Report #11076 check_circle

  • Creation Date: Sept. 7, 2020, 8:18 p.m.
  • Last Update: Sept. 7, 2020, 8:31 p.m.
  • File: 003
  • Results:
Binary
DLL
False cancel
Size
115.50KB
trid
61.7% Win64 Executable
14.7% Win32 Dynamic Link Library
10.0% Win32 Executable
4.5% OS/2 Executable
4.4% Generic Win/DOS Executable
type
PE
wordsize
0
Subsystem
unknown
Hashes
md5
69c242ee355cf2103f327fabc8a08fb8
sha1
ae0379b27d3810a589a316f1ab82ba97a76e2fbf
crc32
0x34a8bd5e
sha224
af69233b71dede10f2df023cbafd0428c9e497c7ab94b66f92c9cda7
sha256
2af156b23d936ece676fa3ad220672970547f5e3218d2359d2596e47a5bf5d3b
sha384
daaf33083df2e57cc1ebf3373b2c930063421f6f505fe6840b0b2e51d7c0084b1f9a68bdbeb11c7856c40a250a2c5f98
sha512
02604a8d4b894a5d1bc8a8ff0399f8196a006a425eee7daed0b08b0e115ff590800d1990065cf0a59af9c47a60c2ba709af45851f7d69a4f681ae7d995890c1e
ssdeep
1536:ck8UL5PbQCu5Nn/HDM5Oo0mjSpUCBMdqICS4AeNf1RjfWwRdzT68k6UGsWMS1Hbe:eVvpXmjmYdJ4Z1RjnRdRkVGH7l87L
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
domain, HasRichSignature, contentis_base64, RijnDael_AES, maldoc_find_kernel32_base_method_1, CRC32_poly_Constant, IsPE32, IsWindowsGUI

Suspicious
True check_circle

Strings
List
o%A0}
t1SSSh
PSSh
AAAAOOOOgggg
BBBBhhhhAAAA
8-878A8K8[8e8o8
s@,E
@X\uft3e
Ti-b[Xv+S
;22dV::tN
&&&&6666????
}e#GEWF
It8]B4
MeOgU~M
O44h\
2dV2:tN:
dV22tN::
V22dN::t
Df""T~**;
`.rdata
2Ht\l
f""D~**T
""Df**T~
;V#npGR2
`3SbE
Gan;6
5,ANf
ServicesActive
pCe-Rn)
N.}U(' PMs
p\lHtW
@.data
a44Do
R##Fe
P[bfie
JNeME~
QPeA~S
kIV,ge
Ur&ge
cl{au
R`ALy
?wreD
-1HA
11#?*0
oAM6N
8ATF
0eoH
goI2
o0Pt
6lMe
cMEDI
`nW;R
lHt\
ct-=h
fTD$n
, @`
t\lHBW
SbEwd
O:gA
r"Ba
!yta
f|ltn
Hiit
uTh
ADeh
Rich
utnY
HDpe
OWpt
OhdW
ilCR
$8,4
+?^1
,0<
)0.
#?*1
5371
` @
~);]
8fTR
Nh.5
xxxx%%%%....
xxJo%%\r..8$
fNt7
hM5t
%Adz!
o%%Jr..\$
%%Jo..\r
F%d&#
tWRf
t!WS
t:DL
~nlD
[SSh
mtPD
NdMY
TRPy
tDSW
LfRp
CSVh

Foremost
Matches
0.exe, 115 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancel
Allowed
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

URLs
Allowed
hasURLs: False cancel
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

Files
Allowed: KERNEL32.dll
hasFiles: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Binary
Sizes
RVA
RVA: 16
Suspicious: False cancel
Code
Size: 72704
Suspicious: False cancel
Image
Address: 4194304
Suspicious: False cancel
Stack
Stack: 4096
Suspicious: False cancel
Headers
Headers: 1024
Suspicious: False cancel
Suspicious: False cancel

Symbols
Number
Number: 0
Suspicious: True check_circle
Pointer
Pointer: 0
Suspicious: True check_circle
Directories
Number: 16
Suspicious: False cancel

Checksum
Value: 0
Suspicous: True check_circle

Sections
Allowed: .text, .rdata, .data, .0lgfxz, .reloc
Suspicious
hasAllowed: True check_circle
hasSections: True check_circle
hasSuspicious: False cancel

Versions
OS
Version: 5
Suspicious: False cancel
Image
Version: True check_circle
Suspicious: 5
Linker
Version: 14.0
Suspicious: False cancel
Subsystem
Version: 5.1
Suspicious: False cancel
Suspicious: False cancel

EntryPoint
Address: 16028
Suspicious: False cancel

Anomalies
Anomalies: The header checksum and the calculated checksum do not match.
hasAnomalies: True check_circle

Libraries
Allowed: kernel32.dll
hasLibs: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Timestamp
Past: False cancel
Valid: True check_circle
Value: 2020-05-08 12:47:59
Future: False cancel

Compilation
Packed: False cancel
Missing: True check_circle
Packers
Compiled: False cancel
Compilers

Obfuscation
XOR: False cancel
Fuzzing: False cancel

PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
True check_circle
Tricks
ldr
.text: 1

pushret
.data: 21
.rdata: 5

pushpopmath
.data: 14
.text: 4
.rdata: 1
.reloc: 1

ss register
.data: 1

garbagebytes
.data: 10
.rdata: 2

software breakpoint
.data: 1
.reloc: 1

programcontrolflowchange
.data: 10
.rdata: 2

AVclass
sodinokibi
1
VirusTotal
md5
69c242ee355cf2103f327fabc8a08fb8
sha1
ae0379b27d3810a589a316f1ab82ba97a76e2fbf
SCANS
AVG
result: Win32:Malware-gen
update: 20200805
version: 18.4.3895.0
detected: True check_circle

CMC
update: 20200805
version: 2.7.2019.1
detected: False cancel

MAX
result: malware (ai score=100)
update: 20200805
version: 2019.9.16.1
detected: True check_circle

APEX
result: Malicious
update: 20200804
version: 6.56
detected: True check_circle

Bkav
update: 20200805
version: 1.3.0.9899
detected: False cancel

K7GW
result: Trojan ( 0054d99c1 )
update: 20200805
version: 11.127.34901
detected: True check_circle

ALYac
result: Trojan.Ransom.Sodinokibi
update: 20200805
version: 1.1.1.5
detected: True check_circle

Avast
result: Win32:Malware-gen
update: 20200805
version: 18.4.3895.0
detected: True check_circle

Avira
result: TR/Crypt.XPACK.Gen
update: 20200805
version: 8.3.3.8
detected: True check_circle

Baidu
update: 20190318
version: 1.0.0.2
detected: False cancel

Cynet
result: Malicious (score: 100)
update: 20200805
version: 4.0.0.24
detected: True check_circle

Cyren
result: W32/Kryptik.AKW.gen!Eldorado
update: 20200805
version: 6.3.0.2
detected: True check_circle

DrWeb
result: Trojan.Encoder.28004
update: 20200805
version: 7.0.46.3050
detected: True check_circle

GData
result: DeepScan:Generic.Ransom.Sodinokibi.FE9FF902
update: 20200805
version: A:25.26484B:27.19695
detected: True check_circle

Panda
result: Trj/GdSda.A
update: 20200805
version: 4.6.4.2
detected: True check_circle

VBA32
result: BScope.Trojan.DelShad
update: 20200805
version: 4.4.1
detected: True check_circle

VIPRE
update: 20200805
version: 85718
detected: False cancel

Zoner
update: 20200805
version: 0.0.0.0
detected: False cancel

ClamAV
result: Win.Ransomware.Sodinokibi-7013612-0
update: 20200805
version: 0.102.4.0
detected: True check_circle

Comodo
result: Malware@#3vdq534lc68gs
update: 20200728
version: 32668
detected: True check_circle

F-Prot
result: W32/Kryptik.AKW.gen!Eldorado
update: 20200805
version: 4.7.1.166
detected: True check_circle

Ikarus
result: Trojan-Ransom.Sodinokibi
update: 20200805
version: 0.1.5.2
detected: True check_circle

McAfee
result: Ransom-Sodnkibi!69C242EE355C
update: 20200805
version: 6.0.6.653
detected: True check_circle

Rising
result: Ransom.Sodin!8.10CD8 (CLOUD)
update: 20200805
version: 25.0.0.26
detected: True check_circle

Sophos
result: Troj/Sodino-BU
update: 20200805
version: 4.98.0
detected: True check_circle

Yandex
result: Trojan.Filecoder!D4ko3vclm2c
update: 20200707
version: 5.5.2.24
detected: True check_circle

Zillya
result: Trojan.Filecoder.Win32.14505
update: 20200805
version: 2.0.0.4148
detected: True check_circle

Acronis
result: suspicious
update: 20200603
version: 1.1.1.76
detected: True check_circle

Alibaba
result: Ransom:Win32/Sodinokibi.cd33c3d7
update: 20190527
version: 0.3.0.5
detected: True check_circle

Arcabit
result: DeepScan:Generic.Ransom.Sodinokibi.FE9FF902
update: 20200805
version: 1.0.0.877
detected: True check_circle

Cylance
result: Unsafe
update: 20200805
version: 2.3.1.101
detected: True check_circle

Endgame
result: malicious (high confidence)
update: 20200727
version: 4.0.6
detected: True check_circle

FireEye
result: Generic.mg.69c242ee355cf210
update: 20200805
version: 32.36.1.0
detected: True check_circle

Sangfor
result: Malware
update: 20200423
version: 1.0
detected: True check_circle

TACHYON
update: 20200805
version: 2020-08-05.02
detected: False cancel

Tencent
result: Malware.Win32.Gencirc.10cdd51f
update: 20200805
version: 1.0.0.1
detected: True check_circle

ViRobot
update: 20200805
version: 2014.3.20.0
detected: False cancel

Webroot
result: W32.Ransom.Sodinokibi
update: 20200805
version: 1.0.0.403
detected: True check_circle

eGambit
update: 20200805
detected: False cancel

Ad-Aware
result: DeepScan:Generic.Ransom.Sodinokibi.FE9FF902
update: 20200805
version: 3.0.5.370
detected: True check_circle

AegisLab
result: Trojan.Win32.Gen.j!c
update: 20200805
version: 4.2
detected: True check_circle

Emsisoft
result: DeepScan:Generic.Ransom.Sodinokibi.FE9FF902 (B)
update: 20200805
version: 2018.12.0.1641
detected: True check_circle

F-Secure
result: Trojan.TR/Crypt.XPACK.Gen
update: 20200805
version: 12.0.86.52
detected: True check_circle

Fortinet
result: W32/Sodinokibi.B!tr.ransom
update: 20200805
version: 6.2.142.0
detected: True check_circle

Invincea
result: heuristic
update: 20200502
version: 6.3.6.26157
detected: True check_circle

Jiangmin
update: 20200805
version: 16.0.100
detected: False cancel

Kingsoft
update: 20200805
version: 2013.8.14.323
detected: False cancel

Paloalto
result: generic.ml
update: 20200805
version: 1.0
detected: True check_circle

Symantec
result: Ransom.Sodinokibi
update: 20200805
version: 1.11.0.0
detected: True check_circle

Trapmine
result: malicious.high.ml.score
update: 20200727
version: 3.5.0.1023
detected: True check_circle

AhnLab-V3
result: Trojan/Win32.RL_Ransom.R290570
update: 20200805
version: 3.18.1.10026
detected: True check_circle

Antiy-AVL
result: Trojan[Ransom]/Win32.Gen
update: 20200805
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: HEUR:Trojan-Ransom.Win32.Gen.gen
update: 20200805
version: 15.0.1.13
detected: True check_circle

Microsoft
result: Ransom:Win32/Sodinokibi.DSB!MTB
update: 20200805
version: 1.1.17300.4
detected: True check_circle

Qihoo-360
result: Win32/Trojan.Ransom.fb6
update: 20200805
version: 1.0.0.1120
detected: True check_circle

ZoneAlarm
result: HEUR:Trojan-Ransom.Win32.Gen.gen
update: 20200805
version: 1.0
detected: True check_circle

Cybereason
result: malicious.e355cf
update: 20190616
version: 1.2.449
detected: True check_circle

ESET-NOD32
result: a variant of Win32/Filecoder.Sodinokibi.B
update: 20200805
version: 21771
detected: True check_circle

TrendMicro
result: Ransom.Win32.SODINOKIB.SMTH
update: 20200805
version: 11.0.0.1006
detected: True check_circle

BitDefender
result: DeepScan:Generic.Ransom.Sodinokibi.FE9FF902
update: 20200805
version: 7.2
detected: True check_circle

CrowdStrike
result: win/malicious_confidence_90% (W)
update: 20190702
version: 1.0
detected: True check_circle

K7AntiVirus
result: Trojan ( 0054d99c1 )
update: 20200805
version: 11.128.34908
detected: True check_circle

SentinelOne
result: DFI - Malicious PE
update: 20200725
version: 4.4.0.0
detected: True check_circle

Avast-Mobile
update: 20200805
version: 200805-00
detected: False cancel

Malwarebytes
result: Ransom.Sodinokibi
update: 20200805
version: 3.6.4.335
detected: True check_circle

TotalDefense
update: 20200804
version: 37.1.62.1
detected: False cancel

CAT-QuickHeal
result: Trojanransom.Gen
update: 20200805
version: 14.00
detected: True check_circle

NANO-Antivirus
result: Virus.Win32.Gen.ccmw
update: 20200805
version: 1.0.134.25119
detected: True check_circle

BitDefenderTheta
result: AI:Packer.59A870CF1E
update: 20200805
version: 7.2.37796.0
detected: True check_circle

MicroWorld-eScan
result: DeepScan:Generic.Ransom.Sodinokibi.FE9FF902
update: 20200805
version: 14.0.409.0
detected: True check_circle

SUPERAntiSpyware
update: 20200731
version: 5.6.0.1032
detected: False cancel

TrendMicro-HouseCall
result: Ransom.Win32.SODINOKIB.SMTH
update: 20200805
version: 10.0.0.1040
detected: True check_circle

