220RegQueryValueHKCU\Environment\TEMPSUCCESSType: REG_EXPAND_SZ, Length: 66, Data: %USERPROFILE%\AppData\Local\Temp
209013:48:28.7372286MsMpEng.exe3220RegEnumValueHKCU\EnvironmentSUCCESSIndex: 2, Type: REG_EXPAND_SZ
209113:48:28.7372340MsMpEng.exe3220RegQueryValueHKCU\Environment\TMPSUCCESSType: REG_EXPAND_SZ, Length: 66, Data: %USERPROFILE%\AppData\Local\Temp
209213:48:28.7372429MsMpEng.exe3220RegEnumValueHKCU\EnvironmentSUCCESSIndex: 3, Type: REG_EXPAND_SZ
209313:48:28.7372484MsMpEng.exe3220RegQueryValueHKCU\Environment\OneDriveSUCCESSType: REG_EXPAND_SZ, Length: 50, Data: C:\Users\hacker\OneDrive
209413:48:28.7372658MsMpEng.exe3220RegCloseKeyHKCU\EnvironmentSUCCESS
209513:48:28.7372761MsMpEng.exe3220RegQueryKeyHKCUSUCCESSQuery: HandleTags, HandleTags: 0x0
209613:48:28.7372831MsMpEng.exe3220RegOpenKeyHKCU\Volatile EnvironmentSUCCESSDesired Access: Read
209713:48:28.7372942MsMpEng.exe3220RegQueryKeyHKCU\Volatile EnvironmentSUCCESSQuery: Cached, SubKeys: 1, Values: 9
209813:48:28.7373007MsMpEng.exe3220RegEnumValueHKCU\Volatile EnvironmentSUCCESSIndex: 0, Type: REG_SZ
209913:48:28.7373073MsMpEng.exe3220RegQueryValueHKCU\Volatile Environment\LOGONSERVERSUCCESSType: REG_SZ, Length: 24, Data: \\WINDOWS11
210013:48:28.7373233MsMpEng.exe3220RegEnumValueHKCU\Volatile EnvironmentSUCCESSIndex: 1, Type: REG_SZ
210113:48:28.7373304MsMpEng.exe3220RegQueryValueHKCU\Volatile Environment\USERDOMAINSUCCESSType: REG_SZ, Length: 20, Data: WINDOWS11
210213:48:28.7373403MsMpEng.exe3220RegEnumValueHKCU\Volatile EnvironmentSUCCESSIndex: 2, Type: REG_SZ
210313:48:28.7373459MsMpEng.exe3220RegQueryValueHKCU\Volatile Environment\USERNAMESUCCESSType: REG_SZ, Length: 14, Data: hacker
210413:48:28.7373543MsMpEng.exe3220RegEnumValueHKCU\Volatile EnvironmentSUCCESSIndex: 3, Type: REG_SZ
210513:48:28.7373596MsMpEng.exe3220RegQueryValueHKCU\Volatile Environment\USERPROFILESUCCESSType: REG_SZ, Length: 32, Data: C:\Users\hacker
210613:48:28.7373675MsMpEng.exe3220RegEnumValueHKCU\Volatile EnvironmentSUCCESSIndex: 4, Type: REG_SZ
210713:48:28.7373729MsMpEng.exe3220RegQueryValueHKCU\Volatile Environment\HOMEPATHSUCCESSType: REG_SZ, Length: 28, Data: \Users\hacker
210813:48:28.7373876MsMpEng.exe3220RegEnumValueHKCU\Volatile EnvironmentSUCCESSIndex: 5, Type: REG_SZ
210913:48:28.7373954MsMpEng.exe3220RegQueryValueHKCU\Volatile Environment\HOMEDRIVESUCCESSType: REG_SZ, Length: 6, Data: C:
211013:48:28.7374048MsMpEng.exe3220RegEnumValueHKCU\Volatile EnvironmentSUCCESSIndex: 6, Type: REG_SZ
211113:48:28.7374602MsMpEng.exe3220RegQueryValueHKCU\Volatile Environment\APPDATASUCCESSType: REG_SZ, Length: 64, Data: C:\Users\hacker\AppData\Roaming
211213:48:28.7374867MsMpEng.exe3220RegEnumValueHKCU\Volatile EnvironmentSUCCESSIndex: 7, Type: REG_SZ
211313:48:28.7374960MsMpEng.exe3220RegQueryValueHKCU\Volatile Environment\LOCALAPPDATASUCCESSType: REG_SZ, Length: 60, Data: C:\Users\hacker\AppData\Local
211413:48:28.7375067MsMpEng.exe3220RegEnumValueHKCU\Volatile EnvironmentSUCCESSIndex: 8, Type: REG_SZ
211513:48:28.7375128MsMpEng.exe3220RegQueryValueHKCU\Volatile Environment\USERDOMAIN_ROAMINGPROFILESUCCESSType: REG_SZ, Length: 20, Data: WINDOWS11
211613:48:28.7375255MsMpEng.exe3220RegCloseKeyHKCU\Volatile EnvironmentSUCCESS
211713:48:28.7375356MsMpEng.exe3220RegQueryKeyHKCUSUCCESSQuery: HandleTags, HandleTags: 0x0
211813:48:28.7375514MsMpEng.exe3220RegOpenKeyHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSDesired Access: Read
211913:48:28.7375801MsMpEng.exe3220RegQueryKeyHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSQuery: Cached, SubKeys: 0, Values: 31
212013:48:28.7375873MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 0, Type: REG_SZ
212113:48:28.7375941MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\!Do not use this registry keySUCCESSType: REG_SZ, Length: 130, Data: Use the SHGetFolderPath or SHGetKnownFolderPath function instead
212213:48:28.7376117MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 1, Type: REG_SZ
212313:48:28.7376185MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\AppDataSUCCESSType: REG_SZ, Length: 64, Data: C:\Users\hacker\AppData\Roaming
212413:48:28.7376286MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 2, Type: REG_SZ
212513:48:28.7376346MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Local AppDataSUCCESSType: REG_SZ, Length: 60, Data: C:\Users\hacker\AppData\Local
212613:48:28.7376426MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 3, Type: REG_SZ
212713:48:28.7376482MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CD BurningSUCCESSType: REG_SZ, Length: 116, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\Burn\Burn
212813:48:28.7376562MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 4, Type: REG_SZ
212913:48:28.7376682MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}SUCCESSType: REG_SZ, Length: 120, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Libraries
213013:48:28.7376787MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 5, Type: REG_SZ
213113:48:28.7376842MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My VideoSUCCESSType: REG_SZ, Length: 46, Data: C:\Users\hacker\Videos
213213:48:28.7376922MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 6, Type: REG_SZ
213313:48:28.7376975MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My PicturesSUCCESSType: REG_SZ, Length: 50, Data: C:\Users\hacker\Pictures
213413:48:28.7377062MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 7, Type: REG_SZ
213513:48:28.7377114MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\DesktopSUCCESSType: REG_SZ, Length: 48, Data: C:\Users\hacker\Desktop