total
72
sha256
2af156b23d936ece676fa3ad220672970547f5e3218d2359d2596e47a5bf5d3b
scan_id
2af156b23d936ece676fa3ad220672970547f5e3218d2359d2596e47a5bf5d3b-1596653897
resource
69c242ee355cf2103f327fabc8a08fb8
positives
59
scan_date
2020-08-05 18:58:17
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
7/9/2020 - 19:45:45.553Open1480C:\malware.exeC:\
7/9/2020 - 19:45:45.554Unknown1480C:\malware.exeC:\
7/9/2020 - 19:45:45.559Open1480C:\malware.exeC:\
7/9/2020 - 19:45:45.559Unknown1480C:\malware.exeC:\
7/9/2020 - 19:45:45.597Open1480C:\malware.exeC:\Windows\SysWOW64\rpcss.dll
7/9/2020 - 19:45:45.598Open1480C:\malware.exeC:\Windows\SysWOW64\rpcss.dll
7/9/2020 - 19:45:45.728Open1480C:\malware.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
7/9/2020 - 19:45:45.731Open1480C:\malware.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
7/9/2020 - 19:45:45.736Open1480C:\malware.exeC:\Windows\SysWOW64\wbem\wbemcomn.dll
7/9/2020 - 19:45:45.736Open1480C:\malware.exeC:\Windows\SysWOW64\wbemcomn.dll
7/9/2020 - 19:45:45.740Open1480C:\malware.exeC:\powershell.exe
7/9/2020 - 19:45:45.741Open1480C:\malware.exeC:\Monitor\powershell.exe
7/9/2020 - 19:45:45.741Open1480C:\malware.exeC:\Windows\System32\powershell.exe
7/9/2020 - 19:45:45.741Open1480C:\malware.exeC:\Windows\system\powershell.exe
7/9/2020 - 19:45:45.742Open1480C:\malware.exeC:\Windows\powershell.exe
7/9/2020 - 19:45:45.742Open1480C:\malware.exeC:\Windows\System32\powershell.exe
7/9/2020 - 19:45:45.742Open1480C:\malware.exeC:\Windows\powershell.exe
7/9/2020 - 19:45:45.742Open1480C:\malware.exeC:\Windows\System32\wbem\powershell.exe
7/9/2020 - 19:45:45.742Open1480C:\malware.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
7/9/2020 - 19:45:45.743Unknown1480C:\malware.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
7/9/2020 - 19:45:45.743Open1480C:\malware.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
7/9/2020 - 19:45:45.743Unknown1480C:\malware.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
7/9/2020 - 19:45:45.743Open1480C:\malware.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
7/9/2020 - 19:45:45.745Open1480C:\malware.exeC:\Windows\SysWOW64\wbemcomn.dll
7/9/2020 - 19:45:45.754Open1480C:\malware.exeC:\Windows\SysWOW64\wbem\Logs
7/9/2020 - 19:45:45.756Unknown1480C:\malware.exeC:\Windows\SysWOW64\wbem\Logs
7/9/2020 - 19:45:45.757Open1480C:\malware.exeC:\CRYPTSP.dll
7/9/2020 - 19:45:45.758Open1480C:\malware.exeC:\Windows\SysWOW64\cryptsp.dll
7/9/2020 - 19:45:45.758Open1480C:\malware.exeC:\Windows\SysWOW64\cryptsp.dll
7/9/2020 - 19:45:45.759Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
7/9/2020 - 19:45:45.759Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
7/9/2020 - 19:45:45.760Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
7/9/2020 - 19:45:45.760Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
7/9/2020 - 19:45:45.760Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
7/9/2020 - 19:45:45.761Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
7/9/2020 - 19:45:45.761Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
7/9/2020 - 19:45:45.761Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
7/9/2020 - 19:45:45.762Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
7/9/2020 - 19:45:45.762Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
7/9/2020 - 19:45:45.768Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
7/9/2020 - 19:45:45.768Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
7/9/2020 - 19:45:45.770Open1480C:\malware.exeC:\Windows\Globalization\Sorting\SortDefault.nls
7/9/2020 - 19:45:45.770Unknown1480C:\malware.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
7/9/2020 - 19:45:45.771Open1480C:\malware.exeC:\RpcRtRemote.dll
7/9/2020 - 19:45:45.771Open1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dll
7/9/2020 - 19:45:45.771Unknown1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
7/9/2020 - 19:45:45.771Open1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dll
7/9/2020 - 19:45:45.772Unknown1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
7/9/2020 - 19:45:45.772Open1480C:\malware.exeC:\Windows\SysWOW64\apphelp.dll
7/9/2020 - 19:45:45.773Open1480C:\malware.exeC:\Windows\SysWOW64\apphelp.dll
7/9/2020 - 19:45:45.774Open1480C:\malware.exeC:\Windows\AppPatch\AppPatch64\sysmain.sdb
7/9/2020 - 19:45:45.774Open1480C:\malware.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:45:45.774Unknown1480C:\malware.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:45:45.775Open1480C:\malware.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
7/9/2020 - 19:45:45.775Unknown1480C:\malware.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
7/9/2020 - 19:45:45.775Open1480C:\malware.exeC:\
7/9/2020 - 19:45:45.775Unknown1480C:\malware.exeC:\
7/9/2020 - 19:45:45.775Open1480C:\malware.exeC:\Windows
7/9/2020 - 19:45:45.775Unknown1480C:\malware.exeC:\Windows
7/9/2020 - 19:45:45.775Open1480C:\malware.exeC:\Windows\System32\WindowsPowerShell
7/9/2020 - 19:45:45.776Unknown1480C:\malware.exeC:\Windows\System32\WindowsPowerShell
7/9/2020 - 19:45:45.778Unknown1480C:\malware.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
7/9/2020 - 19:45:45.863Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Prefetch\POWERSHELL.EXE-920BBA2A.pf
7/9/2020 - 19:45:45.864Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:45:46.43Open1480C:\malware.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
7/9/2020 - 19:45:46.44Open1480C:\malware.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
7/9/2020 - 19:45:46.60Open1480C:\malware.exeC:\Windows\SysWOW64\wbem\fastprox.dll
7/9/2020 - 19:45:46.69Open1480C:\malware.exeC:\Windows\SysWOW64\wbem\fastprox.dll
7/9/2020 - 19:45:46.87Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\sechost.dll
7/9/2020 - 19:45:46.87Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\sechost.dll
7/9/2020 - 19:45:46.90Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\ATL.DLL
7/9/2020 - 19:45:46.91Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\atl.dll
7/9/2020 - 19:45:46.91Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\atl.dll
7/9/2020 - 19:45:46.93Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\mscoree.dll
7/9/2020 - 19:45:46.93Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\mscoree.dll
7/9/2020 - 19:45:46.93Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\mscoree.dll
7/9/2020 - 19:45:46.95Open1480C:\malware.exeC:\Windows\SysWOW64\wbem\NTDSAPI.dll
7/9/2020 - 19:45:46.97Open1480C:\malware.exeC:\Windows\SysWOW64\ntdsapi.dll
7/9/2020 - 19:45:46.97Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\imm32.dll
7/9/2020 - 19:45:46.98Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\imm32.dll
7/9/2020 - 19:45:46.98Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\imm32.dll
7/9/2020 - 19:45:46.98Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\imm32.dll
7/9/2020 - 19:45:46.98Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\imm32.dll
7/9/2020 - 19:45:46.99Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\imm32.dll
7/9/2020 - 19:45:46.100Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\pt-BR\powershell.exe.mui
7/9/2020 - 19:45:46.101Open1480C:\malware.exeC:\Windows\SysWOW64\ntdsapi.dll
7/9/2020 - 19:45:46.104Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rpcss.dll
7/9/2020 - 19:45:46.104Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rpcss.dll
7/9/2020 - 19:45:46.104Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rpcss.dll
7/9/2020 - 19:45:46.105Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rpcss.dll
7/9/2020 - 19:45:46.105Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\CRYPTBASE.dll
7/9/2020 - 19:45:46.105Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cryptbase.dll
7/9/2020 - 19:45:46.105Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cryptbase.dllcryptbase.dll
7/9/2020 - 19:45:46.105Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cryptbase.dll
7/9/2020 - 19:45:46.106Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cryptbase.dllcryptbase.dll
7/9/2020 - 19:45:46.106Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\uxtheme.dll
7/9/2020 - 19:45:46.106Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\uxtheme.dll
7/9/2020 - 19:45:46.151Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shell32.dll
7/9/2020 - 19:45:46.152Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shell32.dll
7/9/2020 - 19:45:46.155Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shell32.dll
7/9/2020 - 19:45:46.156Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
7/9/2020 - 19:45:46.156Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
7/9/2020 - 19:45:46.156Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
7/9/2020 - 19:45:46.157Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
7/9/2020 - 19:45:46.157Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
7/9/2020 - 19:45:46.157Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
7/9/2020 - 19:45:46.157Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
7/9/2020 - 19:45:46.157Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
7/9/2020 - 19:45:46.158Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\WindowsShell.Manifest
7/9/2020 - 19:45:46.158Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\WindowsShell.ManifestWindowsShell.Manifest
7/9/2020 - 19:45:46.160Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Globalization\Sorting\SortDefault.nls
7/9/2020 - 19:45:46.160Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
7/9/2020 - 19:45:46.160Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
7/9/2020 - 19:45:46.160Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
7/9/2020 - 19:45:46.161Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
7/9/2020 - 19:45:46.161Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
7/9/2020 - 19:45:46.162Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
7/9/2020 - 19:45:46.162Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
7/9/2020 - 19:45:46.162Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.162Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.162Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.162Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.162Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell
7/9/2020 - 19:45:46.162Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell
7/9/2020 - 19:45:46.164Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
7/9/2020 - 19:45:46.164Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
7/9/2020 - 19:45:46.165Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.165Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.166Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\propsys.dll
7/9/2020 - 19:45:46.166Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\propsys.dll
7/9/2020 - 19:45:46.166Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches
7/9/2020 - 19:45:46.166Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
7/9/2020 - 19:45:46.166Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches
7/9/2020 - 19:45:46.166Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
7/9/2020 - 19:45:46.167Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000000.db
7/9/2020 - 19:45:46.167Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\desktop.ini
7/9/2020 - 19:45:46.167Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\desktop.ini
7/9/2020 - 19:45:46.168Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
7/9/2020 - 19:45:46.169Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
7/9/2020 - 19:45:46.169Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:46.169Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:46.169Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
7/9/2020 - 19:45:46.169Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
7/9/2020 - 19:45:46.169Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
7/9/2020 - 19:45:46.170Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
7/9/2020 - 19:45:46.170Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\desktop.ini
7/9/2020 - 19:45:46.170Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
7/9/2020 - 19:45:46.170Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
7/9/2020 - 19:45:46.170Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
7/9/2020 - 19:45:46.170Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
7/9/2020 - 19:45:46.170Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
7/9/2020 - 19:45:46.171Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
7/9/2020 - 19:45:46.171Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Desktop\desktop.ini
7/9/2020 - 19:45:46.171Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Desktop\desktop.ini
7/9/2020 - 19:45:46.175Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
7/9/2020 - 19:45:46.175Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
7/9/2020 - 19:45:46.175Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.175Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.176Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
7/9/2020 - 19:45:46.176Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
7/9/2020 - 19:45:46.176Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:46.176Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:46.176Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
7/9/2020 - 19:45:46.176Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
7/9/2020 - 19:45:46.176Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
7/9/2020 - 19:45:46.177Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
7/9/2020 - 19:45:46.177Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
7/9/2020 - 19:45:46.177Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
7/9/2020 - 19:45:46.177Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
7/9/2020 - 19:45:46.177Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
7/9/2020 - 19:45:46.177Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
7/9/2020 - 19:45:46.177Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
7/9/2020 - 19:45:46.178Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
7/9/2020 - 19:45:46.178Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
7/9/2020 - 19:45:46.178Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/9/2020 - 19:45:46.179Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/9/2020 - 19:45:46.179Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.179Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.179Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
7/9/2020 - 19:45:46.179Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
7/9/2020 - 19:45:46.179Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\desktop.ini
7/9/2020 - 19:45:46.183Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
7/9/2020 - 19:45:46.186Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
7/9/2020 - 19:45:46.186Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
7/9/2020 - 19:45:46.187Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
7/9/2020 - 19:45:46.187Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
7/9/2020 - 19:45:46.187Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
7/9/2020 - 19:45:46.277Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/9/2020 - 19:45:46.277Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/9/2020 - 19:45:46.280Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.287Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.287Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
7/9/2020 - 19:45:46.287Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
7/9/2020 - 19:45:46.288Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
7/9/2020 - 19:45:46.288Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
7/9/2020 - 19:45:46.288Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
7/9/2020 - 19:45:46.288Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
7/9/2020 - 19:45:46.289Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/9/2020 - 19:45:46.289Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/9/2020 - 19:45:46.289Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
7/9/2020 - 19:45:46.289Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
7/9/2020 - 19:45:46.290Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Desktop
7/9/2020 - 19:45:46.290Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Desktop
7/9/2020 - 19:45:46.290Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.290Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.291Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
7/9/2020 - 19:45:46.291Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
7/9/2020 - 19:45:46.291Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:46.291Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:46.291Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\Desktop
7/9/2020 - 19:45:46.291Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\Desktop
7/9/2020 - 19:45:46.291Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.291Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.291Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
7/9/2020 - 19:45:46.292Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
7/9/2020 - 19:45:46.292Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\desktop.ini
7/9/2020 - 19:45:46.292Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\desktop.ini
7/9/2020 - 19:45:46.292Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public
7/9/2020 - 19:45:46.293Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public
7/9/2020 - 19:45:46.293Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\Desktop\desktop.ini
7/9/2020 - 19:45:46.293Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\Desktop\desktop.ini
7/9/2020 - 19:45:46.294Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\apphelp.dll
7/9/2020 - 19:45:46.294Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\apphelp.dll
7/9/2020 - 19:45:46.295Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\apphelp.dll
7/9/2020 - 19:45:46.296Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\gameux.dll
7/9/2020 - 19:45:46.297Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\gameux.dll
7/9/2020 - 19:45:46.297Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\gameux.dll
7/9/2020 - 19:45:46.298Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\gameux.dll
7/9/2020 - 19:45:46.298Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
7/9/2020 - 19:45:46.298Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
7/9/2020 - 19:45:46.299Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
7/9/2020 - 19:45:46.299Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
7/9/2020 - 19:45:46.299Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
7/9/2020 - 19:45:46.299Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_14556c1e8b95d0b8
7/9/2020 - 19:45:46.300Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_14556c1e8b95d0b8
7/9/2020 - 19:45:46.300Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_14556c1e8b95d0b8
7/9/2020 - 19:45:46.300Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_14556c1e8b95d0b8\GdiPlus.dll
7/9/2020 - 19:45:46.300Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_14556c1e8b95d0b8\GdiPlus.dll
7/9/2020 - 19:45:46.353Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\xmllite.dll
7/9/2020 - 19:45:46.354Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\xmllite.dll
7/9/2020 - 19:45:46.355Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wer.dll
7/9/2020 - 19:45:46.355Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wer.dll
7/9/2020 - 19:45:46.358Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
7/9/2020 - 19:45:46.443Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
7/9/2020 - 19:45:46.444Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
7/9/2020 - 19:45:46.444Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
7/9/2020 - 19:45:46.445Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
7/9/2020 - 19:45:46.445Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
7/9/2020 - 19:45:46.446Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
7/9/2020 - 19:45:46.447Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
7/9/2020 - 19:45:46.447Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
7/9/2020 - 19:45:46.448Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
7/9/2020 - 19:45:46.448Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
7/9/2020 - 19:45:46.449Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
7/9/2020 - 19:45:46.450Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
7/9/2020 - 19:45:46.450Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
7/9/2020 - 19:45:46.450Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.451Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.451Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
7/9/2020 - 19:45:46.451Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
7/9/2020 - 19:45:46.451Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:46.451Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:46.451Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
7/9/2020 - 19:45:46.452Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
7/9/2020 - 19:45:46.452Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
7/9/2020 - 19:45:46.452Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
7/9/2020 - 19:45:46.452Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
7/9/2020 - 19:45:46.452Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
7/9/2020 - 19:45:46.454Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer
7/9/2020 - 19:45:46.454Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer
7/9/2020 - 19:45:46.454Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
7/9/2020 - 19:45:46.454Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
7/9/2020 - 19:45:46.455Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
7/9/2020 - 19:45:46.455Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
7/9/2020 - 19:45:46.457Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shdocvw.dll
7/9/2020 - 19:45:46.458Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shdocvw.dll
7/9/2020 - 19:45:46.458Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shdocvw.dll
7/9/2020 - 19:45:46.459Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.459Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.459Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
7/9/2020 - 19:45:46.459Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
7/9/2020 - 19:45:46.459Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:46.459Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:46.460Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
7/9/2020 - 19:45:46.460Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
7/9/2020 - 19:45:46.460Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
7/9/2020 - 19:45:46.460Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
7/9/2020 - 19:45:46.460Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
7/9/2020 - 19:45:46.460Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
7/9/2020 - 19:45:46.460Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer
7/9/2020 - 19:45:46.461Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer
7/9/2020 - 19:45:46.461Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
7/9/2020 - 19:45:46.461Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
7/9/2020 - 19:45:46.522Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
7/9/2020 - 19:45:46.523Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms
7/9/2020 - 19:45:46.524Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
7/9/2020 - 19:45:46.566Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk\desktop.ini
7/9/2020 - 19:45:46.567Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk\desktop.ini
7/9/2020 - 19:45:46.568Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.568Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.568Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
7/9/2020 - 19:45:46.568Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
7/9/2020 - 19:45:46.568Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
7/9/2020 - 19:45:46.568Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
7/9/2020 - 19:45:46.569Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
7/9/2020 - 19:45:46.569Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
7/9/2020 - 19:45:46.569Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/9/2020 - 19:45:46.569Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/9/2020 - 19:45:46.569Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/9/2020 - 19:45:46.570Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/9/2020 - 19:45:46.570Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
7/9/2020 - 19:45:46.570Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
7/9/2020 - 19:45:46.570Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
7/9/2020 - 19:45:46.571Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
7/9/2020 - 19:45:46.571Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
7/9/2020 - 19:45:46.571Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
7/9/2020 - 19:45:46.571Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.571Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.572Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\LINKINFO.dll
7/9/2020 - 19:45:46.572Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\linkinfo.dll
7/9/2020 - 19:45:46.572Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\linkinfo.dll
7/9/2020 - 19:45:46.573Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.573Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.573Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\ntshrui.dll
7/9/2020 - 19:45:46.574Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\ntshrui.dll
7/9/2020 - 19:45:46.574Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\ntshrui.dll
7/9/2020 - 19:45:46.574Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\srvcli.dll
7/9/2020 - 19:45:46.575Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\srvcli.dll
7/9/2020 - 19:45:46.575Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\srvcli.dll
7/9/2020 - 19:45:46.618Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\cscapi.dll
7/9/2020 - 19:45:46.618Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cscapi.dll
7/9/2020 - 19:45:46.618Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cscapi.dll
7/9/2020 - 19:45:46.619Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\slc.dll
7/9/2020 - 19:45:46.619Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\slc.dll
7/9/2020 - 19:45:46.620Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\slc.dll
7/9/2020 - 19:45:46.620Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
7/9/2020 - 19:45:46.621Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.621Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.621Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.621Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.622Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.625Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnkWindows PowerShell.lnk
7/9/2020 - 19:45:46.625Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.625Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.625Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
7/9/2020 - 19:45:46.625Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
7/9/2020 - 19:45:46.625Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
7/9/2020 - 19:45:46.625Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
7/9/2020 - 19:45:46.625Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
7/9/2020 - 19:45:46.626Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
7/9/2020 - 19:45:46.626Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/9/2020 - 19:45:46.626Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/9/2020 - 19:45:46.626Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/9/2020 - 19:45:46.626Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/9/2020 - 19:45:46.626Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
7/9/2020 - 19:45:46.627Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
7/9/2020 - 19:45:46.627Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.627Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.627Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.627Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.627Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
7/9/2020 - 19:45:46.628Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.628Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.628Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.628Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.628Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/9/2020 - 19:45:46.628Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnkWindows PowerShell.lnk
7/9/2020 - 19:45:46.629Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:45:46.629Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:45:46.629Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.629Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.629Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.629Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.630Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32
7/9/2020 - 19:45:46.630Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32
7/9/2020 - 19:45:46.630Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell
7/9/2020 - 19:45:46.630Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell
7/9/2020 - 19:45:46.630Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:45:46.630Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:45:46.631Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.631Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.631Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe
7/9/2020 - 19:45:46.631Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:45:46.632Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:45:46.632Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:45:46.632Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:45:46.632Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:45:46.632Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exepowershell_ise.exe
7/9/2020 - 19:45:46.633Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.633Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.633Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.634Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.634Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.634Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.634Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\hh.exe
7/9/2020 - 19:45:46.644Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.644Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.645Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.645Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.645Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.645Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
7/9/2020 - 19:45:46.646Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\CRYPTSP.dll
7/9/2020 - 19:45:46.646Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cryptsp.dll
7/9/2020 - 19:45:46.646Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cryptsp.dll
7/9/2020 - 19:45:46.647Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
7/9/2020 - 19:45:46.648Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
7/9/2020 - 19:45:46.648Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
7/9/2020 - 19:45:46.648Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
7/9/2020 - 19:45:46.649Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
7/9/2020 - 19:45:46.649Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
7/9/2020 - 19:45:46.650Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
7/9/2020 - 19:45:46.650Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
7/9/2020 - 19:45:46.650Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
7/9/2020 - 19:45:46.651Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
7/9/2020 - 19:45:46.655Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
7/9/2020 - 19:45:46.655Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
7/9/2020 - 19:45:46.656Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XWRKP2UEYJKKWAKBW3AF.temp
7/9/2020 - 19:45:46.657Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XWRKP2UEYJKKWAKBW3AF.temp
7/9/2020 - 19:45:46.657Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XWRKP2UEYJKKWAKBW3AF.tempXWRKP2UEYJKKWAKBW3AF.temp
7/9/2020 - 19:45:46.658Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XWRKP2UEYJKKWAKBW3AF.tempXWRKP2UEYJKKWAKBW3AF.temp
7/9/2020 - 19:45:46.658Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XWRKP2UEYJKKWAKBW3AF.tempXWRKP2UEYJKKWAKBW3AF.temp
7/9/2020 - 19:45:46.659Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XWRKP2UEYJKKWAKBW3AF.tempXWRKP2UEYJKKWAKBW3AF.temp
7/9/2020 - 19:45:46.659Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms
7/9/2020 - 19:45:46.659Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XWRKP2UEYJKKWAKBW3AF.temp
7/9/2020 - 19:45:46.659Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
7/9/2020 - 19:45:46.659Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XWRKP2UEYJKKWAKBW3AF.tempXWRKP2UEYJKKWAKBW3AF.temp
7/9/2020 - 19:45:46.660Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
7/9/2020 - 19:45:46.661Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
7/9/2020 - 19:45:46.669Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\mscoree.dll.local
7/9/2020 - 19:45:46.669Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727
7/9/2020 - 19:45:46.670Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727
7/9/2020 - 19:45:46.670Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\Upgrades.2.0.50727
7/9/2020 - 19:45:46.670Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\Upgrades.2.0.50727
7/9/2020 - 19:45:46.677Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.config
7/9/2020 - 19:45:46.678Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727
7/9/2020 - 19:45:46.678Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727
7/9/2020 - 19:45:46.678Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
7/9/2020 - 19:45:46.678Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
7/9/2020 - 19:45:46.701Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
7/9/2020 - 19:45:46.718Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