213613:48:28.7377189MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 8, Type: REG_SZ
213713:48:28.7377296MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\HistorySUCCESSType: REG_SZ, Length: 112, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\History
213813:48:28.7377399MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 9, Type: REG_SZ
213913:48:28.7377453MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\NetHoodBUFFER OVERFLOWLength: 144
214013:48:28.7377519MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\NetHoodSUCCESSType: REG_SZ, Length: 136, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Network Shortcuts
214113:48:28.7377597MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 10, Type: REG_SZ
214213:48:28.7377654MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{56784854-C6CB-462B-8169-88E350ACB882}SUCCESSType: REG_SZ, Length: 50, Data: C:\Users\hacker\Contacts
214313:48:28.7377739MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 11, Type: REG_SZ
214413:48:28.7377795MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{00BCFC5A-ED94-4E48-96A1-3F6217F21990}SUCCESSType: REG_SZ, Length: 122, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\RoamingTiles
214513:48:28.7377938MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 12, Type: REG_SZ
214613:48:28.7378002MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CookiesSUCCESSType: REG_SZ, Length: 120, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\INetCookies
214713:48:28.7378085MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 13, Type: REG_SZ
214813:48:28.7378138MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\FavoritesSUCCESSType: REG_SZ, Length: 52, Data: C:\Users\hacker\Favorites
214913:48:28.7378216MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 14, Type: REG_SZ
215013:48:28.7378268MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\SendToSUCCESSType: REG_SZ, Length: 114, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\SendTo
215113:48:28.7378341MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 15, Type: REG_SZ
215213:48:28.7378394MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Start MenuSUCCESSType: REG_SZ, Length: 122, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu
215313:48:28.7378543MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 16, Type: REG_SZ
215413:48:28.7378605MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My MusicSUCCESSType: REG_SZ, Length: 44, Data: C:\Users\hacker\Music
215513:48:28.7378687MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 17, Type: REG_SZ
215613:48:28.7378739MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ProgramsBUFFER OVERFLOWLength: 144
215713:48:28.7378805MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ProgramsSUCCESSType: REG_SZ, Length: 140, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
215813:48:28.7378882MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 18, Type: REG_SZ
215913:48:28.7378936MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\RecentSUCCESSType: REG_SZ, Length: 114, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Recent
216013:48:28.7379012MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 19, Type: REG_SZ
216113:48:28.7379117MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\PrintHoodBUFFER OVERFLOWLength: 144
216213:48:28.7379201MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\PrintHoodSUCCESSType: REG_SZ, Length: 136, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
216313:48:28.7379285MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 20, Type: REG_SZ
216413:48:28.7379342MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}SUCCESSType: REG_SZ, Length: 50, Data: C:\Users\hacker\Searches
216513:48:28.7379433MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 21, Type: REG_SZ
216613:48:28.7379487MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{374DE290-123F-4565-9164-39C4925E467B}SUCCESSType: REG_SZ, Length: 52, Data: C:\Users\hacker\Downloads
216713:48:28.7379572MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 22, Type: REG_SZ
216813:48:28.7379625MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{A520A1A4-1780-4FF6-BD18-167343C5AF16}SUCCESSType: REG_SZ, Length: 66, Data: C:\Users\hacker\AppData\LocalLow
216913:48:28.7379771MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 23, Type: REG_SZ
217013:48:28.7379832MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\StartupBUFFER OVERFLOWLength: 144
217113:48:28.7379912MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\StartupSUCCESSType: REG_SZ, Length: 156, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
217213:48:28.7379995MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 24, Type: REG_SZ
217313:48:28.7380049MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Administrative ToolsBUFFER OVERFLOWLength: 144
217413:48:28.7380114MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Administrative ToolsSUCCESSType: REG_SZ, Length: 182, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
217513:48:28.7380196MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 25, Type: REG_SZ
217613:48:28.7380250MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\PersonalSUCCESSType: REG_SZ, Length: 52, Data: C:\Users\hacker\Documents
217713:48:28.7380396MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 26, Type: REG_SZ
217813:48:28.7380457MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}SUCCESSType: REG_SZ, Length: 44, Data: C:\Users\hacker\Links
217913:48:28.7380544MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 27, Type: REG_SZ
218013:48:28.7380596MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CacheSUCCESSType: REG_SZ, Length: 116, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\INetCache
218113:48:28.7380692MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 28, Type: REG_SZ
218213:48:28.7380745MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\TemplatesSUCCESSType: REG_SZ, Length: 120, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Templates
218313:48:28.7380821MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 29, Type: REG_SZ
218413:48:28.7380931MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}SUCCESSType: REG_SZ, Length: 56, Data: C:\Users\hacker\Saved Games
218513:48:28.7381039MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESSIndex: 30, Type: REG_SZ
218613:48:28.7381096MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\FontsSUCCESSType: REG_SZ, Length: 34, Data: C:\WINDOWS\Fonts
218713:48:28.7381198MsMpEng.exe3220RegCloseKeyHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSUCCESS
218813:48:28.7381281MsMpEng.exe3220RegQueryKeyHKCUSUCCESSQuery: HandleTags, HandleTags: 0x0
218913:48:28.7381357MsMpEng.exe3220RegOpenKeyHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSDesired Access: Read
219013:48:28.7381460MsMpEng.exe3220RegQueryKeyHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSQuery: Cached, SubKeys: 0, Values: 20
219113:48:28.7381591MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 0, Type: REG_EXPAND_SZ
219213:48:28.7381665MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppDataSUCCESSType: REG_EXPAND_SZ, Length: 60, Data: %USERPROFILE%\AppData\Roaming
219313:48:28.7381763MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 1, Type: REG_EXPAND_SZ
219413:48:28.7381819MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CacheSUCCESSType: REG_EXPAND_SZ, Length: 112, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCache
219513:48:28.7382524MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 2, Type: REG_EXPAND_SZ
219613:48:28.7382629MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CookiesSUCCESSType: REG_EXPAND_SZ, Length: 116, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCookies
219713:48:28.7382839MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 3, Type: REG_EXPAND_SZ
219813:48:28.7382909MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\DesktopSUCCESSType: REG_EXPAND_SZ, Length: 44, Data: %USERPROFILE%\Desktop
219913:48:28.7383003MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 4, Type: REG_EXPAND_SZ
220013:48:28.7383057MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\FavoritesSUCCESSType: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Favorites
220113:48:28.7383137MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 5, Type: REG_EXPAND_SZ
220213:48:28.7383190MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\HistorySUCCESSType: REG_EXPAND_SZ, Length: 108, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\History
220313:48:28.7383272MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 6, Type: REG_EXPAND_SZ
220413:48:28.7383395MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppDataSUCCESSType: REG_EXPAND_SZ, Length: 56, Data: %USERPROFILE%\AppData\Local
220513:48:28.7383514MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 7, Type: REG_EXPAND_SZ
220613:48:28.7383579MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My MusicSUCCESSType: REG_EXPAND_SZ, Length: 40, Data: %USERPROFILE%\Music
220713:48:28.7383658MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 8, Type: REG_EXPAND_SZ
220813:48:28.7383712MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My PicturesSUCCESSType: REG_EXPAND_SZ, Length: 46, Data: %USERPROFILE%\Pictures
220913:48:28.7383789MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 9, Type: REG_EXPAND_SZ
221013:48:28.7383841MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My VideoSUCCESSType: REG_EXPAND_SZ, Length: 42, Data: %USERPROFILE%\Videos
221113:48:28.7384017MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 10, Type: REG_EXPAND_SZ
221213:48:28.7384099MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\NetHoodSUCCESSType: REG_EXPAND_SZ, Length: 132, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts
221313:48:28.7384197MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 11, Type: REG_EXPAND_SZ
221413:48:28.7384259MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\PersonalSUCCESSType: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Documents
221513:48:28.7384359MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 12, Type: REG_EXPAND_SZ
221613:48:28.7384416MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\PrintHoodSUCCESSType: REG_EXPAND_SZ, Length: 132, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
221713:48:28.7384642MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 13, Type: REG_EXPAND_SZ
221813:48:28.7384819MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\ProgramsBUFFER OVERFLOWLength: 144
221913:48:28.7384906MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\ProgramsSUCCESSType: REG_EXPAND_SZ, Length: 136, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
222013:48:28.7384996MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 14, Type: REG_EXPAND_SZ
222113:48:28.7385051MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\RecentSUCCESSType: REG_EXPAND_SZ, Length: 110, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent
222213:48:28.7385153MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 15, Type: REG_EXPAND_SZ