7/9/2020 - 19:45:46.718Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs
7/9/2020 - 19:45:46.718Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:45:46.721Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:45:46.721Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:45:46.721Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6\msvcr80.dll
7/9/2020 - 19:45:46.722Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6\msvcr80.dll
7/9/2020 - 19:45:46.723Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6\msvcr80.dll
7/9/2020 - 19:45:46.723Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.723Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:45:46.723Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.724Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
7/9/2020 - 19:45:46.724Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:45:46.724Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:45:49.71Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config
7/9/2020 - 19:45:49.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
7/9/2020 - 19:45:49.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
7/9/2020 - 19:45:49.645Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
7/9/2020 - 19:45:49.645Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
7/9/2020 - 19:45:49.646Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
7/9/2020 - 19:45:49.646Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
7/9/2020 - 19:45:49.646Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.config
7/9/2020 - 19:45:49.794Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\fusion.localgac
7/9/2020 - 19:45:50.100Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config
7/9/2020 - 19:45:50.101Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch
7/9/2020 - 19:45:50.102Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config
7/9/2020 - 19:45:50.102Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch
7/9/2020 - 19:45:50.219Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:50.219Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:50.219Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:45:50.219Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
7/9/2020 - 19:45:50.220Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
7/9/2020 - 19:45:50.220Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
7/9/2020 - 19:45:50.220Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config
7/9/2020 - 19:45:50.220Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch
7/9/2020 - 19:45:50.466Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\index187.dat
7/9/2020 - 19:45:50.506Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dll
7/9/2020 - 19:45:50.514Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.514Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dll
7/9/2020 - 19:45:50.514Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.515Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.518Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.521Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.558Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.558Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.578Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.578Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.579Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.579Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.579Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.580Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.580Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.581Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.581Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.581Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.582Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.582Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.583Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.583Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.583Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.584Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.586Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.592Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.625Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.659Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.727Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.762Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.796Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.797Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.797Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:50.868Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089
7/9/2020 - 19:45:50.902Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089
7/9/2020 - 19:45:50.936Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089
7/9/2020 - 19:45:50.969Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.177Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.210Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.278Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.319Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.354Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.387Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.420Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.455Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.490Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.523Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.563Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.596Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.748Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:51.927Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.42Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.105Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.247Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.322Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.358Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.391Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.569Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.604Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.642Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.710Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.745Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.778Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.811Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.844Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.901Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.935Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:52.972Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.14Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.82Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.419Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.454Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.492Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.526Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.570Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.711Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\ole32.dll
7/9/2020 - 19:45:53.782Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.816Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.860Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.894Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.928Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:53.964Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.0Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.68Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.176Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.210Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.244Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.278Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.312Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.346Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.383Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.416Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.450Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.484Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.517Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.550Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.583Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.617Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.650Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.752Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.794Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.828Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.863Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.896Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.929Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.962Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:54.996Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.29Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.70Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.124Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.162Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.195Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.228Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.261Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.295Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.330Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.363Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.396Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.429Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.463Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.498Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.564Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.598Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.632Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.666Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.699Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.732Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.765Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.798Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.832Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.868Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.901Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.934Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:55.967Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:56.0Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:56.34Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:56.67Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:56.100Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:56.134Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:56.170Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\OLEAUT32.dll
7/9/2020 - 19:45:56.170Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:56.205Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:57.202Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:57.238Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:57.304Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:57.337Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:57.371Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:57.409Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:57.515Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:57.563Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:57.646Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Globalization\pt-br.nlp
7/9/2020 - 19:45:57.646Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:57.753Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:57.787Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:57.998Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:58.35Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.config
7/9/2020 - 19:45:58.70Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\pubpol4.dat
7/9/2020 - 19:45:58.71Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC\PublisherPolicy.tme
7/9/2020 - 19:45:58.72Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config
7/9/2020 - 19:45:58.72Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
7/9/2020 - 19:45:58.73Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config
7/9/2020 - 19:45:58.73Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
7/9/2020 - 19:45:58.74Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
7/9/2020 - 19:45:58.74Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
7/9/2020 - 19:45:58.74Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
7/9/2020 - 19:45:58.74Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
7/9/2020 - 19:45:58.144Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:45:58.312Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:45:58.312Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:58.347Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:58.348Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:58.348Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:58.381Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:58.415Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:58.448Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:58.485Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:58.519Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:58.552Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:58.621Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:45:58.621Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:45:58.721Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Management.Automation\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:45:58.721Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:45:58.829Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:45:58.829Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
7/9/2020 - 19:45:58.872Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:58.873Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
7/9/2020 - 19:45:58.873Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:58.907Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:58.943Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:58.977Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:59.51Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:59.92Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:59.138Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:59.171Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:59.205Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:59.238Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:59.272Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:59.306Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:59.361Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:45:59.416Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:59.416Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:59.416Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:59.416Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:59.417Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:59.417Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:45:59.633Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:59.700Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:59.766Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:59.800Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:59.834Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:59.869Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:59.902Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:59.935Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:45:59.968Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:46:0.1Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
7/9/2020 - 19:46:0.35Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
7/9/2020 - 19:46:0.134Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
7/9/2020 - 19:46:0.210Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
7/9/2020 - 19:46:0.210Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:0.210Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:0.210Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:0.558Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.559Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.560Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.561Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.561Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.563Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.564Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.565Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.573Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.577Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.577Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.583Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:0.584Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:0.584Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.584Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.585Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.585Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.586Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.586Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.587Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.587Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.588Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.589Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.625Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
7/9/2020 - 19:46:0.625Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
7/9/2020 - 19:46:0.625Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.625Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
7/9/2020 - 19:46:0.625Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.625Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.626Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.679Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.717Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.750Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.784Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.817Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:0.850Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.919Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:0.986Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:1.152Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\BVTBin\Tests\installpackage\csilogfile.log
7/9/2020 - 19:46:1.188Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:1.221Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:1.254Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:1.288Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:1.321Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:1.355Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:1.388Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:1.421Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:1.455Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:1.493Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:1.527Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:1.561Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:1.595Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:1.810Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:1.859Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:1.912Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:1.956Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:1.992Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dll
7/9/2020 - 19:46:2.92Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.92Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dll
7/9/2020 - 19:46:2.92Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.126Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.160Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.199Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.232Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.265Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.298Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.332Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.366Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.399Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.432Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.471Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.504Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.539Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.572Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.605Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.638Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.671Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.708Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089
7/9/2020 - 19:46:2.778Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089
7/9/2020 - 19:46:2.779Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.812Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.845Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.882Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.930Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:2.965Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:3.63Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:3.109Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:3.142Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:3.175Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:3.209Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:3.244Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:3.313Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.347Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.380Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.414Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.447Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.481Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.516Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.549Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.583Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.616Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.649Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.682Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.715Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.750Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.784Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.817Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.850Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.884Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.953Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:3.986Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:4.19Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:4.86Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.120Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.187Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.232Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.286Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.324Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.357Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.390Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.423Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.458Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.492Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.525Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.558Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.592Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.625Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.660Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.693Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:4.727Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.760Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.793Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:4.827Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:4.865Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.899Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.932Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:4.965Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.33Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:5.80Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:5.113Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:5.146Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.180Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
7/9/2020 - 19:46:5.180Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:5.180Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.231Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.264Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.297Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.331Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.398Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.444Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\version.dll
7/9/2020 - 19:46:5.445Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\version.dll
7/9/2020 - 19:46:5.445Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\version.dll
7/9/2020 - 19:46:5.446Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.500Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
7/9/2020 - 19:46:5.501Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:5.501Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:5.540Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:5.573Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
7/9/2020 - 19:46:5.573Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:5.573Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.607Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.640Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:5.707Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\l_intl.nls
7/9/2020 - 19:46:5.774Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.807Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\pt-BR\KernelBase.dll.mui
7/9/2020 - 19:46:5.808Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.841Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.875Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.909Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.942Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:5.975Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.8Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.41Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.75Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.108Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.142Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.175Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.208Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.242Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.275Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.308Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.341Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.375Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.408Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.441Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.474Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.507Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.631Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.678Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.711Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.745Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.778Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.811Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.844Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.879Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.913Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.946Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:6.979Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:7.14Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:7.47Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
7/9/2020 - 19:46:7.48Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:7.115Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:7.148Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll
7/9/2020 - 19:46:7.149Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:7.182Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.216Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:7.250Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:7.283Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.316Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.351Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.384Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.417Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.451Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.484Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.518Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.554Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.589Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:7.624Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.657Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.690Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.760Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.760Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.761Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.770Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.771Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.771Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.772Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.773Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.774Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.774Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.775Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.780Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.815Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:7.882Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:7.961Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:8.7Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:8.41Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:8.74Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:8.107Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089
7/9/2020 - 19:46:8.107Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
7/9/2020 - 19:46:8.208Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
7/9/2020 - 19:46:8.278Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:8.311Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:8.344Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:8.377Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:8.411Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:8.444Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:8.481Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:8.514Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:8.548Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:8.582Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:8.615Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:8.648Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:8.684Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:8.718Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:8.752Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dll
7/9/2020 - 19:46:8.852Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:8.852Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dll
7/9/2020 - 19:46:8.852Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:8.886Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:8.920Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:8.954Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:8.987Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.54Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.99Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.152Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.189Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.222Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.255Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.289Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.322Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089
7/9/2020 - 19:46:9.391Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089
7/9/2020 - 19:46:9.392Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.425Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.459Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.493Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.526Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.559Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.592Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.625Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.659Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.692Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.725Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.758Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:9.791Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:9.825Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:9.859Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:9.892Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:9.958Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:9.993Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:10.26Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:10.59Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:10.92Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:10.128Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:10.162Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:10.195Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:10.264Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:10.313Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:10.368Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:10.406Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:10.474Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
7/9/2020 - 19:46:10.474Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:10.474Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
7/9/2020 - 19:46:10.474Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:10.474Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
7/9/2020 - 19:46:10.475Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:10.475Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:10.508Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:10.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:10.577Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:10.611Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:10.686Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:10.719Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:10.752Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:10.786Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:10.852Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:10.891Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:11.77Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:11.110Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:11.144Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:11.177Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:11.371Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:11.404Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:11.444Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:11.519Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:11.596Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:11.596Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:11.630Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:11.630Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:11.630Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:11.665Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:11.698Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:11.731Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:11.769Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:11.802Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:11.887Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:11.888Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:11.888Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Core\3.5.0.0__b77a5c561934e089
7/9/2020 - 19:46:11.888Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089
7/9/2020 - 19:46:11.962Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089
7/9/2020 - 19:46:11.962Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll
7/9/2020 - 19:46:11.998Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
7/9/2020 - 19:46:11.998Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll
7/9/2020 - 19:46:11.998Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
7/9/2020 - 19:46:12.32Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
7/9/2020 - 19:46:12.65Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
7/9/2020 - 19:46:12.98Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
7/9/2020 - 19:46:12.131Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
7/9/2020 - 19:46:12.165Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
7/9/2020 - 19:46:12.198Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
7/9/2020 - 19:46:12.231Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
7/9/2020 - 19:46:12.264Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
7/9/2020 - 19:46:12.297Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
7/9/2020 - 19:46:12.331Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
7/9/2020 - 19:46:12.364Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:12.364Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:12.365Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:12.365Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:12.365Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:12.365Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
7/9/2020 - 19:46:12.366Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:12.401Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:12.435Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:12.471Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:12.506Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:12.549Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.583Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.583Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.583Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.618Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.651Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.684Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.717Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.750Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a
7/9/2020 - 19:46:12.784Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a
7/9/2020 - 19:46:12.784Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.818Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.851Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.890Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.954Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:12.988Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:13.64Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:13.105Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:13.163Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:13.213Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:13.249Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:13.288Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:13.321Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:13.355Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:13.397Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:13.498Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:13.498Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
7/9/2020 - 19:46:13.534Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:13.534Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
7/9/2020 - 19:46:13.534Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:13.567Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:13.600Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:13.633Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:13.666Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:13.700Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:13.733Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:13.766Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:13.799Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:13.799Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:13.799Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:13.800Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:13.833Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:13.833Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll
7/9/2020 - 19:46:13.833Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
7/9/2020 - 19:46:13.833Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll
7/9/2020 - 19:46:13.834Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
7/9/2020 - 19:46:13.870Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
7/9/2020 - 19:46:13.903Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
7/9/2020 - 19:46:13.936Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
7/9/2020 - 19:46:13.936Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
7/9/2020 - 19:46:13.936Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:13.936Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
7/9/2020 - 19:46:13.937Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:13.937Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:13.940Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:13.940Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:13.941Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll
7/9/2020 - 19:46:13.941Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll
7/9/2020 - 19:46:13.941Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
7/9/2020 - 19:46:13.941Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll
7/9/2020 - 19:46:13.941Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
7/9/2020 - 19:46:13.941Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
7/9/2020 - 19:46:13.943Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:13.982Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:14.52Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:14.87Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:14.121Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:14.154Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:14.188Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:14.256Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:14.303Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:14.356Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:14.393Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:14.426Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:14.460Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:14.496Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:14.533Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:14.569Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:14.604Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:14.637Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:14.670Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:14.706Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:14.739Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:14.772Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:14.805Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:14.838Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:14.875Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:14.909Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:14.977Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dll
7/9/2020 - 19:46:15.44Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.44Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dll
7/9/2020 - 19:46:15.44Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.78Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.111Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.144Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.179Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.212Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.246Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.279Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089
7/9/2020 - 19:46:15.312Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089
7/9/2020 - 19:46:15.312Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.346Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.379Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.413Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.484Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.533Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
7/9/2020 - 19:46:15.587Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
7/9/2020 - 19:46:15.587Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
7/9/2020 - 19:46:15.587Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
7/9/2020 - 19:46:15.625Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
7/9/2020 - 19:46:15.658Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
7/9/2020 - 19:46:15.691Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
7/9/2020 - 19:46:15.725Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
7/9/2020 - 19:46:15.731Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
7/9/2020 - 19:46:15.732Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
7/9/2020 - 19:46:15.732Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
7/9/2020 - 19:46:15.732Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:15.733Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:15.733Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:15.735Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
7/9/2020 - 19:46:15.735Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
7/9/2020 - 19:46:15.736Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
7/9/2020 - 19:46:15.736Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
7/9/2020 - 19:46:15.737Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.770Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.803Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.803Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.804Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.804Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.805Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:15.808Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:15.814Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:15.815Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:15.815Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.815Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.815Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.816Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.816Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.816Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.817Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.817Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.818Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.818Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.818Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.819Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.819Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.819Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.820Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:15.820Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:15.820Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.821Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.822Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.822Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.822Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.822Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.890Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.890Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.892Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:15.930Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:15.969Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:16.2Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:16.2Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.2Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.2Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.3Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.37Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.70Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.103Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.136Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.169Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.203Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.236Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.269Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:16.269Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:16.270Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.270Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.270Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.270Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.270Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.270Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:16.272Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:16.306Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dll
7/9/2020 - 19:46:16.373Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.373Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dll
7/9/2020 - 19:46:16.373Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.406Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.439Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.472Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.505Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.574Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.607Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.640Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a
7/9/2020 - 19:46:16.717Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a
7/9/2020 - 19:46:16.717Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.763Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.817Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.855Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.888Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.921Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.955Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:16.988Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:17.21Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:17.54Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:17.87Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:17.156Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.190Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.190Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.190Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.223Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.256Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.290Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.323Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.356Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.389Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a
7/9/2020 - 19:46:17.457Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a
7/9/2020 - 19:46:17.457Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.493Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.527Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.562Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.596Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.629Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.663Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.696Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:17.737Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:17.770Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:17.770Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll
7/9/2020 - 19:46:17.804Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
7/9/2020 - 19:46:17.804Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll
7/9/2020 - 19:46:17.804Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
7/9/2020 - 19:46:17.839Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
7/9/2020 - 19:46:17.909Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
7/9/2020 - 19:46:17.954Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
7/9/2020 - 19:46:18.10Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
7/9/2020 - 19:46:18.48Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:18.48Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35
7/9/2020 - 19:46:18.49Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll
7/9/2020 - 19:46:18.49Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll
7/9/2020 - 19:46:18.49Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
7/9/2020 - 19:46:18.49Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll
7/9/2020 - 19:46:18.50Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
7/9/2020 - 19:46:18.50Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
7/9/2020 - 19:46:18.50Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:18.136Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:18.170Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:18.204Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:18.237Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:18.271Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:18.305Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Globalization\en.nlp
7/9/2020 - 19:46:18.306Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.config
7/9/2020 - 19:46:18.307Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\Microsoft.PowerShell.ConsoleHost.resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:18.307Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:18.307Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:18.308Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.308Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.308Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.308Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.342Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.375Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.409Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.442Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:18.442Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:18.443Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.443Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.443Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.443Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.444Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.444Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
7/9/2020 - 19:46:18.445Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:18.524Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:18.597Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:18.636Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
7/9/2020 - 19:46:18.672Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:18.706Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:18.739Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:18.782Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:18.818Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:18.852Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:18.852Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:18.881Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:18.934Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:18.967Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:18.967Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:18.968Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:19.2Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:19.3Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:19.3Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:19.4Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:19.4Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:19.5Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:19.20Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:19.21Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:19.75Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:19.108Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:19.176Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:19.225Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:19.278Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:19.318Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:19.352Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:19.385Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:19.418Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:19.453Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:19.488Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:19.527Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:19.560Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:19.599Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:19.632Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:19.710Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:19.748Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:19.785Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:19.818Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:19.855Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:19.888Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:19.921Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:19.955Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:19.988Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.21Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.54Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.87Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.121Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.154Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.187Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.220Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.253Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.287Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.323Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.416Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.461Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.495Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.528Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.561Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:20.596Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.703Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:20.736Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:20.774Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:20.813Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:20.847Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:20.884Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.920Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:20.957Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:21.25Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:21.64Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:21.99Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:21.133Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:21.170Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:21.205Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:21.241Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:21.274Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:21.317Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:21.389Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:21.428Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:21.461Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:21.500Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:21.534Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:21.630Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:21.724Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:21.769Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:21.805Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:21.839Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:21.873Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:21.906Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:21.940Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:21.973Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:22.6Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.73Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.73Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.73Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.106Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.139Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.172Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.206Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.239Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.272Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.305Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.338Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a
7/9/2020 - 19:46:22.405Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a
7/9/2020 - 19:46:22.405Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.444Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.478Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.512Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.545Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.579Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.612Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.645Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.678Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.746Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.791Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.841Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:22.882Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:22.922Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:22.975Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:23.8Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:23.41Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:23.75Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:23.108Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:23.141Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:23.181Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:23.216Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Management.Automation.resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:23.216Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:23.250Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:23.250Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.285Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.285Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.285Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.319Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.352Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.385Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.418Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.452Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:23.453Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:23.454Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.454Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.454Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.454Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.454Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.454Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.455Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:23.490Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:23.529Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:23.562Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:23.595Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:23.628Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\shfolder.dll
7/9/2020 - 19:46:23.629Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shfolder.dll
7/9/2020 - 19:46:23.663Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shfolder.dll
7/9/2020 - 19:46:23.892Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Documents
7/9/2020 - 19:46:23.892Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Documents
7/9/2020 - 19:46:23.929Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:23.970Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:24.116Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:24.173Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:24.229Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:24.262Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:46:24.262Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:46:24.264Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xml
7/9/2020 - 19:46:24.298Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
7/9/2020 - 19:46:24.299Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xml
7/9/2020 - 19:46:24.333Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:24.380Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:24.416Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:24.449Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:24.483Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:24.516Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:24.549Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:24.583Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:24.616Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:24.649Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:24.682Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:24.715Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:24.752Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:24.788Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:24.821Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:24.873Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:24.906Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:24.939Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xml
7/9/2020 - 19:46:24.939Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
7/9/2020 - 19:46:24.939Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
7/9/2020 - 19:46:24.941Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
7/9/2020 - 19:46:24.941Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
7/9/2020 - 19:46:24.941Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
7/9/2020 - 19:46:24.941Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
7/9/2020 - 19:46:24.941Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
7/9/2020 - 19:46:24.981Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:25.14Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:25.47Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:25.81Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:25.121Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xml
7/9/2020 - 19:46:25.122Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
7/9/2020 - 19:46:25.122Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:25.166Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.200Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.267Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.313Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.366Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.403Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.436Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.469Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.503Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.537Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.574Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.611Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.644Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.677Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.710Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.747Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:25.817Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:25.873Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:25.909Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:25.942Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:25.976Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:26.9Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:26.107Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:26.195Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:26.229Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:26.438Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:26.493Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:26.568Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:26.801Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xml