222313:48:28.7385290MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\SendToSUCCESSType: REG_EXPAND_SZ, Length: 110, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo
222413:48:28.7385503MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 16, Type: REG_EXPAND_SZ
222513:48:28.7385676MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Start MenuSUCCESSType: REG_EXPAND_SZ, Length: 118, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu
222613:48:28.7385903MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 17, Type: REG_EXPAND_SZ
222713:48:28.7385996MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\StartupBUFFER OVERFLOWLength: 144
222813:48:28.7386083MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\StartupSUCCESSType: REG_EXPAND_SZ, Length: 152, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
222913:48:28.7386167MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 18, Type: REG_EXPAND_SZ
223013:48:28.7386223MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\TemplatesSUCCESSType: REG_EXPAND_SZ, Length: 116, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates
223113:48:28.7386305MsMpEng.exe3220RegEnumValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESSIndex: 19, Type: REG_EXPAND_SZ
223213:48:28.7386527MsMpEng.exe3220RegQueryValueHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{374DE290-123F-4565-9164-39C4925E467B}SUCCESSType: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Downloads
223313:48:28.7386664MsMpEng.exe3220RegCloseKeyHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSUCCESS
223413:48:28.7386807MsMpEng.exe3220RegCloseKeyHKCUSUCCESS
223513:48:28.7387061MsMpEng.exe3220RegCloseKeyHKCU\Software\ClassesSUCCESS
223613:48:28.7387344MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
223713:48:28.7387561MsMpEng.exe3220RegOpenKeyHKLM\SYSTEM\CurrentControlSet\Control\hivelistREPARSEDesired Access: Read
223813:48:28.7387762MsMpEng.exe3220RegOpenKeyHKLM\System\CurrentControlSet\Control\hivelistSUCCESSDesired Access: Read
223913:48:28.7387889MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000SUCCESSType: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT
224013:48:28.7388415MsMpEng.exe3220RegQueryKeyHKUSUCCESSQuery: HandleTags, HandleTags: 0x0
224113:48:28.7388895MsMpEng.exe3220RegOpenKeyHKCUSUCCESSDesired Access: Read
224213:48:28.7389065MsMpEng.exe3220RegCloseKeyHKLM\System\CurrentControlSet\Control\hivelistSUCCESS
224313:48:28.7389145MsMpEng.exe3220RegQueryKeyHKLMSUCCESSQuery: HandleTags, HandleTags: 0x0
224413:48:28.7389211MsMpEng.exe3220RegOpenKeyHKLM\SYSTEM\CurrentControlSet\Control\hivelistREPARSEDesired Access: Read
224513:48:28.7389293MsMpEng.exe3220RegOpenKeyHKLM\System\CurrentControlSet\Control\hivelistSUCCESSDesired Access: Read
224613:48:28.7389381MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_ClassesBUFFER OVERFLOWLength: 144
224713:48:28.7389843MsMpEng.exe3220RegQueryValueHKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_ClassesSUCCESSType: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat
224813:48:28.7390375MsMpEng.exe3220RegQueryKeyHKUSUCCESSQuery: HandleTags, HandleTags: 0x0
224913:48:28.7390918MsMpEng.exe3220RegOpenKeyHKCU\Software\ClassesSUCCESSDesired Access: Read
225013:48:28.7391128MsMpEng.exe3220RegCloseKeyHKLM\System\CurrentControlSet\Control\hivelistSUCCESS
225113:48:28.7393535MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
225213:48:28.7393842MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
225313:48:28.7394502MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
225413:48:28.7394850MsMpEng.exe3220QueryBasicInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A
225513:48:28.7394935MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 0, Length: 512, Priority: Normal
225613:48:28.7395081MsMpEng.exe3220QueryStandardInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSAllocationSize: 380’928, EndOfFile: 378’880, NumberOfLinks: 1, DeletePending: False, Directory: False
225713:48:28.7395335MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 0, Length: 64, Priority: Normal
225813:48:28.7395904MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 272, Length: 28, Priority: Normal
225913:48:28.7396358MsMpEng.exe3220ReadFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSOffset: 0, Length: 4’096, Priority: Normal
226013:48:28.7397768MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
226113:48:28.7398065MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
226213:48:28.7399169MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
226313:48:28.7399524MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
226413:48:28.7400261MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
226513:48:28.7400669MsMpEng.exe3220DeviceIoControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
226613:48:28.7400735MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
226713:48:28.7401629MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeNOT A DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a
226813:48:28.7402399MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
226913:48:28.7403014MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
227013:48:28.7403201MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
227113:48:28.7403289MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESS
227213:48:28.7404410MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
227313:48:28.7404587MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESS
227413:48:28.7406256MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