7/9/2020 - 19:46:26.801Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:26.801Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:26.802Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:26.803Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:26.871Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:26.904Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.47Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.47Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.47Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.47Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.48Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.48Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.48Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.48Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.48Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.48Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.48Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.49Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.49Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.49Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.49Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.49Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.49Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.50Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.50Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.50Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.50Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.50Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.50Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.50Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.50Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.50Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.51Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.51Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.51Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.51Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.51Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.52Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.52Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.52Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.52Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.52Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.52Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.52Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.52Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.53Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.53Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xml
7/9/2020 - 19:46:27.53Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
7/9/2020 - 19:46:27.62Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.63Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.143Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.176Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.209Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.243Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.282Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.315Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.348Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.381Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.415Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.448Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.481Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.515Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.554Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.587Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.621Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.655Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.723Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.805Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.849Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.901Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:27.936Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:27.969Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:28.3Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:28.37Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:28.75Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:28.176Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.345Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:28.378Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:28.423Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.528Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.562Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.595Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.629Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.663Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.696Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.729Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.763Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.796Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.830Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.871Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.909Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.947Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:28.980Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.13Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.46Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.80Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.120Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.153Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.186Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.219Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.288Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.333Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.384Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.421Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.456Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.490Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.524Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.557Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.590Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.624Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.659Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:29.692Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:29.725Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:29.758Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:29.791Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:29.825Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:29.863Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:29.896Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:29.929Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:29.963Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:29.997Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:30.30Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:30.63Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:30.96Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:30.130Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:30.167Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:30.202Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:30.238Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
7/9/2020 - 19:46:30.271Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:30.304Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:30.337Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:30.371Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:30.405Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:30.438Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:30.506Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:30.559Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:30.613Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
7/9/2020 - 19:46:30.660Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:30.758Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:30.795Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:30.829Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:30.866Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:30.902Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:30.935Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:30.968Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:31.70Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:46:31.70Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
7/9/2020 - 19:46:31.70Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml
7/9/2020 - 19:46:31.104Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
7/9/2020 - 19:46:31.104Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xml
7/9/2020 - 19:46:31.137Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
7/9/2020 - 19:46:31.137Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml
7/9/2020 - 19:46:31.170Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
7/9/2020 - 19:46:31.170Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml
7/9/2020 - 19:46:31.170Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:31.171Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xml
7/9/2020 - 19:46:31.172Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
7/9/2020 - 19:46:31.172Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml
7/9/2020 - 19:46:31.207Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:31.207Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml
7/9/2020 - 19:46:31.240Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:31.240Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml
7/9/2020 - 19:46:31.273Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
7/9/2020 - 19:46:31.273Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml
7/9/2020 - 19:46:31.273Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
7/9/2020 - 19:46:31.323Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:31.356Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:31.391Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:31.427Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\tzres.dll
7/9/2020 - 19:46:31.428Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\tzres.dll
7/9/2020 - 19:46:31.428Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\tzres.dll
7/9/2020 - 19:46:31.428Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\tzres.dll
7/9/2020 - 19:46:31.439Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.477Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml
7/9/2020 - 19:46:31.480Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
7/9/2020 - 19:46:31.480Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
7/9/2020 - 19:46:31.481Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:31.484Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
7/9/2020 - 19:46:31.484Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
7/9/2020 - 19:46:31.484Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
7/9/2020 - 19:46:31.484Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
7/9/2020 - 19:46:31.484Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
7/9/2020 - 19:46:31.484Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
7/9/2020 - 19:46:31.485Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
7/9/2020 - 19:46:31.485Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
7/9/2020 - 19:46:31.485Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml
7/9/2020 - 19:46:31.485Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
7/9/2020 - 19:46:31.487Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.488Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.488Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.489Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.490Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.490Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.493Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.493Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.495Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.495Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:31.533Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.567Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.740Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xml
7/9/2020 - 19:46:31.740Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
7/9/2020 - 19:46:31.740Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
7/9/2020 - 19:46:31.741Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
7/9/2020 - 19:46:31.741Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
7/9/2020 - 19:46:31.741Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
7/9/2020 - 19:46:31.741Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
7/9/2020 - 19:46:31.742Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
7/9/2020 - 19:46:31.742Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
7/9/2020 - 19:46:31.742Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
7/9/2020 - 19:46:31.742Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xml
7/9/2020 - 19:46:31.742Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
7/9/2020 - 19:46:31.836Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:31.892Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml
7/9/2020 - 19:46:31.892Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
7/9/2020 - 19:46:31.892Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
7/9/2020 - 19:46:31.893Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
7/9/2020 - 19:46:31.893Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
7/9/2020 - 19:46:31.893Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
7/9/2020 - 19:46:31.893Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
7/9/2020 - 19:46:31.893Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
7/9/2020 - 19:46:31.893Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
7/9/2020 - 19:46:31.894Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
7/9/2020 - 19:46:31.894Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
7/9/2020 - 19:46:31.894Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml
7/9/2020 - 19:46:31.894Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
7/9/2020 - 19:46:31.999Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:32.37Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:32.73Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:32.173Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.174Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.174Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.175Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.208Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.208Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.208Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.208Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.208Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.208Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.208Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.209Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.209Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.209Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.209Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.209Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.209Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.209Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.210Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.210Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.210Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.210Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.210Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.211Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
7/9/2020 - 19:46:32.214Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:32.215Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:32.216Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:32.249Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:32.282Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:32.315Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
7/9/2020 - 19:46:32.357Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xml
7/9/2020 - 19:46:32.358Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
7/9/2020 - 19:46:32.358Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
7/9/2020 - 19:46:32.359Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
7/9/2020 - 19:46:32.359Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
7/9/2020 - 19:46:32.359Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
7/9/2020 - 19:46:32.359Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
7/9/2020 - 19:46:32.359Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
7/9/2020 - 19:46:32.359Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
7/9/2020 - 19:46:32.359Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
7/9/2020 - 19:46:32.359Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xml
7/9/2020 - 19:46:32.359Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
7/9/2020 - 19:46:32.361Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml
7/9/2020 - 19:46:32.361Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.361Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.362Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.396Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.396Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.396Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.396Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.396Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.396Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.396Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.396Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.396Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.397Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.397Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.397Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.397Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.397Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.398Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.398Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.398Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.398Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.398Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.398Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.398Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.398Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.398Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.399Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.399Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.399Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.399Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.399Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.399Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.399Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.400Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.400Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.400Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.400Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.400Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.400Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.400Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.400Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.400Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.401Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.401Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.401Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.401Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.401Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.401Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.401Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.401Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.401Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.438Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.438Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.438Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.438Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.438Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.438Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.438Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.438Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.438Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.438Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.439Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.439Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.439Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.439Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.439Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.439Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml
7/9/2020 - 19:46:32.439Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
7/9/2020 - 19:46:32.446Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:32.499Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.499Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.500Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.500Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.500Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.500Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.500Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.505Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.505Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.505Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.505Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.505Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.505Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.541Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.542Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
7/9/2020 - 19:46:32.558Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml
7/9/2020 - 19:46:32.558Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
7/9/2020 - 19:46:32.558Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
7/9/2020 - 19:46:32.559Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
7/9/2020 - 19:46:32.559Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
7/9/2020 - 19:46:32.559Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
7/9/2020 - 19:46:32.560Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
7/9/2020 - 19:46:32.560Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
7/9/2020 - 19:46:32.560Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
7/9/2020 - 19:46:32.560Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml
7/9/2020 - 19:46:32.560Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
7/9/2020 - 19:46:32.561Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml
7/9/2020 - 19:46:32.561Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
7/9/2020 - 19:46:32.561Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
7/9/2020 - 19:46:32.562Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
7/9/2020 - 19:46:32.562Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
7/9/2020 - 19:46:32.562Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
7/9/2020 - 19:46:32.562Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
7/9/2020 - 19:46:32.562Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
7/9/2020 - 19:46:32.562Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
7/9/2020 - 19:46:32.562Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml
7/9/2020 - 19:46:32.562Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
7/9/2020 - 19:46:32.629Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:32.717Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
7/9/2020 - 19:46:32.762Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:32.847Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\Microsoft.WSMan.Management.resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:32.848Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:32.848Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:32.848Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:32.849Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:32.849Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:32.849Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:32.883Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:32.916Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:32.950Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:32.983Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:32.983Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:32.983Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:32.984Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:32.984Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:32.984Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:32.984Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:32.984Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
7/9/2020 - 19:46:33.50Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.84Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.159Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.198Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.252Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.286Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.319Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.418Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.452Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.486Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.520Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.554Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.595Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:33.665Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\secur32.dll
7/9/2020 - 19:46:33.666Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\secur32.dll
7/9/2020 - 19:46:33.666Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\secur32.dll
7/9/2020 - 19:46:33.666Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\secur32.dll
7/9/2020 - 19:46:33.666Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\SSPICLI.DLL
7/9/2020 - 19:46:33.666Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\sspicli.dll
7/9/2020 - 19:46:33.666Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\sspicli.dll
7/9/2020 - 19:46:33.667Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:33.704Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:33.739Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:33.783Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:33.822Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:34.98Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:34.104Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:46:34.104Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
7/9/2020 - 19:46:34.104Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:34.109Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:34.109Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:34.143Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.144Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.144Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.144Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.153Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.153Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.154Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.154Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.155Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.155Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.193Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:34.199Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
7/9/2020 - 19:46:34.202Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:34.250Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
7/9/2020 - 19:46:34.291Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\Microsoft.PowerShell.Security.resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:34.292Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:34.293Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:34.293Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll
7/9/2020 - 19:46:34.293Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
7/9/2020 - 19:46:34.293Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll
7/9/2020 - 19:46:34.293Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
7/9/2020 - 19:46:34.294Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
7/9/2020 - 19:46:34.294Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
7/9/2020 - 19:46:34.295Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:34.295Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
7/9/2020 - 19:46:34.295Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll
7/9/2020 - 19:46:34.295Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll
7/9/2020 - 19:46:34.296Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
7/9/2020 - 19:46:34.296Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll
7/9/2020 - 19:46:34.296Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
7/9/2020 - 19:46:34.296Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
7/9/2020 - 19:46:34.681Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:34.715Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:34.804Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.804Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.804Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.804Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.870Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.870Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.870Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.870Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
7/9/2020 - 19:46:34.870Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.870Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.870Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.871Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.872Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.872Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.872Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.872Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.872Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:34.919Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:34.919Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:35.13Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:35.14Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:35.16Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:35.16Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:35.216Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:35.270Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:35.339Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:35.373Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:35.406Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:35.439Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:35.472Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
7/9/2020 - 19:46:35.542Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:35.830Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:35.885Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dll
7/9/2020 - 19:46:35.975Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:35.975Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dll
7/9/2020 - 19:46:35.975Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.8Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.42Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.76Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.109Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.143Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.176Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.209Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.246Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.279Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.312Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.378Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.412Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.445Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.478Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089
7/9/2020 - 19:46:36.545Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089
7/9/2020 - 19:46:36.545Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.579Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.612Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.677Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.710Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.744Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:36.777Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
7/9/2020 - 19:46:36.810Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:36.810Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
7/9/2020 - 19:46:36.810Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:36.843Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:36.876Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:36.910Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:36.943Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:36.976Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:37.54Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
7/9/2020 - 19:46:37.62Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:37.62Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:37.63Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:37.64Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
7/9/2020 - 19:46:37.64Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:37.64Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:37.64Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:37.66Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:37.73Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:37.73Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:37.74Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:37.74Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.107Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.107Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.108Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.109Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.110Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.110Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.147Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.147Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.148Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
7/9/2020 - 19:46:37.164Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.165Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.166Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.166Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.166Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.167Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.170Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.171Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.226Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:37.259Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:37.292Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:37.327Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:37.363Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:37.396Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:37.625Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.659Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.692Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.725Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.758Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.791Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.825Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.858Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.891Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.924Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.958Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:37.991Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.24Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.57Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.90Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.124Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.157Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.191Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.224Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.293Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.338Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.390Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.428Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.463Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.497Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.530Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.563Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.597Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.651Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.721Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:38.908Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\profile.ps1
7/9/2020 - 19:46:38.909Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Microsoft.PowerShell_profile.ps1
7/9/2020 - 19:46:38.909Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Documents\WindowsPowerShell\profile.ps1
7/9/2020 - 19:46:38.909Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1
7/9/2020 - 19:46:39.141Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:39.175Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:39.365Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
7/9/2020 - 19:46:39.531Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:39.679Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:39.735Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:39.828Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:39.867Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:39.901Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:39.934Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:39.967Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:40.0Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:40.275Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:40.309Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Globalization\en-us.nlp
7/9/2020 - 19:46:40.310Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089
7/9/2020 - 19:46:40.310Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089
7/9/2020 - 19:46:40.376Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089
7/9/2020 - 19:46:40.376Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
7/9/2020 - 19:46:40.444Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
7/9/2020 - 19:46:40.444Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
7/9/2020 - 19:46:40.444Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
7/9/2020 - 19:46:40.478Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
7/9/2020 - 19:46:40.511Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
7/9/2020 - 19:46:40.544Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
7/9/2020 - 19:46:40.578Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
7/9/2020 - 19:46:40.611Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089
7/9/2020 - 19:46:40.611Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089
7/9/2020 - 19:46:40.611Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
7/9/2020 - 19:46:40.612Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
7/9/2020 - 19:46:40.612Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
7/9/2020 - 19:46:40.612Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
7/9/2020 - 19:46:40.612Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
7/9/2020 - 19:46:40.612Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
7/9/2020 - 19:46:40.613Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
7/9/2020 - 19:46:40.895Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:41.2Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:41.37Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:41.79Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:41.124Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:41.294Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.329Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.362Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.395Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.428Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.461Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.496Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.530Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.564Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.598Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.632Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.666Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.700Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.734Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:41.963Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
7/9/2020 - 19:46:42.0Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
7/9/2020 - 19:46:42.69Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.110Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.144Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.178Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.270Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:42.304Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:42.338Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:42.374Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.414Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.467Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.504Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.538Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.571Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.672Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\RpcRtRemote.dll
7/9/2020 - 19:46:42.673Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\RpcRtRemote.dll
7/9/2020 - 19:46:42.673Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\RpcRtRemote.dllRpcRtRemote.dll
7/9/2020 - 19:46:42.673Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\RpcRtRemote.dll
7/9/2020 - 19:46:42.673Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\RpcRtRemote.dllRpcRtRemote.dll
7/9/2020 - 19:46:42.708Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.708Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll
7/9/2020 - 19:46:42.742Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
7/9/2020 - 19:46:42.742Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll
7/9/2020 - 19:46:42.742Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
7/9/2020 - 19:46:42.775Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
7/9/2020 - 19:46:42.775Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
7/9/2020 - 19:46:42.776Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll
7/9/2020 - 19:46:42.782Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
7/9/2020 - 19:46:42.782Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
7/9/2020 - 19:46:42.783Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
7/9/2020 - 19:46:42.783Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:42.783Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:42.783Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:42.783Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
7/9/2020 - 19:46:42.907Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.942Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:42.976Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wmiutils.dll
7/9/2020 - 19:46:42.977Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wmiutils.dll
7/9/2020 - 19:46:42.977Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wbemcomn.dll
7/9/2020 - 19:46:42.978Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbemcomn.dll
7/9/2020 - 19:46:42.978Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbemcomn.dll
7/9/2020 - 19:46:42.979Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\Logs
7/9/2020 - 19:46:42.979Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\Logs
7/9/2020 - 19:46:42.980Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wbemprox.dll
7/9/2020 - 19:46:43.14Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wbemprox.dll
7/9/2020 - 19:46:43.48Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:43.90Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll
7/9/2020 - 19:46:43.126Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\nlaapi.dll
7/9/2020 - 19:46:43.126Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\nlaapi.dll
7/9/2020 - 19:46:43.127Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\NapiNSP.dll
7/9/2020 - 19:46:43.127Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\NapiNSP.dll
7/9/2020 - 19:46:43.196Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\pnrpnsp.dll
7/9/2020 - 19:46:43.197Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\pnrpnsp.dll
7/9/2020 - 19:46:43.263Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\mswsock.dll
7/9/2020 - 19:46:43.263Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\mswsock.dll
7/9/2020 - 19:46:43.264Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DNSAPI.dll
7/9/2020 - 19:46:43.264Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\dnsapi.dll
7/9/2020 - 19:46:43.264Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\dnsapi.dll
7/9/2020 - 19:46:43.265Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\winrnr.dll
7/9/2020 - 19:46:43.266Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\winrnr.dll
7/9/2020 - 19:46:43.340Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\IPHLPAPI.DLL
7/9/2020 - 19:46:43.340Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\IPHLPAPI.DLL
7/9/2020 - 19:46:43.341Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\IPHLPAPI.DLL
7/9/2020 - 19:46:43.341Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WINNSI.DLL
7/9/2020 - 19:46:43.342Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\winnsi.dll
7/9/2020 - 19:46:43.342Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\winnsi.dll
7/9/2020 - 19:46:43.378Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\FWPUCLNT.DLL
7/9/2020 - 19:46:43.378Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\FWPUCLNT.DLL
7/9/2020 - 19:46:43.448Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\rasadhlp.dll
7/9/2020 - 19:46:43.449Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rasadhlp.dll
7/9/2020 - 19:46:43.449Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rasadhlp.dll
7/9/2020 - 19:46:43.650Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wbemsvc.dll
7/9/2020 - 19:46:43.650Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wbemsvc.dll
7/9/2020 - 19:46:43.692Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\fastprox.dll
7/9/2020 - 19:46:43.692Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\fastprox.dll
7/9/2020 - 19:46:43.693Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\NTDSAPI.dll
7/9/2020 - 19:46:43.693Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\ntdsapi.dll
7/9/2020 - 19:46:43.693Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\ntdsapi.dll
7/9/2020 - 19:46:44.73Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:45.711Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:45.716Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:45.957Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:46.29Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\pt-BR\wmiutils.dll.mui
7/9/2020 - 19:46:46.29Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\system32\wbem\pt\wmiutils.dll.mui
7/9/2020 - 19:46:46.30Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\en-US\wmiutils.dll.mui
7/9/2020 - 19:46:46.63Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\en-US\wmiutils.dll.muiwmiutils.dll.mui
7/9/2020 - 19:46:46.429Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:46.476Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:46.517Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:46.550Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
7/9/2020 - 19:46:47.66Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:47.99Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
7/9/2020 - 19:46:47.132Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
7/9/2020 - 19:46:48.960Read2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
7/9/2020 - 19:46:49.76Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch.2476.1121640
7/9/2020 - 19:46:49.76Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch.2476.1121640
7/9/2020 - 19:46:49.77Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch.2476.1121765
7/9/2020 - 19:46:49.78Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\netutils.dll
7/9/2020 - 19:46:49.78Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\netutils.dll
7/9/2020 - 19:46:49.79Open2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\netutils.dll
7/9/2020 - 19:46:49.88Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
7/9/2020 - 19:46:49.89Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\pt-BR\powershell.exe.muipowershell.exe.mui
7/9/2020 - 19:46:49.89Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
7/9/2020 - 19:46:49.89Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_14556c1e8b95d0b8
7/9/2020 - 19:46:49.89Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:49.89Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:49.90Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\pt-BR\KernelBase.dll.muiKernelBase.dll.mui
7/9/2020 - 19:46:49.90Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:49.90Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:49.90Unknown2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
7/9/2020 - 19:46:49.99Open1480C:\malware.exeC:\
7/9/2020 - 19:46:49.100Unknown1480C:\malware.exeC:\
7/9/2020 - 19:46:49.100Open1480C:\malware.exeC:\
7/9/2020 - 19:46:49.100Unknown1480C:\malware.exeC:\
7/9/2020 - 19:46:49.100Open1480C:\malware.exeC:\43cd2k60-readme.txt
7/9/2020 - 19:46:49.100Write1480C:\malware.exeC:\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.101Unknown1480C:\malware.exeC:\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.101Open1480C:\malware.exeC:\
7/9/2020 - 19:46:49.101Open1480C:\malware.exeC:\Monitor
7/9/2020 - 19:46:49.101Unknown1480C:\malware.exeC:\Monitor
7/9/2020 - 19:46:49.101Open1480C:\malware.exeC:\Monitor
7/9/2020 - 19:46:49.101Unknown1480C:\malware.exeC:\Monitor
7/9/2020 - 19:46:49.102Open1480C:\malware.exeC:\Monitor\43cd2k60-readme.txt
7/9/2020 - 19:46:49.102Write1480C:\malware.exeC:\Monitor\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.103Unknown1480C:\malware.exeC:\Monitor\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.103Open1480C:\malware.exeC:\Program Files
7/9/2020 - 19:46:49.103Unknown1480C:\malware.exeC:\Program Files
7/9/2020 - 19:46:49.103Open1480C:\malware.exeC:\Program Files
7/9/2020 - 19:46:49.103Unknown1480C:\malware.exeC:\Program Files
7/9/2020 - 19:46:49.103Open1480C:\malware.exeC:\Program Files\43cd2k60-readme.txt
7/9/2020 - 19:46:49.104Write1480C:\malware.exeC:\Program Files\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.104Unknown1480C:\malware.exeC:\Program Files\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.104Open1480C:\malware.exeC:\Program Files (x86)
7/9/2020 - 19:46:49.104Unknown1480C:\malware.exeC:\Program Files (x86)
7/9/2020 - 19:46:49.104Open1480C:\malware.exeC:\Program Files (x86)
7/9/2020 - 19:46:49.104Unknown1480C:\malware.exeC:\Program Files (x86)
7/9/2020 - 19:46:49.104Open1480C:\malware.exeC:\Program Files (x86)\43cd2k60-readme.txt
7/9/2020 - 19:46:49.105Write1480C:\malware.exeC:\Program Files (x86)\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.105Unknown1480C:\malware.exeC:\Program Files (x86)\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.105Open1480C:\malware.exeC:\Recovery
7/9/2020 - 19:46:49.105Unknown1480C:\malware.exeC:\Recovery
7/9/2020 - 19:46:49.105Open1480C:\malware.exeC:\Recovery
7/9/2020 - 19:46:49.106Unknown1480C:\malware.exeC:\Recovery
7/9/2020 - 19:46:49.106Open1480C:\malware.exeC:\Recovery\43cd2k60-readme.txt
7/9/2020 - 19:46:49.106Write1480C:\malware.exeC:\Recovery\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.106Unknown1480C:\malware.exeC:\Recovery\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.106Open1480C:\malware.exeC:\Users
7/9/2020 - 19:46:49.122Unknown1480C:\malware.exeC:\Users
7/9/2020 - 19:46:49.122Open1480C:\malware.exeC:\Users
7/9/2020 - 19:46:49.122Unknown1480C:\malware.exeC:\Users
7/9/2020 - 19:46:49.122Open1480C:\malware.exeC:\Users\43cd2k60-readme.txt
7/9/2020 - 19:46:49.122Write1480C:\malware.exeC:\Users\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.123Unknown1480C:\malware.exeC:\Users\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.123Unknown1480C:\malware.exeC:\
7/9/2020 - 19:46:49.123Open1480C:\malware.exeC:\Monitor
7/9/2020 - 19:46:49.123Open1480C:\malware.exeC:\Monitor\Files
7/9/2020 - 19:46:49.123Unknown1480C:\malware.exeC:\Monitor\Files
7/9/2020 - 19:46:49.123Open1480C:\malware.exeC:\Monitor\Files
7/9/2020 - 19:46:49.123Unknown1480C:\malware.exeC:\Monitor\Files
7/9/2020 - 19:46:49.123Open1480C:\malware.exeC:\Monitor\Files\43cd2k60-readme.txt
7/9/2020 - 19:46:49.124Write1480C:\malware.exeC:\Monitor\Files\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.124Unknown1480C:\malware.exeC:\Monitor\Files\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.124Open1480C:\malware.exeC:\Monitor\Malware
7/9/2020 - 19:46:49.124Unknown1480C:\malware.exeC:\Monitor\Malware
7/9/2020 - 19:46:49.124Open1480C:\malware.exeC:\Monitor\Malware
7/9/2020 - 19:46:49.124Unknown1480C:\malware.exeC:\Monitor\Malware
7/9/2020 - 19:46:49.125Open1480C:\malware.exeC:\43cd2k60-readme.txt
7/9/2020 - 19:46:49.125Write1480C:\malware.exeC:\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.125Unknown1480C:\malware.exeC:\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.125Open1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:46:49.125Unknown1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:46:49.125Open1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:46:49.125Unknown1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:46:49.125Open1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\43cd2k60-readme.txt
7/9/2020 - 19:46:49.125Write1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.125Unknown1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.125Unknown1480C:\malware.exeC:\Monitor
7/9/2020 - 19:46:49.125Open1480C:\malware.exeC:\Program Files
7/9/2020 - 19:46:49.125Unknown1480C:\malware.exeC:\Program Files
7/9/2020 - 19:46:49.125Open1480C:\malware.exeC:\Program Files (x86)
7/9/2020 - 19:46:49.125Unknown1480C:\malware.exeC:\Program Files (x86)
7/9/2020 - 19:46:49.125Open1480C:\malware.exeC:\Recovery
7/9/2020 - 19:46:49.126Open1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
7/9/2020 - 19:46:49.126Unknown1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
7/9/2020 - 19:46:49.126Open1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
7/9/2020 - 19:46:49.126Unknown1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
7/9/2020 - 19:46:49.126Open1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\43cd2k60-readme.txt
7/9/2020 - 19:46:49.126Write1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.127Unknown1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.127Unknown1480C:\malware.exeC:\Recovery
7/9/2020 - 19:46:49.127Open1480C:\malware.exeC:\Users
7/9/2020 - 19:46:49.127Open1480C:\malware.exeC:\Users\Behemot
7/9/2020 - 19:46:49.127Unknown1480C:\malware.exeC:\Users\Behemot
7/9/2020 - 19:46:49.127Open1480C:\malware.exeC:\Users\Behemot
7/9/2020 - 19:46:49.128Unknown1480C:\malware.exeC:\Users\Behemot
7/9/2020 - 19:46:49.128Open1480C:\malware.exeC:\Users\Behemot\43cd2k60-readme.txt
7/9/2020 - 19:46:49.128Write1480C:\malware.exeC:\Users\Behemot\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.128Unknown1480C:\malware.exeC:\Users\Behemot\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.128Open1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:46:49.129Unknown1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:46:49.129Open1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:46:49.129Unknown1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:46:49.129Open1480C:\malware.exeC:\Users\Default\43cd2k60-readme.txt
7/9/2020 - 19:46:49.129Write1480C:\malware.exeC:\Users\Default\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.130Unknown1480C:\malware.exeC:\Users\Default\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.130Open1480C:\malware.exeC:\Users\Public
7/9/2020 - 19:46:49.130Unknown1480C:\malware.exeC:\Users\Public
7/9/2020 - 19:46:49.130Open1480C:\malware.exeC:\Users\Public
7/9/2020 - 19:46:49.130Unknown1480C:\malware.exeC:\Users\Public
7/9/2020 - 19:46:49.130Open1480C:\malware.exeC:\Users\Public\43cd2k60-readme.txt
7/9/2020 - 19:46:49.131Write1480C:\malware.exeC:\Users\Public\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.131Unknown1480C:\malware.exeC:\Users\Public\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.131Unknown1480C:\malware.exeC:\Users
7/9/2020 - 19:46:49.131Open1480C:\malware.exeC:\Monitor\Files
7/9/2020 - 19:46:49.131Open1480C:\malware.exeC:\Monitor\Files\DeletedFiles
7/9/2020 - 19:46:49.131Unknown1480C:\malware.exeC:\Monitor\Files\DeletedFiles
7/9/2020 - 19:46:49.132Open1480C:\malware.exeC:\Monitor\Files\DeletedFiles
7/9/2020 - 19:46:49.132Unknown1480C:\malware.exeC:\Monitor\Files\DeletedFiles
7/9/2020 - 19:46:49.132Open1480C:\malware.exeC:\Monitor\Files\DeletedFiles\43cd2k60-readme.txt
7/9/2020 - 19:46:49.132Write1480C:\malware.exeC:\Monitor\Files\DeletedFiles\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.132Unknown1480C:\malware.exeC:\Monitor\Files\DeletedFiles\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.132Open1480C:\malware.exeC:\Monitor\Files\Logs
7/9/2020 - 19:46:49.132Unknown1480C:\malware.exeC:\Monitor\Files\Logs
7/9/2020 - 19:46:49.132Open1480C:\malware.exeC:\Monitor\Files\Logs
7/9/2020 - 19:46:49.133Unknown1480C:\malware.exeC:\Monitor\Files\Logs
7/9/2020 - 19:46:49.133Open1480C:\malware.exeC:\Monitor\Files\Logs\43cd2k60-readme.txt
7/9/2020 - 19:46:49.134Write1480C:\malware.exeC:\Monitor\Files\Logs\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.134Unknown1480C:\malware.exeC:\Monitor\Files\Logs\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.134Unknown1480C:\malware.exeC:\Monitor\Files
7/9/2020 - 19:46:49.134Open1480C:\malware.exeC:\Monitor\Malware
7/9/2020 - 19:46:49.134Unknown1480C:\malware.exeC:\Monitor\Malware
7/9/2020 - 19:46:49.134Open1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:46:49.134Open1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
7/9/2020 - 19:46:49.134Read1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:46:49.134Read1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:46:49.166Open1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
7/9/2020 - 19:46:49.167Open1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
7/9/2020 - 19:46:49.167Read1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:46:49.168Open1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
7/9/2020 - 19:46:49.169Unknown1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:46:49.169Open1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
7/9/2020 - 19:46:49.170Open1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/9/2020 - 19:46:49.170Read1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/9/2020 - 19:46:49.171Read1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/9/2020 - 19:46:49.184Open1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/9/2020 - 19:46:49.195Open1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/9/2020 - 19:46:49.195Read1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/9/2020 - 19:46:49.196Read1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/9/2020 - 19:46:49.196Open1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/9/2020 - 19:46:49.198Unknown1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
7/9/2020 - 19:46:49.198Open1480C:\malware.exeC:\Users\Behemot
7/9/2020 - 19:46:49.199Open1480C:\malware.exeC:\Users\Behemot\Contacts
7/9/2020 - 19:46:49.199Unknown1480C:\malware.exeC:\Users\Behemot\Contacts
7/9/2020 - 19:46:49.199Open1480C:\malware.exeC:\Users\Behemot\Contacts
7/9/2020 - 19:46:49.199Unknown1480C:\malware.exeC:\Users\Behemot\Contacts
7/9/2020 - 19:46:49.199Open1480C:\malware.exeC:\Users\Behemot\Contacts\43cd2k60-readme.txt
7/9/2020 - 19:46:49.200Write1480C:\malware.exeC:\Users\Behemot\Contacts\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.200Unknown1480C:\malware.exeC:\Users\Behemot\Contacts\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.200Open1480C:\malware.exeC:\Users\Behemot\Desktop
7/9/2020 - 19:46:49.201Unknown1480C:\malware.exeC:\Users\Behemot\Desktop
7/9/2020 - 19:46:49.201Open1480C:\malware.exeC:\Users\Behemot\Desktop
7/9/2020 - 19:46:49.201Unknown1480C:\malware.exeC:\Users\Behemot\Desktop
7/9/2020 - 19:46:49.201Open1480C:\malware.exeC:\Users\Behemot\Desktop\43cd2k60-readme.txt
7/9/2020 - 19:46:49.202Write1480C:\malware.exeC:\Users\Behemot\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.204Unknown1480C:\malware.exeC:\Users\Behemot\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.204Open1480C:\malware.exeC:\Users\Behemot\Documents
7/9/2020 - 19:46:49.205Unknown1480C:\malware.exeC:\Users\Behemot\Documents
7/9/2020 - 19:46:49.205Open1480C:\malware.exeC:\Users\Behemot\Documents
7/9/2020 - 19:46:49.205Unknown1480C:\malware.exeC:\Users\Behemot\Documents
7/9/2020 - 19:46:49.205Open1480C:\malware.exeC:\Users\Behemot\Documents\43cd2k60-readme.txt
7/9/2020 - 19:46:49.205Write1480C:\malware.exeC:\Users\Behemot\Documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.206Unknown1480C:\malware.exeC:\Users\Behemot\Documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.206Open1480C:\malware.exeC:\Users\Behemot\Downloads
7/9/2020 - 19:46:49.206Unknown1480C:\malware.exeC:\Users\Behemot\Downloads
7/9/2020 - 19:46:49.206Open1480C:\malware.exeC:\Users\Behemot\Downloads
7/9/2020 - 19:46:49.207Unknown1480C:\malware.exeC:\Users\Behemot\Downloads
7/9/2020 - 19:46:49.207Open1480C:\malware.exeC:\Users\Behemot\Downloads\43cd2k60-readme.txt
7/9/2020 - 19:46:49.208Write1480C:\malware.exeC:\Users\Behemot\Downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.208Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.208Open1480C:\malware.exeC:\Users\Behemot\Favorites
7/9/2020 - 19:46:49.209Unknown1480C:\malware.exeC:\Users\Behemot\Favorites
7/9/2020 - 19:46:49.209Open1480C:\malware.exeC:\Users\Behemot\Favorites
7/9/2020 - 19:46:49.209Unknown1480C:\malware.exeC:\Users\Behemot\Favorites
7/9/2020 - 19:46:49.210Open1480C:\malware.exeC:\Users\Behemot\Favorites\43cd2k60-readme.txt
7/9/2020 - 19:46:49.210Write1480C:\malware.exeC:\Users\Behemot\Favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.211Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.211Open1480C:\malware.exeC:\Users\Behemot\Links
7/9/2020 - 19:46:49.211Unknown1480C:\malware.exeC:\Users\Behemot\Links
7/9/2020 - 19:46:49.211Open1480C:\malware.exeC:\Users\Behemot\Links
7/9/2020 - 19:46:49.212Unknown1480C:\malware.exeC:\Users\Behemot\Links
7/9/2020 - 19:46:49.212Open1480C:\malware.exeC:\Users\Behemot\Links\43cd2k60-readme.txt
7/9/2020 - 19:46:49.213Write1480C:\malware.exeC:\Users\Behemot\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.213Unknown1480C:\malware.exeC:\Users\Behemot\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.213Open1480C:\malware.exeC:\Users\Behemot\Music
7/9/2020 - 19:46:49.214Unknown1480C:\malware.exeC:\Users\Behemot\Music
7/9/2020 - 19:46:49.214Open1480C:\malware.exeC:\Users\Behemot\Music
7/9/2020 - 19:46:49.214Unknown1480C:\malware.exeC:\Users\Behemot\Music
7/9/2020 - 19:46:49.214Open1480C:\malware.exeC:\Users\Behemot\Music\43cd2k60-readme.txt
7/9/2020 - 19:46:49.215Write1480C:\malware.exeC:\Users\Behemot\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.215Unknown1480C:\malware.exeC:\Users\Behemot\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:46:49.215Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:49.216Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:49.216Open1480C:\malware.exeC:\Windows\SysWOW64\uxtheme.dll
7/9/2020 - 19:46:49.217Open1480C:\malware.exeC:\Windows\SysWOW64\uxtheme.dll
7/9/2020 - 19:46:49.280Read1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:46:49.280Read1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:46:49.281Read1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/9/2020 - 19:46:49.281Read1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/9/2020 - 19:46:49.335Read1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/9/2020 - 19:46:49.335Read1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/9/2020 - 19:46:49.372Open1480C:\malware.exeC:\Windows\SysWOW64\bcryptprimitives.dll
7/9/2020 - 19:46:49.372Unknown1480C:\malware.exeC:\Windows\SysWOW64\bcryptprimitives.dllbcryptprimitives.dll
7/9/2020 - 19:46:49.372Open1480C:\malware.exeC:\Windows\SysWOW64\bcryptprimitives.dll
7/9/2020 - 19:46:49.373Unknown1480C:\malware.exeC:\Windows\SysWOW64\bcryptprimitives.dllbcryptprimitives.dll
7/9/2020 - 19:46:49.380Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:49.380Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:49.380Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:49.391Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:49.393Write1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:46:49.393Write1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:46:49.403Write1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/9/2020 - 19:46:49.412Write1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/9/2020 - 19:46:49.413Write1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:46:49.413Write1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:46:49.413Write1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/9/2020 - 19:46:49.413Write1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/9/2020 - 19:46:49.413Unknown1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:46:49.413Open1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
7/9/2020 - 19:46:49.414Open1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:46:49.414Unknown1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:46:49.414Unknown1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:46:49.451Unknown1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/9/2020 - 19:46:49.451Open1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/9/2020 - 19:46:49.451Open1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
7/9/2020 - 19:46:49.451Unknown1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/9/2020 - 19:46:49.452Unknown1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:46:49.452Open1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
7/9/2020 - 19:46:49.452Open1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:46:49.452Unknown1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:46:49.453Unknown1480C:\malware.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:46:49.488Unknown1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
7/9/2020 - 19:46:49.488Unknown1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/9/2020 - 19:46:49.489Open1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/9/2020 - 19:46:49.489Open1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
7/9/2020 - 19:46:49.489Unknown1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/9/2020 - 19:46:49.489Unknown1480C:\malware.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