227513:48:28.7406784MsMpEng.exe3220DeviceIoControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
227613:48:28.7406900MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESS
227713:48:28.7407828MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
227813:48:28.7408331MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
227913:48:28.7408465MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESS
228013:48:28.7409301MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpersIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
228113:48:28.7410086MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
228213:48:28.7411956MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpersNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
228313:48:28.7412144MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESS
228413:48:28.7413168MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
228513:48:28.7413549MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESS
228613:48:28.7414419MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
228713:48:28.7414673MsMpEng.exe3220DeviceIoControlC:\Users\hacker\source\repos\EDR-Introspection\helpersINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
228813:48:28.7414760MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESS
228913:48:28.7415551MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
229013:48:28.7416005MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpersNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
229113:48:28.7416211MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESS
229213:48:28.7417197MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-IntrospectionIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
229313:48:28.7417880MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
229413:48:28.7418063MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-IntrospectionNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
229513:48:28.7418250MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESS
229613:48:28.7418960MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
229713:48:28.7419122MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESS
229813:48:28.7419790MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
229913:48:28.7420146MsMpEng.exe3220DeviceIoControlC:\Users\hacker\source\repos\EDR-IntrospectionINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
230013:48:28.7420344MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESS
230113:48:28.7421119MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
230213:48:28.7421403MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-IntrospectionNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
230313:48:28.7421495MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESS
230413:48:28.7422778MsMpEng.exe3220CreateFileC:\Users\hacker\source\reposIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
230513:48:28.7423534MsMpEng.exe3220CreateFileC:\Users\hacker\source\reposSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
230613:48:28.7423819MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\reposNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
230713:48:28.7423912MsMpEng.exe3220CloseFileC:\Users\hacker\source\reposSUCCESS
230813:48:28.7424634MsMpEng.exe3220CreateFileC:\Users\hacker\source\reposSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
230913:48:28.7424789MsMpEng.exe3220CloseFileC:\Users\hacker\source\reposSUCCESS
231013:48:28.7425914MsMpEng.exe3220CreateFileC:\Users\hacker\source\reposSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
231113:48:28.7426246MsMpEng.exe3220DeviceIoControlC:\Users\hacker\source\reposINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
231213:48:28.7426316MsMpEng.exe3220CloseFileC:\Users\hacker\source\reposSUCCESS
231313:48:28.7427065MsMpEng.exe3220CreateFileC:\Users\hacker\source\reposSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
231413:48:28.7427267MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\reposNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
231513:48:28.7427491MsMpEng.exe3220CloseFileC:\Users\hacker\source\reposSUCCESS
231613:48:28.7428650MsMpEng.exe3220CreateFileC:\Users\hacker\sourceIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
231713:48:28.7431174MsMpEng.exe3220CreateFileC:\Users\hacker\sourceSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
231813:48:28.7431884MsMpEng.exe3220FileSystemControlC:\Users\hacker\sourceNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
231913:48:28.7432054MsMpEng.exe3220CloseFileC:\Users\hacker\sourceSUCCESS
232013:48:28.7432834MsMpEng.exe3220CreateFileC:\Users\hacker\sourceSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
232113:48:28.7433079MsMpEng.exe3220CloseFileC:\Users\hacker\sourceSUCCESS
232213:48:28.7434197MsMpEng.exe3220CreateFileC:\Users\hacker\sourceSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
232313:48:28.7434633MsMpEng.exe3220DeviceIoControlC:\Users\hacker\sourceINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
232413:48:28.7434707MsMpEng.exe3220CloseFileC:\Users\hacker\sourceSUCCESS
232513:48:28.7435491MsMpEng.exe3220CreateFileC:\Users\hacker\sourceSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
232613:48:28.7435834MsMpEng.exe3220FileSystemControlC:\Users\hacker\sourceNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
232713:48:28.7435928MsMpEng.exe3220CloseFileC:\Users\hacker\sourceSUCCESS
232813:48:28.7436667MsMpEng.exe3220CreateFileC:\Users\hackerIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