7/9/2020 - 19:46:50.396Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:50.399Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:50.399Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:50.400Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:50.452Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:51.470Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:51.475Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:51.475Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:51.475Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:51.519Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:52.535Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:52.535Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:52.535Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:52.538Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:52.538Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:52.539Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:52.579Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:52.579Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:52.579Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:52.620Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:53.649Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:53.652Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:53.652Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:53.652Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:53.693Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:53.693Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:53.693Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:53.731Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:54.740Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:54.742Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:54.743Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:54.743Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:54.783Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:54.783Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:54.783Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:54.821Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:55.830Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:55.831Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:55.831Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:55.833Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:55.833Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:55.833Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:55.875Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:55.875Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:55.876Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:55.916Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:55.916Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:55.917Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:55.958Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:56.979Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:56.981Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:56.981Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:56.982Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:57.22Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:57.22Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:57.22Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:57.60Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:57.60Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:57.60Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:57.99Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:58.112Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:58.116Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:58.116Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:58.116Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:58.159Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:58.160Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:58.160Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:58.203Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:58.203Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:58.203Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:58.280Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:59.324Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:59.324Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:46:59.325Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:46:59.327Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:59.328Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:59.328Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:59.412Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:46:59.413Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:59.414Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:59.458Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:46:59.458Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:59.458Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:59.501Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:46:59.502Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:46:59.502Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:46:59.578Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:0.615Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:0.620Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:0.620Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:0.620Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:0.671Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:0.671Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:0.671Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:0.711Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:0.711Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:0.712Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:0.784Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:0.784Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:0.784Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:0.825Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:1.860Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:1.863Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:1.863Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:1.864Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:1.904Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:1.904Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:1.905Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:1.945Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:1.945Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:1.946Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:1.986Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:1.986Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:1.987Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:2.58Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:3.69Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:3.70Open1480C:\malware.exeC:\Users\Behemot\Pictures
7/9/2020 - 19:47:3.71Unknown1480C:\malware.exeC:\Users\Behemot\Pictures
7/9/2020 - 19:47:3.71Open1480C:\malware.exeC:\Users\Behemot\Pictures
7/9/2020 - 19:47:3.71Unknown1480C:\malware.exeC:\Users\Behemot\Pictures
7/9/2020 - 19:47:3.71Open1480C:\malware.exeC:\Users\Behemot\Pictures\43cd2k60-readme.txt
7/9/2020 - 19:47:3.72Write1480C:\malware.exeC:\Users\Behemot\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.73Unknown1480C:\malware.exeC:\Users\Behemot\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.73Open1480C:\malware.exeC:\Users\Behemot\Saved Games
7/9/2020 - 19:47:3.73Unknown1480C:\malware.exeC:\Users\Behemot\Saved Games
7/9/2020 - 19:47:3.73Open1480C:\malware.exeC:\Users\Behemot\Saved Games
7/9/2020 - 19:47:3.74Unknown1480C:\malware.exeC:\Users\Behemot\Saved Games
7/9/2020 - 19:47:3.74Open1480C:\malware.exeC:\Users\Behemot\Saved Games\43cd2k60-readme.txt
7/9/2020 - 19:47:3.74Write1480C:\malware.exeC:\Users\Behemot\Saved Games\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.75Unknown1480C:\malware.exeC:\Users\Behemot\Saved Games\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.75Open1480C:\malware.exeC:\Users\Behemot\Searches
7/9/2020 - 19:47:3.75Unknown1480C:\malware.exeC:\Users\Behemot\Searches
7/9/2020 - 19:47:3.76Open1480C:\malware.exeC:\Users\Behemot\Searches
7/9/2020 - 19:47:3.76Unknown1480C:\malware.exeC:\Users\Behemot\Searches
7/9/2020 - 19:47:3.76Open1480C:\malware.exeC:\Users\Behemot\Searches\43cd2k60-readme.txt
7/9/2020 - 19:47:3.144Write1480C:\malware.exeC:\Users\Behemot\Searches\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.145Unknown1480C:\malware.exeC:\Users\Behemot\Searches\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.145Open1480C:\malware.exeC:\Users\Behemot\Videos
7/9/2020 - 19:47:3.145Unknown1480C:\malware.exeC:\Users\Behemot\Videos
7/9/2020 - 19:47:3.145Open1480C:\malware.exeC:\Users\Behemot\Videos
7/9/2020 - 19:47:3.146Unknown1480C:\malware.exeC:\Users\Behemot\Videos
7/9/2020 - 19:47:3.146Open1480C:\malware.exeC:\Users\Behemot\Videos\43cd2k60-readme.txt
7/9/2020 - 19:47:3.146Write1480C:\malware.exeC:\Users\Behemot\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.147Unknown1480C:\malware.exeC:\Users\Behemot\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.147Unknown1480C:\malware.exeC:\Users\Behemot
7/9/2020 - 19:47:3.148Open1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:47:3.148Open1480C:\malware.exeC:\Users\Default\Desktop
7/9/2020 - 19:47:3.148Unknown1480C:\malware.exeC:\Users\Default\Desktop
7/9/2020 - 19:47:3.149Open1480C:\malware.exeC:\Users\Default\Desktop
7/9/2020 - 19:47:3.149Unknown1480C:\malware.exeC:\Users\Default\Desktop
7/9/2020 - 19:47:3.149Open1480C:\malware.exeC:\Users\Default\Desktop\43cd2k60-readme.txt
7/9/2020 - 19:47:3.149Write1480C:\malware.exeC:\Users\Default\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.150Unknown1480C:\malware.exeC:\Users\Default\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.150Open1480C:\malware.exeC:\Users\Default\Documents
7/9/2020 - 19:47:3.150Unknown1480C:\malware.exeC:\Users\Default\Documents
7/9/2020 - 19:47:3.151Open1480C:\malware.exeC:\Users\Default\Documents
7/9/2020 - 19:47:3.151Unknown1480C:\malware.exeC:\Users\Default\Documents
7/9/2020 - 19:47:3.151Read1480C:\malware.exeC:\Users\Default\Documents
7/9/2020 - 19:47:3.151Open1480C:\malware.exeC:\Users\Default\Documents\43cd2k60-readme.txt
7/9/2020 - 19:47:3.213Write1480C:\malware.exeC:\Users\Default\Documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.213Unknown1480C:\malware.exeC:\Users\Default\Documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.213Open1480C:\malware.exeC:\Users\Default\Downloads
7/9/2020 - 19:47:3.214Unknown1480C:\malware.exeC:\Users\Default\Downloads
7/9/2020 - 19:47:3.215Open1480C:\malware.exeC:\Users\Default\Downloads
7/9/2020 - 19:47:3.215Unknown1480C:\malware.exeC:\Users\Default\Downloads
7/9/2020 - 19:47:3.215Open1480C:\malware.exeC:\Users\Default\Downloads\43cd2k60-readme.txt
7/9/2020 - 19:47:3.265Write1480C:\malware.exeC:\Users\Default\Downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.265Unknown1480C:\malware.exeC:\Users\Default\Downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.265Open1480C:\malware.exeC:\Users\Default\Favorites
7/9/2020 - 19:47:3.321Unknown1480C:\malware.exeC:\Users\Default\Favorites
7/9/2020 - 19:47:3.321Open1480C:\malware.exeC:\Users\Default\Favorites
7/9/2020 - 19:47:3.321Unknown1480C:\malware.exeC:\Users\Default\Favorites
7/9/2020 - 19:47:3.321Open1480C:\malware.exeC:\Users\Default\Favorites\43cd2k60-readme.txt
7/9/2020 - 19:47:3.322Write1480C:\malware.exeC:\Users\Default\Favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.322Unknown1480C:\malware.exeC:\Users\Default\Favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.322Open1480C:\malware.exeC:\Users\Default\Links
7/9/2020 - 19:47:3.323Unknown1480C:\malware.exeC:\Users\Default\Links
7/9/2020 - 19:47:3.323Open1480C:\malware.exeC:\Users\Default\Links
7/9/2020 - 19:47:3.323Unknown1480C:\malware.exeC:\Users\Default\Links
7/9/2020 - 19:47:3.323Open1480C:\malware.exeC:\Users\Default\Links\43cd2k60-readme.txt
7/9/2020 - 19:47:3.324Write1480C:\malware.exeC:\Users\Default\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.324Unknown1480C:\malware.exeC:\Users\Default\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.324Open1480C:\malware.exeC:\Users\Default\Music
7/9/2020 - 19:47:3.324Unknown1480C:\malware.exeC:\Users\Default\Music
7/9/2020 - 19:47:3.325Open1480C:\malware.exeC:\Users\Default\Music
7/9/2020 - 19:47:3.325Unknown1480C:\malware.exeC:\Users\Default\Music
7/9/2020 - 19:47:3.325Open1480C:\malware.exeC:\Users\Default\Music\43cd2k60-readme.txt
7/9/2020 - 19:47:3.325Write1480C:\malware.exeC:\Users\Default\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.326Unknown1480C:\malware.exeC:\Users\Default\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.326Open1480C:\malware.exeC:\Users\Default\NTUSER.DAT.LOG1
7/9/2020 - 19:47:3.326Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
7/9/2020 - 19:47:3.326Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
7/9/2020 - 19:47:3.327Open1480C:\malware.exeC:\Users\Default\NTUSER.DAT.LOG1
7/9/2020 - 19:47:3.329Open1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:3.329Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:3.329Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:3.330Open1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:3.331Open1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:3.332Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:3.332Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:3.332Open1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:3.333Open1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:3.334Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:3.334Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:3.334Open1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:3.336Open1480C:\malware.exeC:\Users\Default\Pictures
7/9/2020 - 19:47:3.337Unknown1480C:\malware.exeC:\Users\Default\Pictures
7/9/2020 - 19:47:3.337Open1480C:\malware.exeC:\Users\Default\Pictures
7/9/2020 - 19:47:3.337Unknown1480C:\malware.exeC:\Users\Default\Pictures
7/9/2020 - 19:47:3.337Open1480C:\malware.exeC:\Users\Default\Pictures\43cd2k60-readme.txt
7/9/2020 - 19:47:3.338Write1480C:\malware.exeC:\Users\Default\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.339Unknown1480C:\malware.exeC:\Users\Default\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.339Open1480C:\malware.exeC:\Users\Default\Saved Games
7/9/2020 - 19:47:3.339Unknown1480C:\malware.exeC:\Users\Default\Saved Games
7/9/2020 - 19:47:3.339Open1480C:\malware.exeC:\Users\Default\Saved Games
7/9/2020 - 19:47:3.340Unknown1480C:\malware.exeC:\Users\Default\Saved Games
7/9/2020 - 19:47:3.340Open1480C:\malware.exeC:\Users\Default\Saved Games\43cd2k60-readme.txt
7/9/2020 - 19:47:3.340Write1480C:\malware.exeC:\Users\Default\Saved Games\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.341Unknown1480C:\malware.exeC:\Users\Default\Saved Games\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.341Open1480C:\malware.exeC:\Users\Default\Videos
7/9/2020 - 19:47:3.341Unknown1480C:\malware.exeC:\Users\Default\Videos
7/9/2020 - 19:47:3.341Open1480C:\malware.exeC:\Users\Default\Videos
7/9/2020 - 19:47:3.342Unknown1480C:\malware.exeC:\Users\Default\Videos
7/9/2020 - 19:47:3.342Open1480C:\malware.exeC:\Users\Default\Videos\43cd2k60-readme.txt
7/9/2020 - 19:47:3.342Write1480C:\malware.exeC:\Users\Default\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.343Unknown1480C:\malware.exeC:\Users\Default\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.343Unknown1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:47:3.343Open1480C:\malware.exeC:\Users\Public
7/9/2020 - 19:47:3.343Open1480C:\malware.exeC:\Users\Public\Desktop
7/9/2020 - 19:47:3.343Unknown1480C:\malware.exeC:\Users\Public\Desktop
7/9/2020 - 19:47:3.344Open1480C:\malware.exeC:\Users\Public\Desktop
7/9/2020 - 19:47:3.344Unknown1480C:\malware.exeC:\Users\Public\Desktop
7/9/2020 - 19:47:3.344Open1480C:\malware.exeC:\Users\Public\Desktop\43cd2k60-readme.txt
7/9/2020 - 19:47:3.344Write1480C:\malware.exeC:\Users\Public\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.346Unknown1480C:\malware.exeC:\Users\Public\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.346Open1480C:\malware.exeC:\Users\Public\Documents
7/9/2020 - 19:47:3.346Unknown1480C:\malware.exeC:\Users\Public\Documents
7/9/2020 - 19:47:3.346Open1480C:\malware.exeC:\Users\Public\Documents
7/9/2020 - 19:47:3.347Unknown1480C:\malware.exeC:\Users\Public\Documents
7/9/2020 - 19:47:3.347Open1480C:\malware.exeC:\Users\Public\Documents\43cd2k60-readme.txt
7/9/2020 - 19:47:3.348Write1480C:\malware.exeC:\Users\Public\Documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.348Unknown1480C:\malware.exeC:\Users\Public\Documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.348Open1480C:\malware.exeC:\Users\Public\Downloads
7/9/2020 - 19:47:3.349Unknown1480C:\malware.exeC:\Users\Public\Downloads
7/9/2020 - 19:47:3.349Open1480C:\malware.exeC:\Users\Public\Downloads
7/9/2020 - 19:47:3.349Unknown1480C:\malware.exeC:\Users\Public\Downloads
7/9/2020 - 19:47:3.349Open1480C:\malware.exeC:\Users\Public\Downloads\43cd2k60-readme.txt
7/9/2020 - 19:47:3.350Write1480C:\malware.exeC:\Users\Public\Downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.350Unknown1480C:\malware.exeC:\Users\Public\Downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.350Open1480C:\malware.exeC:\Users\Public\Favorites
7/9/2020 - 19:47:3.351Unknown1480C:\malware.exeC:\Users\Public\Favorites
7/9/2020 - 19:47:3.351Open1480C:\malware.exeC:\Users\Public\Favorites
7/9/2020 - 19:47:3.351Unknown1480C:\malware.exeC:\Users\Public\Favorites
7/9/2020 - 19:47:3.351Open1480C:\malware.exeC:\Users\Public\Favorites\43cd2k60-readme.txt
7/9/2020 - 19:47:3.352Write1480C:\malware.exeC:\Users\Public\Favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.352Unknown1480C:\malware.exeC:\Users\Public\Favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.352Open1480C:\malware.exeC:\Users\Public\Libraries
7/9/2020 - 19:47:3.353Unknown1480C:\malware.exeC:\Users\Public\Libraries
7/9/2020 - 19:47:3.353Open1480C:\malware.exeC:\Users\Public\Libraries
7/9/2020 - 19:47:3.353Unknown1480C:\malware.exeC:\Users\Public\Libraries
7/9/2020 - 19:47:3.353Open1480C:\malware.exeC:\Users\Public\Libraries\43cd2k60-readme.txt
7/9/2020 - 19:47:3.354Write1480C:\malware.exeC:\Users\Public\Libraries\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.354Unknown1480C:\malware.exeC:\Users\Public\Libraries\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.354Open1480C:\malware.exeC:\Users\Public\Music
7/9/2020 - 19:47:3.354Unknown1480C:\malware.exeC:\Users\Public\Music
7/9/2020 - 19:47:3.355Open1480C:\malware.exeC:\Users\Public\Music
7/9/2020 - 19:47:3.355Unknown1480C:\malware.exeC:\Users\Public\Music
7/9/2020 - 19:47:3.355Open1480C:\malware.exeC:\Users\Public\Music\43cd2k60-readme.txt
7/9/2020 - 19:47:3.356Write1480C:\malware.exeC:\Users\Public\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.356Unknown1480C:\malware.exeC:\Users\Public\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.356Open1480C:\malware.exeC:\Users\Public\Pictures
7/9/2020 - 19:47:3.357Unknown1480C:\malware.exeC:\Users\Public\Pictures
7/9/2020 - 19:47:3.357Open1480C:\malware.exeC:\Users\Public\Pictures
7/9/2020 - 19:47:3.357Unknown1480C:\malware.exeC:\Users\Public\Pictures
7/9/2020 - 19:47:3.357Open1480C:\malware.exeC:\Users\Public\Pictures\43cd2k60-readme.txt
7/9/2020 - 19:47:3.358Write1480C:\malware.exeC:\Users\Public\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.358Unknown1480C:\malware.exeC:\Users\Public\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.358Open1480C:\malware.exeC:\Users\Public\Recorded TV
7/9/2020 - 19:47:3.359Unknown1480C:\malware.exeC:\Users\Public\Recorded TV
7/9/2020 - 19:47:3.359Open1480C:\malware.exeC:\Users\Public\Recorded TV
7/9/2020 - 19:47:3.359Unknown1480C:\malware.exeC:\Users\Public\Recorded TV
7/9/2020 - 19:47:3.359Open1480C:\malware.exeC:\Users\Public\Recorded TV\43cd2k60-readme.txt
7/9/2020 - 19:47:3.361Write1480C:\malware.exeC:\Users\Public\Recorded TV\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.362Unknown1480C:\malware.exeC:\Users\Public\Recorded TV\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.362Open1480C:\malware.exeC:\Users\Public\Videos
7/9/2020 - 19:47:3.362Unknown1480C:\malware.exeC:\Users\Public\Videos
7/9/2020 - 19:47:3.363Open1480C:\malware.exeC:\Users\Public\Videos
7/9/2020 - 19:47:3.363Unknown1480C:\malware.exeC:\Users\Public\Videos
7/9/2020 - 19:47:3.363Open1480C:\malware.exeC:\Users\Public\Videos\43cd2k60-readme.txt
7/9/2020 - 19:47:3.363Write1480C:\malware.exeC:\Users\Public\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.364Unknown1480C:\malware.exeC:\Users\Public\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.364Unknown1480C:\malware.exeC:\Users\Public
7/9/2020 - 19:47:3.364Open1480C:\malware.exeC:\Monitor\Files\DeletedFiles
7/9/2020 - 19:47:3.364Unknown1480C:\malware.exeC:\Monitor\Files\DeletedFiles
7/9/2020 - 19:47:3.364Open1480C:\malware.exeC:\Monitor\Files\Logs
7/9/2020 - 19:47:3.365Unknown1480C:\malware.exeC:\Monitor\Files\Logs
7/9/2020 - 19:47:3.365Open1480C:\malware.exeC:\Users\Behemot\Contacts
7/9/2020 - 19:47:3.365Open1480C:\malware.exeC:\Users\Behemot\Contacts\Behemot.contact
7/9/2020 - 19:47:3.365Read1480C:\malware.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/9/2020 - 19:47:3.365Read1480C:\malware.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/9/2020 - 19:47:3.366Open1480C:\malware.exeC:\Users\Behemot\Contacts\Behemot.contact
7/9/2020 - 19:47:3.368Unknown1480C:\malware.exeC:\Users\Behemot\Contacts
7/9/2020 - 19:47:3.368Open1480C:\malware.exeC:\Users\Behemot\Desktop
7/9/2020 - 19:47:3.368Unknown1480C:\malware.exeC:\Users\Behemot\Desktop
7/9/2020 - 19:47:3.368Open1480C:\malware.exeC:\Users\Behemot\Documents
7/9/2020 - 19:47:3.368Unknown1480C:\malware.exeC:\Users\Behemot\Documents
7/9/2020 - 19:47:3.368Open1480C:\malware.exeC:\Users\Behemot\Downloads
7/9/2020 - 19:47:3.369Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor
7/9/2020 - 19:47:3.369Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor
7/9/2020 - 19:47:3.369Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor
7/9/2020 - 19:47:3.370Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor
7/9/2020 - 19:47:3.370Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\43cd2k60-readme.txt
7/9/2020 - 19:47:3.371Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.371Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.371Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor.zip
7/9/2020 - 19:47:3.371Read1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor.zip
7/9/2020 - 19:47:3.372Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor.zip
7/9/2020 - 19:47:3.374Unknown1480C:\malware.exeC:\Users\Behemot\Downloads
7/9/2020 - 19:47:3.374Open1480C:\malware.exeC:\Users\Behemot\Favorites
7/9/2020 - 19:47:3.374Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links
7/9/2020 - 19:47:3.375Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links
7/9/2020 - 19:47:3.375Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links
7/9/2020 - 19:47:3.375Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links
7/9/2020 - 19:47:3.375Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links\43cd2k60-readme.txt
7/9/2020 - 19:47:3.375Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.376Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.376Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:47:3.376Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:47:3.377Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:47:3.377Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:47:3.377Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\43cd2k60-readme.txt
7/9/2020 - 19:47:3.377Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.378Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.378Unknown1480C:\malware.exeC:\Users\Behemot\Favorites
7/9/2020 - 19:47:3.378Open1480C:\malware.exeC:\Users\Behemot\Links
7/9/2020 - 19:47:3.378Unknown1480C:\malware.exeC:\Users\Behemot\Links
7/9/2020 - 19:47:3.378Open1480C:\malware.exeC:\Users\Behemot\Music
7/9/2020 - 19:47:3.379Unknown1480C:\malware.exeC:\Users\Behemot\Music
7/9/2020 - 19:47:3.379Open1480C:\malware.exeC:\Users\Behemot\Pictures
7/9/2020 - 19:47:3.379Unknown1480C:\malware.exeC:\Users\Behemot\Pictures
7/9/2020 - 19:47:3.379Open1480C:\malware.exeC:\Users\Behemot\Saved Games
7/9/2020 - 19:47:3.379Unknown1480C:\malware.exeC:\Users\Behemot\Saved Games
7/9/2020 - 19:47:3.379Open1480C:\malware.exeC:\Users\Behemot\Searches
7/9/2020 - 19:47:3.380Open1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-ms
7/9/2020 - 19:47:3.380Read1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/9/2020 - 19:47:3.380Read1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/9/2020 - 19:47:3.380Open1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-ms
7/9/2020 - 19:47:3.380Open1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-ms
7/9/2020 - 19:47:3.381Unknown1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/9/2020 - 19:47:3.381Open1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-ms
7/9/2020 - 19:47:3.381Unknown1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/9/2020 - 19:47:3.381Open1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-ms
7/9/2020 - 19:47:3.382Unknown1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/9/2020 - 19:47:3.382Open1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-ms
7/9/2020 - 19:47:3.382Unknown1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/9/2020 - 19:47:3.382Unknown1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/9/2020 - 19:47:3.382Open1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-ms
7/9/2020 - 19:47:3.433Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
7/9/2020 - 19:47:3.433Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
7/9/2020 - 19:47:3.434Open1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
7/9/2020 - 19:47:3.434Read1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/9/2020 - 19:47:3.434Open1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
7/9/2020 - 19:47:3.435Open1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
7/9/2020 - 19:47:3.435Unknown1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/9/2020 - 19:47:3.435Open1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
7/9/2020 - 19:47:3.436Unknown1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/9/2020 - 19:47:3.436Open1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
7/9/2020 - 19:47:3.436Unknown1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/9/2020 - 19:47:3.436Open1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
7/9/2020 - 19:47:3.437Unknown1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/9/2020 - 19:47:3.437Unknown1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/9/2020 - 19:47:3.437Open1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
7/9/2020 - 19:47:3.439Unknown1480C:\malware.exeC:\Users\Behemot\Searches
7/9/2020 - 19:47:3.439Open1480C:\malware.exeC:\Users\Behemot\Videos
7/9/2020 - 19:47:3.439Unknown1480C:\malware.exeC:\Users\Behemot\Videos
7/9/2020 - 19:47:3.439Open1480C:\malware.exeC:\Users\Default\Desktop
7/9/2020 - 19:47:3.440Unknown1480C:\malware.exeC:\Users\Default\Desktop
7/9/2020 - 19:47:3.440Open1480C:\malware.exeC:\Users\Default\Documents
7/9/2020 - 19:47:3.440Unknown1480C:\malware.exeC:\Users\Default\Documents
7/9/2020 - 19:47:3.440Open1480C:\malware.exeC:\Users\Default\Downloads
7/9/2020 - 19:47:3.440Unknown1480C:\malware.exeC:\Users\Default\Downloads
7/9/2020 - 19:47:3.440Open1480C:\malware.exeC:\Users\Default\Favorites
7/9/2020 - 19:47:3.441Unknown1480C:\malware.exeC:\Users\Default\Favorites
7/9/2020 - 19:47:3.441Open1480C:\malware.exeC:\Users\Default\Links
7/9/2020 - 19:47:3.441Unknown1480C:\malware.exeC:\Users\Default\Links
7/9/2020 - 19:47:3.441Open1480C:\malware.exeC:\Users\Default\Music
7/9/2020 - 19:47:3.441Unknown1480C:\malware.exeC:\Users\Default\Music
7/9/2020 - 19:47:3.441Open1480C:\malware.exeC:\Users\Default\Pictures
7/9/2020 - 19:47:3.442Unknown1480C:\malware.exeC:\Users\Default\Pictures
7/9/2020 - 19:47:3.442Open1480C:\malware.exeC:\Users\Default\Saved Games
7/9/2020 - 19:47:3.442Unknown1480C:\malware.exeC:\Users\Default\Saved Games
7/9/2020 - 19:47:3.442Open1480C:\malware.exeC:\Users\Default\Videos
7/9/2020 - 19:47:3.442Unknown1480C:\malware.exeC:\Users\Default\Videos
7/9/2020 - 19:47:3.442Open1480C:\malware.exeC:\Users\Public\Desktop
7/9/2020 - 19:47:3.442Unknown1480C:\malware.exeC:\Users\Public\Desktop
7/9/2020 - 19:47:3.443Open1480C:\malware.exeC:\Users\Public\Documents
7/9/2020 - 19:47:3.443Unknown1480C:\malware.exeC:\Users\Public\Documents
7/9/2020 - 19:47:3.443Open1480C:\malware.exeC:\Users\Public\Downloads
7/9/2020 - 19:47:3.443Unknown1480C:\malware.exeC:\Users\Public\Downloads
7/9/2020 - 19:47:3.443Open1480C:\malware.exeC:\Users\Public\Favorites
7/9/2020 - 19:47:3.443Unknown1480C:\malware.exeC:\Users\Public\Favorites
7/9/2020 - 19:47:3.444Open1480C:\malware.exeC:\Users\Public\Libraries
7/9/2020 - 19:47:3.444Open1480C:\malware.exeC:\Users\Public\Libraries\RecordedTV.library-ms
7/9/2020 - 19:47:3.444Read1480C:\malware.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/9/2020 - 19:47:3.444Read1480C:\malware.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/9/2020 - 19:47:3.445Open1480C:\malware.exeC:\Users\Public\Libraries\RecordedTV.library-ms
7/9/2020 - 19:47:3.447Unknown1480C:\malware.exeC:\Users\Public\Libraries
7/9/2020 - 19:47:3.447Open1480C:\malware.exeC:\Users\Public\Music
7/9/2020 - 19:47:3.447Open1480C:\malware.exeC:\Users\Public\Music\Sample Music
7/9/2020 - 19:47:3.447Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music
7/9/2020 - 19:47:3.448Open1480C:\malware.exeC:\Users\Public\Music\Sample Music
7/9/2020 - 19:47:3.448Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music
7/9/2020 - 19:47:3.448Open1480C:\malware.exeC:\Users\Public\Music\Sample Music\43cd2k60-readme.txt
7/9/2020 - 19:47:3.449Write1480C:\malware.exeC:\Users\Public\Music\Sample Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.449Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.449Unknown1480C:\malware.exeC:\Users\Public\Music
7/9/2020 - 19:47:3.449Open1480C:\malware.exeC:\Users\Public\Pictures
7/9/2020 - 19:47:3.449Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:3.450Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:3.450Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:3.450Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:3.451Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\43cd2k60-readme.txt
7/9/2020 - 19:47:3.451Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.452Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.452Unknown1480C:\malware.exeC:\Users\Public\Pictures
7/9/2020 - 19:47:3.452Open1480C:\malware.exeC:\Users\Public\Recorded TV
7/9/2020 - 19:47:3.452Open1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media
7/9/2020 - 19:47:3.454Unknown1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media
7/9/2020 - 19:47:3.454Open1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media
7/9/2020 - 19:47:3.454Unknown1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media
7/9/2020 - 19:47:3.455Open1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\43cd2k60-readme.txt
7/9/2020 - 19:47:3.461Write1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.462Unknown1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.462Unknown1480C:\malware.exeC:\Users\Public\Recorded TV
7/9/2020 - 19:47:3.462Open1480C:\malware.exeC:\Users\Public\Videos
7/9/2020 - 19:47:3.462Open1480C:\malware.exeC:\Users\Public\Videos\Sample Videos
7/9/2020 - 19:47:3.463Unknown1480C:\malware.exeC:\Users\Public\Videos\Sample Videos
7/9/2020 - 19:47:3.463Open1480C:\malware.exeC:\Users\Public\Videos\Sample Videos
7/9/2020 - 19:47:3.463Unknown1480C:\malware.exeC:\Users\Public\Videos\Sample Videos
7/9/2020 - 19:47:3.463Open1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\43cd2k60-readme.txt
7/9/2020 - 19:47:3.464Write1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.464Unknown1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.464Unknown1480C:\malware.exeC:\Users\Public\Videos
7/9/2020 - 19:47:3.464Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor
7/9/2020 - 19:47:3.465Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor
7/9/2020 - 19:47:3.465Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor
7/9/2020 - 19:47:3.465Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor
7/9/2020 - 19:47:3.465Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor
7/9/2020 - 19:47:3.466Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\43cd2k60-readme.txt
7/9/2020 - 19:47:3.466Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.466Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.467Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor
7/9/2020 - 19:47:3.467Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links
7/9/2020 - 19:47:3.467Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.url
7/9/2020 - 19:47:3.467Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/9/2020 - 19:47:3.467Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.url
7/9/2020 - 19:47:3.469Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.url
7/9/2020 - 19:47:3.469Read1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/9/2020 - 19:47:3.470Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.url
7/9/2020 - 19:47:3.472Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links
7/9/2020 - 19:47:3.472Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:47:3.472Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.url
7/9/2020 - 19:47:3.472Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/9/2020 - 19:47:3.472Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.url
7/9/2020 - 19:47:3.474Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.url
7/9/2020 - 19:47:3.474Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/9/2020 - 19:47:3.474Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.url
7/9/2020 - 19:47:3.512Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:3.512Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:3.476Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.url
7/9/2020 - 19:47:3.516Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/9/2020 - 19:47:3.516Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.url
7/9/2020 - 19:47:3.522Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:47:3.522Open1480C:\malware.exeC:\Users\Public\Music\Sample Music
7/9/2020 - 19:47:3.522Open1480C:\malware.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/9/2020 - 19:47:3.523Read1480C:\malware.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/9/2020 - 19:47:3.523Read1480C:\malware.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/9/2020 - 19:47:3.537Open1480C:\malware.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/9/2020 - 19:47:3.540Open1480C:\malware.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