232913:48:28.7437296MsMpEng.exe3220CreateFileC:\Users\hackerSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
233013:48:28.7437566MsMpEng.exe3220FileSystemControlC:\Users\hackerNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
233113:48:28.7437655MsMpEng.exe3220CloseFileC:\Users\hackerSUCCESS
233213:48:28.7438820MsMpEng.exe3220CreateFileC:\Users\hackerSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
233313:48:28.7439112MsMpEng.exe3220CloseFileC:\Users\hackerSUCCESS
233413:48:28.7439786MsMpEng.exe3220CreateFileC:\Users\hackerSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
233513:48:28.7440009MsMpEng.exe3220DeviceIoControlC:\Users\hackerINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
233613:48:28.7440072MsMpEng.exe3220CloseFileC:\Users\hackerSUCCESS
233713:48:28.7441213MsMpEng.exe3220CreateFileC:\Users\hackerSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
233813:48:28.7441415MsMpEng.exe3220FileSystemControlC:\Users\hackerNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
233913:48:28.7441503MsMpEng.exe3220CloseFileC:\Users\hackerSUCCESS
234013:48:28.7442189MsMpEng.exe3220CreateFileC:\UsersIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
234113:48:28.7442821MsMpEng.exe3220CreateFileC:\UsersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
234213:48:28.7443100MsMpEng.exe3220FileSystemControlC:\UsersNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
234313:48:28.7443190MsMpEng.exe3220CloseFileC:\UsersSUCCESS
234413:48:28.7443851MsMpEng.exe3220CreateFileC:\UsersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
234513:48:28.7444010MsMpEng.exe3220CloseFileC:\UsersSUCCESS
234613:48:28.7444651MsMpEng.exe3220CreateFileC:\UsersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
234713:48:28.7444979MsMpEng.exe3220DeviceIoControlC:\UsersINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
234813:48:28.7445042MsMpEng.exe3220CloseFileC:\UsersSUCCESS
234913:48:28.7445867MsMpEng.exe3220CreateFileC:\UsersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
235013:48:28.7446136MsMpEng.exe3220FileSystemControlC:\UsersNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
235113:48:28.7446228MsMpEng.exe3220CloseFileC:\UsersSUCCESS
235213:48:28.7446965MsMpEng.exe3220CreateFileC:\SUCCESSDesired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
235313:48:28.7447232MsMpEng.exe3220QueryNameInformationFileC:\SUCCESSName: \
235413:48:28.7447412MsMpEng.exe3220QueryAttributeInformationVolumeC:\SUCCESSFileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS
235513:48:28.7447503MsMpEng.exe3220CloseFileC:\SUCCESS
235613:48:28.7448286MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
235713:48:28.7448610MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
235813:48:28.7449587MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
235913:48:28.7449876MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
236013:48:28.7450919MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
236113:48:28.7451194MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
236213:48:28.7451909MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
236313:48:28.7452145MsMpEng.exe3220DeviceIoControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
236413:48:28.7452207MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
236513:48:28.7452865MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeNOT A DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a
236613:48:28.7455915MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
236713:48:28.7457070MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
236813:48:28.7457267MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
236913:48:28.7457357MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESS
237013:48:28.7458159MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
237113:48:28.7458344MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESS
237213:48:28.7459025MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
237313:48:28.7459539MsMpEng.exe3220DeviceIoControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
237413:48:28.7459874MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESS
237513:48:28.7460974MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
237613:48:28.7461214MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
237713:48:28.7461298MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDUSUCCESS
237813:48:28.7462148MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpersIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
237913:48:28.7462754MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
238013:48:28.7463001MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpersNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
238113:48:28.7463091MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESS
238213:48:28.7463756MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
238313:48:28.7463986MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESS
238413:48:28.7464606MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
238513:48:28.7464834MsMpEng.exe3220DeviceIoControlC:\Users\hacker\source\repos\EDR-Introspection\helpersINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
238613:48:28.7464895MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESS
238713:48:28.7465545MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
238813:48:28.7465893MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpersNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
238913:48:28.7465975MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpersSUCCESS
239013:48:28.7466621MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-IntrospectionIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
239113:48:28.7467212MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
239213:48:28.7467361MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-IntrospectionNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
239313:48:28.7467436MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESS
239413:48:28.7468348MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
239513:48:28.7468582MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESS
239613:48:28.7469527MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
239713:48:28.7469822MsMpEng.exe3220DeviceIoControlC:\Users\hacker\source\repos\EDR-IntrospectionINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
239813:48:28.7469907MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESS
239913:48:28.7473531MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
240013:48:28.7473887MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-IntrospectionNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
240113:48:28.7474173MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-IntrospectionSUCCESS
240213:48:28.7475161MsMpEng.exe3220CreateFileC:\Users\hacker\source\reposIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
240313:48:28.7475951MsMpEng.exe3220CreateFileC:\Users\hacker\source\reposSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
240413:48:28.7476136MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\reposNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
240513:48:28.7476230MsMpEng.exe3220CloseFileC:\Users\hacker\source\reposSUCCESS
240613:48:28.7476888MsMpEng.exe3220CreateFileC:\Users\hacker\source\reposSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
240713:48:28.7477161MsMpEng.exe3220CloseFileC:\Users\hacker\source\reposSUCCESS
240813:48:28.7478065MsMpEng.exe3220CreateFileC:\Users\hacker\source\reposSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
240913:48:28.7479147MsMpEng.exe3220DeviceIoControlC:\Users\hacker\source\reposINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
241013:48:28.7479226MsMpEng.exe3220CloseFileC:\Users\hacker\source\reposSUCCESS
241113:48:28.7480143MsMpEng.exe3220CreateFileC:\Users\hacker\source\reposSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
241213:48:28.7480356MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\reposNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
241313:48:28.7480442MsMpEng.exe3220CloseFileC:\Users\hacker\source\reposSUCCESS
241413:48:28.7481137MsMpEng.exe3220CreateFileC:\Users\hacker\sourceIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
241513:48:28.7481771MsMpEng.exe3220CreateFileC:\Users\hacker\sourceSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
241613:48:28.7482053MsMpEng.exe3220FileSystemControlC:\Users\hacker\sourceNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
241713:48:28.7482138MsMpEng.exe3220CloseFileC:\Users\hacker\sourceSUCCESS
241813:48:28.7482801MsMpEng.exe3220CreateFileC:\Users\hacker\sourceSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
241913:48:28.7482961MsMpEng.exe3220CloseFileC:\Users\hacker\sourceSUCCESS
242013:48:28.7484759MsMpEng.exe3220CreateFileC:\Users\hacker\sourceSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
242113:48:28.7485050MsMpEng.exe3220DeviceIoControlC:\Users\hacker\sourceINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
242213:48:28.7485120MsMpEng.exe3220CloseFileC:\Users\hacker\sourceSUCCESS
242313:48:28.7486166MsMpEng.exe3220CreateFileC:\Users\hacker\sourceSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
242413:48:28.7486382MsMpEng.exe3220FileSystemControlC:\Users\hacker\sourceNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
242513:48:28.7486567MsMpEng.exe3220CloseFileC:\Users\hacker\sourceSUCCESS
242613:48:28.7487301MsMpEng.exe3220CreateFileC:\Users\hackerIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
242713:48:28.7487954MsMpEng.exe3220CreateFileC:\Users\hackerSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
242813:48:28.7488132MsMpEng.exe3220FileSystemControlC:\Users\hackerNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
242913:48:28.7488219MsMpEng.exe3220CloseFileC:\Users\hackerSUCCESS
243013:48:28.7488854MsMpEng.exe3220CreateFileC:\Users\hackerSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
243113:48:28.7491222MsMpEng.exe3220CloseFileC:\Users\hackerSUCCESS
243213:48:28.7492076MsMpEng.exe3220CreateFileC:\Users\hackerSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
243313:48:28.7492327MsMpEng.exe3220DeviceIoControlC:\Users\hackerINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
243413:48:28.7492391MsMpEng.exe3220CloseFileC:\Users\hackerSUCCESS
243513:48:28.7493034MsMpEng.exe3220CreateFileC:\Users\hackerSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
243613:48:28.7493268MsMpEng.exe3220FileSystemControlC:\Users\hackerNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
243713:48:28.7493377MsMpEng.exe3220CloseFileC:\Users\hackerSUCCESS
243813:48:28.7496489MsMpEng.exe3220CreateFileC:\UsersIS DIRECTORYDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
243913:48:28.7497192MsMpEng.exe3220CreateFileC:\UsersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
244013:48:28.7497489MsMpEng.exe3220FileSystemControlC:\UsersNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
244113:48:28.7497581MsMpEng.exe3220CloseFileC:\UsersSUCCESS
244213:48:28.7498255MsMpEng.exe3220CreateFileC:\UsersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
244313:48:28.7498500MsMpEng.exe3220CloseFileC:\UsersSUCCESS
244413:48:28.7499186MsMpEng.exe3220CreateFileC:\UsersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
244513:48:28.7499437MsMpEng.exe3220DeviceIoControlC:\UsersINVALID PARAMETERControl: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
244613:48:28.7499503MsMpEng.exe3220CloseFileC:\UsersSUCCESS
244713:48:28.7500475MsMpEng.exe3220CreateFileC:\UsersSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
244813:48:28.7500661MsMpEng.exe3220FileSystemControlC:\UsersNOT REPARSE POINTControl: FSCTL_GET_REPARSE_POINT
244913:48:28.7500749MsMpEng.exe3220CloseFileC:\UsersSUCCESS
245013:48:28.7501453MsMpEng.exe3220CreateFileC:\SUCCESSDesired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Free Space Query, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened
245113:48:28.7501729MsMpEng.exe3220QuerySizeInformationVolumeC:\SUCCESSTotalAllocationUnits: 20’646’655, AvailableAllocationUnits: 5’331’773, SectorsPerAllocationUnit: 8, BytesPerSector: 512
245213:48:28.7501804MsMpEng.exe3220CloseFileC:\SUCCESS
245313:48:28.7502491MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
245413:48:28.7502770MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
245513:48:28.7503784MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: True, Offset: 124, Length: 1, Fail Immediately: True
245613:48:28.7503877MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
245713:48:28.7504024MsMpEng.exe3220LockFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSExclusive: False, Offset: 124, Length: 1, Fail Immediately: True
245813:48:28.7504179MsMpEng.exe3220ReadFileC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-walSUCCESSOffset: 82’456, Length: 4’096
245913:48:28.7504428MsMpEng.exe3220UnlockFileSingleC:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shmSUCCESSOffset: 124, Length: 1
246013:48:28.7506266MsMpEng.exe3220CreateFileC:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\4F992D724B6D33EA543475A51B3D00E9NAME NOT FOUNDDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
246113:48:28.7506805MsMpEng.exe3220RegCloseKeyHKCUSUCCESS
246213:48:28.7507667MsMpEng.exe3220RegCloseKeyHKCU\Software\ClassesSUCCESS
246313:48:28.7511378MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
246413:48:28.7511747MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
246513:48:28.7511923MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
246613:48:28.7512035MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
246713:48:28.7512088MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
246813:48:28.7512164MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
246913:48:28.7512261MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
247013:48:28.7512435MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
247113:48:28.7513327MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
247213:48:28.7513516MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
247313:48:28.7513829MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
247413:48:28.7513945MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ
247513:48:28.7513998MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
247613:48:28.7514115MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
247713:48:28.7514198MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
247813:48:28.7514434MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
247913:48:28.7515235MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
248013:48:28.7515468MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: WinÄ
248113:48:28.7515724MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
248213:48:28.7515815MsMpEng.exe3220QueryInformationVolumeC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWVolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ
248313:48:28.7515869MsMpEng.exe3220QueryAllInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeBUFFER OVERFLOWCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880
248413:48:28.7515937MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
248513:48:28.7516014MsMpEng.exe3220QueryIdInformationC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
248613:48:28.7516203MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
248713:48:28.7517666MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
248813:48:28.7517917MsMpEng.exe3220FileSystemControlC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSControl: FSCTL_READ_FILE_USN_DATA
248913:48:28.7518120MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
249013:48:28.7520298MsMpEng.exe3220RegQueryKeyHKUSUCCESSQuery: HandleTags, HandleTags: 0x0
249113:48:28.7520408MsMpEng.exe3220RegOpenKeyHKU\S-1-5-18REPARSEDesired Access: Read
249213:48:28.7520507MsMpEng.exe3220RegOpenKeyHKU\.DEFAULTSUCCESSDesired Access: Read
249313:48:28.7520730MsMpEng.exe3220RegCloseKeyHKU\.DEFAULTSUCCESS
249413:48:28.7520835MsMpEng.exe3220RegQueryKeyHKUSUCCESSQuery: HandleTags, HandleTags: 0x0
249513:48:28.7520898MsMpEng.exe3220RegOpenKeyHKU\S-1-5-18REPARSEDesired Access: Read
249613:48:28.7520973MsMpEng.exe3220RegOpenKeyHKU\.DEFAULTSUCCESSDesired Access: Read
249713:48:28.7522784MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
249813:48:28.7522935MsMpEng.exe3220QueryNetworkOpenInformationFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSCreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A
249913:48:28.7522999MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESS
250013:48:28.7525831MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exeSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
The file is too large to be shown. View Raw