7/9/2020 - 19:47:3.541Read1480C:\malware.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/9/2020 - 19:47:3.541Read1480C:\malware.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/9/2020 - 19:47:3.541Open1480C:\malware.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
7/9/2020 - 19:47:3.542Open1480C:\malware.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3
7/9/2020 - 19:47:3.542Read1480C:\malware.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/9/2020 - 19:47:3.542Read1480C:\malware.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/9/2020 - 19:47:3.543Open1480C:\malware.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3
7/9/2020 - 19:47:3.545Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music
7/9/2020 - 19:47:3.545Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:3.545Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
7/9/2020 - 19:47:3.545Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/9/2020 - 19:47:3.545Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/9/2020 - 19:47:3.546Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
7/9/2020 - 19:47:3.548Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/9/2020 - 19:47:3.549Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/9/2020 - 19:47:3.549Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/9/2020 - 19:47:3.549Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/9/2020 - 19:47:3.551Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
7/9/2020 - 19:47:3.552Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/9/2020 - 19:47:3.552Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/9/2020 - 19:47:3.552Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
7/9/2020 - 19:47:3.554Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
7/9/2020 - 19:47:3.554Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/9/2020 - 19:47:3.554Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/9/2020 - 19:47:3.555Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
7/9/2020 - 19:47:3.557Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/9/2020 - 19:47:3.557Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/9/2020 - 19:47:3.557Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/9/2020 - 19:47:3.557Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/9/2020 - 19:47:3.559Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
7/9/2020 - 19:47:3.560Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/9/2020 - 19:47:3.560Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/9/2020 - 19:47:3.560Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
7/9/2020 - 19:47:3.562Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/9/2020 - 19:47:3.563Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/9/2020 - 19:47:3.563Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/9/2020 - 19:47:3.563Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/9/2020 - 19:47:3.565Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/9/2020 - 19:47:3.566Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/9/2020 - 19:47:3.566Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/9/2020 - 19:47:3.566Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/9/2020 - 19:47:3.593Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:3.593Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:3.594Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:3.595Open1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media
7/9/2020 - 19:47:3.595Open1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
7/9/2020 - 19:47:3.629Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:3.629Read1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:3.629Read1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/9/2020 - 19:47:3.630Read1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/9/2020 - 19:47:3.665Open1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
7/9/2020 - 19:47:3.666Unknown1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media
7/9/2020 - 19:47:3.666Open1480C:\malware.exeC:\Users\Public\Videos\Sample Videos
7/9/2020 - 19:47:3.666Open1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/9/2020 - 19:47:3.667Read1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/9/2020 - 19:47:3.667Read1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/9/2020 - 19:47:3.667Open1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/9/2020 - 19:47:3.669Unknown1480C:\malware.exeC:\Users\Public\Videos\Sample Videos
7/9/2020 - 19:47:3.669Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor
7/9/2020 - 19:47:3.669Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
7/9/2020 - 19:47:3.670Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
7/9/2020 - 19:47:3.670Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
7/9/2020 - 19:47:3.671Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
7/9/2020 - 19:47:3.671Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\43cd2k60-readme.txt
7/9/2020 - 19:47:3.671Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.671Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.672Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
7/9/2020 - 19:47:3.672Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
7/9/2020 - 19:47:3.672Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
7/9/2020 - 19:47:3.672Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
7/9/2020 - 19:47:3.673Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware\43cd2k60-readme.txt
7/9/2020 - 19:47:3.673Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.673Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.673Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:47:3.674Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:47:3.674Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:47:3.674Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:47:3.675Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:47:3.674Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\43cd2k60-readme.txt
7/9/2020 - 19:47:3.675Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.675Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.675Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor
7/9/2020 - 19:47:3.676Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
7/9/2020 - 19:47:3.676Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
7/9/2020 - 19:47:3.676Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
7/9/2020 - 19:47:3.676Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
7/9/2020 - 19:47:3.677Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
7/9/2020 - 19:47:3.677Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles\43cd2k60-readme.txt
7/9/2020 - 19:47:3.677Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.678Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.678Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
7/9/2020 - 19:47:3.678Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
7/9/2020 - 19:47:3.678Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
7/9/2020 - 19:47:3.679Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
7/9/2020 - 19:47:3.679Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs\43cd2k60-readme.txt
7/9/2020 - 19:47:3.679Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.680Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:3.680Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
7/9/2020 - 19:47:3.680Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
7/9/2020 - 19:47:3.680Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
7/9/2020 - 19:47:3.680Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:47:3.680Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
7/9/2020 - 19:47:3.681Read1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:47:3.681Read1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:47:3.667Read1480C:\malware.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/9/2020 - 19:47:3.681Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
7/9/2020 - 19:47:3.683Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
7/9/2020 - 19:47:3.683Read1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:47:3.683Read1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:47:3.684Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
7/9/2020 - 19:47:3.686Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:47:3.686Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
7/9/2020 - 19:47:3.686Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
7/9/2020 - 19:47:3.686Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
7/9/2020 - 19:47:3.686Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
7/9/2020 - 19:47:3.684Read1480C:\malware.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/9/2020 - 19:47:3.688Open1480C:\malware.exeC:\Windows\SysWOW64\drprov.dll
7/9/2020 - 19:47:3.689Open1480C:\malware.exeC:\Windows\SysWOW64\drprov.dll
7/9/2020 - 19:47:3.692Open1480C:\malware.exeC:\Windows\SysWOW64\winsta.dll
7/9/2020 - 19:47:3.692Open1480C:\malware.exeC:\Windows\SysWOW64\winsta.dll
7/9/2020 - 19:47:3.693Open1480C:\malware.exeC:\Windows\SysWOW64\ntlanman.dll
7/9/2020 - 19:47:3.694Open1480C:\malware.exeC:\Windows\SysWOW64\ntlanman.dll
7/9/2020 - 19:47:3.697Open1480C:\malware.exeC:\Windows\SysWOW64\davclnt.dll
7/9/2020 - 19:47:3.698Open1480C:\malware.exeC:\Windows\SysWOW64\davclnt.dll
7/9/2020 - 19:47:3.701Open1480C:\malware.exeC:\Windows\SysWOW64\davhlpr.dll
7/9/2020 - 19:47:3.701Open1480C:\malware.exeC:\Windows\SysWOW64\davhlpr.dll
7/9/2020 - 19:47:3.741Read1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor.zip
7/9/2020 - 19:47:3.741Read1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor.zip
7/9/2020 - 19:47:3.774Write1480C:\malware.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
7/9/2020 - 19:47:3.774Read1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/9/2020 - 19:47:3.774Read1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/9/2020 - 19:47:3.774Read1480C:\malware.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/9/2020 - 19:47:3.774Read1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/9/2020 - 19:47:3.774Read1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/9/2020 - 19:47:3.775Read1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/9/2020 - 19:47:3.775Read1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/9/2020 - 19:47:3.775Read1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/9/2020 - 19:47:3.775Read1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/9/2020 - 19:47:3.775Read1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/9/2020 - 19:47:3.776Write1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:3.776Read1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/9/2020 - 19:47:3.776Read1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/9/2020 - 19:47:3.777Read1480C:\malware.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/9/2020 - 19:47:3.777Read1480C:\malware.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/9/2020 - 19:47:3.821Read1480C:\malware.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/9/2020 - 19:47:3.822Read1480C:\malware.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/9/2020 - 19:47:3.825Read1480C:\malware.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/9/2020 - 19:47:3.825Read1480C:\malware.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/9/2020 - 19:47:3.865Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/9/2020 - 19:47:3.866Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/9/2020 - 19:47:3.869Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/9/2020 - 19:47:3.870Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/9/2020 - 19:47:3.878Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/9/2020 - 19:47:3.884Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/9/2020 - 19:47:3.886Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/9/2020 - 19:47:3.886Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/9/2020 - 19:47:3.888Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/9/2020 - 19:47:3.888Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/9/2020 - 19:47:3.891Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/9/2020 - 19:47:3.891Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/9/2020 - 19:47:3.894Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/9/2020 - 19:47:3.895Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/9/2020 - 19:47:3.901Write1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:3.903Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/9/2020 - 19:47:3.904Read1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/9/2020 - 19:47:3.909Write1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:3.912Read1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/9/2020 - 19:47:3.915Read1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/9/2020 - 19:47:3.916Read1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/9/2020 - 19:47:3.917Read1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/9/2020 - 19:47:3.926Read1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:47:3.926Read1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:47:3.927Write1480C:\malware.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/9/2020 - 19:47:3.928Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor.zip
7/9/2020 - 19:47:3.928Write1480C:\malware.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
7/9/2020 - 19:47:3.929Write1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/9/2020 - 19:47:3.929Write1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/9/2020 - 19:47:3.929Write1480C:\malware.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/9/2020 - 19:47:3.929Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/9/2020 - 19:47:3.929Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/9/2020 - 19:47:3.929Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/9/2020 - 19:47:3.929Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/9/2020 - 19:47:3.929Write1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:3.930Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/9/2020 - 19:47:3.941Write1480C:\malware.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/9/2020 - 19:47:3.953Write1480C:\malware.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/9/2020 - 19:47:4.2Write1480C:\malware.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/9/2020 - 19:47:4.10Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/9/2020 - 19:47:4.18Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/9/2020 - 19:47:4.23Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/9/2020 - 19:47:4.63Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/9/2020 - 19:47:4.70Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/9/2020 - 19:47:4.75Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/9/2020 - 19:47:4.76Write1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:4.83Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/9/2020 - 19:47:4.83Write1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:4.88Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/9/2020 - 19:47:4.132Write1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/9/2020 - 19:47:4.133Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:47:4.133Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:47:4.133Write1480C:\malware.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/9/2020 - 19:47:4.133Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor.zip
7/9/2020 - 19:47:4.134Unknown1480C:\malware.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
7/9/2020 - 19:47:4.134Open1480C:\malware.exeC:\Users\Default\NTUSER.DAT.LOG1
7/9/2020 - 19:47:4.134Open1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:47:4.134Unknown1480C:\malware.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
7/9/2020 - 19:47:4.135Unknown1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:47:4.135Write1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/9/2020 - 19:47:4.135Write1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/9/2020 - 19:47:4.135Write1480C:\malware.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/9/2020 - 19:47:4.135Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/9/2020 - 19:47:4.136Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/9/2020 - 19:47:4.136Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/9/2020 - 19:47:4.136Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/9/2020 - 19:47:4.136Unknown1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:4.136Open1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:4.136Open1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:47:4.137Unknown1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:4.137Unknown1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:47:4.137Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/9/2020 - 19:47:4.137Write1480C:\malware.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/9/2020 - 19:47:4.146Write1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/9/2020 - 19:47:4.147Write1480C:\malware.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/9/2020 - 19:47:4.147Write1480C:\malware.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/9/2020 - 19:47:4.147Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/9/2020 - 19:47:4.147Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/9/2020 - 19:47:4.147Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/9/2020 - 19:47:4.147Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/9/2020 - 19:47:4.147Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/9/2020 - 19:47:4.148Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/9/2020 - 19:47:4.148Open1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:4.148Open1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:47:4.149Unknown1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:4.149Unknown1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:47:4.149Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/9/2020 - 19:47:4.150Open1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:4.150Open1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:47:4.150Unknown1480C:\malware.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:4.150Unknown1480C:\malware.exeC:\Users\Default
7/9/2020 - 19:47:4.151Write1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/9/2020 - 19:47:4.151Write1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/9/2020 - 19:47:4.151Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:47:4.151Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:47:4.152Open1480C:\malware.exeC:\Users\Behemot\Contacts\Behemot.contact
7/9/2020 - 19:47:4.152Open1480C:\malware.exeC:\Users\Behemot\Contacts
7/9/2020 - 19:47:4.152Unknown1480C:\malware.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/9/2020 - 19:47:4.152Unknown1480C:\malware.exeC:\Users\Behemot\Contacts
7/9/2020 - 19:47:4.153Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor.zip
7/9/2020 - 19:47:4.153Open1480C:\malware.exeC:\Users\Behemot\Downloads
7/9/2020 - 19:47:4.153Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor.zip
7/9/2020 - 19:47:4.153Unknown1480C:\malware.exeC:\Users\Behemot\Downloads
7/9/2020 - 19:47:4.154Open1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-ms
7/9/2020 - 19:47:4.154Open1480C:\malware.exeC:\Users\Behemot\Searches
7/9/2020 - 19:47:4.154Unknown1480C:\malware.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/9/2020 - 19:47:4.154Unknown1480C:\malware.exeC:\Users\Behemot\Searches
7/9/2020 - 19:47:4.154Open1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
7/9/2020 - 19:47:4.155Open1480C:\malware.exeC:\Users\Behemot\Searches
7/9/2020 - 19:47:4.155Unknown1480C:\malware.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/9/2020 - 19:47:4.155Unknown1480C:\malware.exeC:\Users\Behemot\Searches
7/9/2020 - 19:47:4.155Open1480C:\malware.exeC:\Users\Public\Libraries\RecordedTV.library-ms
7/9/2020 - 19:47:4.156Open1480C:\malware.exeC:\Users\Public\Libraries
7/9/2020 - 19:47:4.156Unknown1480C:\malware.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/9/2020 - 19:47:4.156Unknown1480C:\malware.exeC:\Users\Public\Libraries
7/9/2020 - 19:47:4.156Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.url
7/9/2020 - 19:47:4.156Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links
7/9/2020 - 19:47:4.157Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/9/2020 - 19:47:4.157Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links
7/9/2020 - 19:47:4.157Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/9/2020 - 19:47:4.157Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.url
7/9/2020 - 19:47:4.157Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links
7/9/2020 - 19:47:4.157Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/9/2020 - 19:47:4.158Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links
7/9/2020 - 19:47:4.158Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.url
7/9/2020 - 19:47:4.158Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:47:4.158Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/9/2020 - 19:47:4.158Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:47:4.160Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.url
7/9/2020 - 19:47:4.162Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:47:4.169Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/9/2020 - 19:47:4.169Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:47:4.170Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.url
7/9/2020 - 19:47:4.170Open1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:47:4.170Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/9/2020 - 19:47:4.170Unknown1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:47:4.170Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/9/2020 - 19:47:4.170Open1480C:\malware.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/9/2020 - 19:47:4.171Open1480C:\malware.exeC:\Users\Public\Music\Sample Music
7/9/2020 - 19:47:4.171Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/9/2020 - 19:47:4.171Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music
7/9/2020 - 19:47:4.171Write1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/9/2020 - 19:47:4.171Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/9/2020 - 19:47:4.172Open1480C:\malware.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
7/9/2020 - 19:47:4.172Open1480C:\malware.exeC:\Users\Public\Music\Sample Music
7/9/2020 - 19:47:4.172Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/9/2020 - 19:47:4.172Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music
7/9/2020 - 19:47:4.173Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/9/2020 - 19:47:4.173Open1480C:\malware.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3
7/9/2020 - 19:47:4.173Open1480C:\malware.exeC:\Users\Public\Music\Sample Music
7/9/2020 - 19:47:4.173Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/9/2020 - 19:47:4.173Unknown1480C:\malware.exeC:\Users\Public\Music\Sample Music
7/9/2020 - 19:47:4.174Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/9/2020 - 19:47:4.174Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
7/9/2020 - 19:47:4.174Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.174Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/9/2020 - 19:47:4.174Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.175Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/9/2020 - 19:47:4.175Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/9/2020 - 19:47:4.175Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.175Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/9/2020 - 19:47:4.175Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.244Open1480C:\malware.exeC:\wkscli.dll
7/9/2020 - 19:47:4.244Open1480C:\malware.exeC:\Windows\SysWOW64\wkscli.dll
7/9/2020 - 19:47:4.244Open1480C:\malware.exeC:\Windows\SysWOW64\wkscli.dll
7/9/2020 - 19:47:4.246Open1480C:\malware.exeC:\cscapi.dll
7/9/2020 - 19:47:4.246Open1480C:\malware.exeC:\Windows\SysWOW64\cscapi.dll
7/9/2020 - 19:47:4.247Open1480C:\malware.exeC:\Windows\SysWOW64\cscapi.dll
7/9/2020 - 19:47:4.249Open1480C:\malware.exeC:\netutils.dll
7/9/2020 - 19:47:4.249Open1480C:\malware.exeC:\Windows\SysWOW64\netutils.dll
7/9/2020 - 19:47:4.250Open1480C:\malware.exeC:\Windows\SysWOW64\netutils.dll
7/9/2020 - 19:47:4.250Open1480C:\malware.exeC:\browcli.dll
7/9/2020 - 19:47:4.250Open1480C:\malware.exeC:\Windows\SysWOW64\browcli.dll
7/9/2020 - 19:47:4.251Open1480C:\malware.exeC:\Windows\SysWOW64\browcli.dll
7/9/2020 - 19:47:4.175Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/9/2020 - 19:47:4.259Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
7/9/2020 - 19:47:4.259Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.259Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/9/2020 - 19:47:4.259Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.260Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/9/2020 - 19:47:4.260Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
7/9/2020 - 19:47:4.260Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.260Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/9/2020 - 19:47:4.261Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.261Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/9/2020 - 19:47:4.262Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/9/2020 - 19:47:4.262Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.262Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/9/2020 - 19:47:4.262Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.263Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/9/2020 - 19:47:4.263Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
7/9/2020 - 19:47:4.263Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.263Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/9/2020 - 19:47:4.264Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.264Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/9/2020 - 19:47:4.264Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/9/2020 - 19:47:4.265Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.265Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/9/2020 - 19:47:4.265Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.266Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/9/2020 - 19:47:4.266Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/9/2020 - 19:47:4.266Open1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.266Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/9/2020 - 19:47:4.266Unknown1480C:\malware.exeC:\Users\Public\Pictures\Sample Pictures
7/9/2020 - 19:47:4.267Unknown1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/9/2020 - 19:47:4.267Open1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
7/9/2020 - 19:47:4.267Open1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media
7/9/2020 - 19:47:4.267Unknown1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/9/2020 - 19:47:4.268Unknown1480C:\malware.exeC:\Users\Public\Recorded TV\Sample Media
7/9/2020 - 19:47:4.269Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:47:4.269Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
7/9/2020 - 19:47:4.269Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:47:4.269Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/9/2020 - 19:47:4.270Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:47:4.270Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:47:4.270Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
7/9/2020 - 19:47:4.270Open1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:47:4.271Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/9/2020 - 19:47:4.271Unknown1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/9/2020 - 19:47:4.271Unknown1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/9/2020 - 19:47:4.272Open1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/9/2020 - 19:47:4.272Open1480C:\malware.exeC:\Users\Public\Videos\Sample Videos
7/9/2020 - 19:47:4.272Unknown1480C:\malware.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/9/2020 - 19:47:4.272Unknown1480C:\malware.exeC:\Users\Public\Videos\Sample Videos
7/9/2020 - 19:47:6.551Open1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.551Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.552Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.551Open1480C:\malware.exe\Device\Mup\.\.\
7/9/2020 - 19:47:6.552Open1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.552Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.552Unknown1480C:\malware.exe\Device\Mup\.\.\
7/9/2020 - 19:47:6.552Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.553Open1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.553Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.553Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.552Open1480C:\malware.exe\Device\Mup\.\.\
7/9/2020 - 19:47:6.553Open1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.554Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.554Unknown1480C:\malware.exe\Device\Mup\.\.\
7/9/2020 - 19:47:6.554Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.554Open1480C:\malware.exeC:\srvcli.dll
7/9/2020 - 19:47:6.554Open1480C:\malware.exeC:\Windows\SysWOW64\srvcli.dll
7/9/2020 - 19:47:6.555Open1480C:\malware.exeC:\Windows\SysWOW64\srvcli.dll
7/9/2020 - 19:47:6.556Open1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.556Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.556Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.556Open1480C:\malware.exe\Device\Mup\.\.\
7/9/2020 - 19:47:6.556Open1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.557Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.557Unknown1480C:\malware.exe\Device\Mup\.\.\
7/9/2020 - 19:47:6.557Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.557Open1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.557Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.557Open1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.558Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.558Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.558Unknown1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace
7/9/2020 - 19:47:6.557Open1480C:\malware.exe\Device\Mup\;Csc\.\.\W7VM1
7/9/2020 - 19:47:6.558Open1480C:\malware.exeC:\Windows\CSC\v2.0.6\namespace\W7VM1
7/9/2020 - 19:47:6.558Open1480C:\malware.exe\Device\Mup\W7VM1\Users\
7/9/2020 - 19:47:8.460Unknown1480C:\malware.exe\Device\Mup\W7VM1\Users\
7/9/2020 - 19:47:8.527Open1480C:\malware.exe\Device\Mup\W7VM1\Users\
7/9/2020 - 19:47:8.902Unknown1480C:\malware.exe\Device\Mup\W7VM1\Users\
7/9/2020 - 19:47:8.968Open1480C:\malware.exe\Device\Mup\W7VM1\Users\43cd2k60-readme.txt
7/9/2020 - 19:47:9.567Write1480C:\malware.exe\Device\Mup\W7VM1\Users\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:9.567Write1480C:\malware.exeC:\Users\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:9.567Unknown1480C:\malware.exe\Device\Mup\W7VM1\Users\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:9.634Open1480C:\malware.exe\Device\Mup\W7VM1\Users\
7/9/2020 - 19:47:10.109Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot
7/9/2020 - 19:47:10.653Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot
7/9/2020 - 19:47:10.719Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot
7/9/2020 - 19:47:11.178Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot
7/9/2020 - 19:47:11.245Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\43cd2k60-readme.txt
7/9/2020 - 19:47:12.76Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:12.76Write1480C:\malware.exeC:\Users\Behemot\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:12.76Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:12.162Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default
7/9/2020 - 19:47:12.625Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default
7/9/2020 - 19:47:12.691Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default
7/9/2020 - 19:47:13.296Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default
7/9/2020 - 19:47:13.363Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\43cd2k60-readme.txt
7/9/2020 - 19:47:14.189Write1480C:\malware.exe\Device\Mup\w7vm1\users\Default\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:14.189Write1480C:\malware.exeC:\Users\Default\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:14.189Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:14.256Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public
7/9/2020 - 19:47:14.716Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public
7/9/2020 - 19:47:14.784Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public
7/9/2020 - 19:47:15.253Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public
7/9/2020 - 19:47:15.326Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\43cd2k60-readme.txt
7/9/2020 - 19:47:16.193Write1480C:\malware.exe\Device\Mup\w7vm1\users\Public\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:16.193Write1480C:\malware.exeC:\Users\Public\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:16.194Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:16.358Unknown1480C:\malware.exe\Device\Mup\W7VM1\Users\
7/9/2020 - 19:47:16.358Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot
7/9/2020 - 19:47:17.8Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Contacts
7/9/2020 - 19:47:17.469Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Contacts
7/9/2020 - 19:47:17.539Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Contacts
7/9/2020 - 19:47:18.3Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Contacts
7/9/2020 - 19:47:18.123Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Contacts\43cd2k60-readme.txt
7/9/2020 - 19:47:18.907Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Contacts\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:18.907Write1480C:\malware.exeC:\Users\Behemot\Contacts\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:18.907Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Contacts\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:18.973Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Desktop
7/9/2020 - 19:47:19.511Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Desktop
7/9/2020 - 19:47:19.578Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Desktop
7/9/2020 - 19:47:20.120Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Desktop
7/9/2020 - 19:47:20.186Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Desktop\43cd2k60-readme.txt
7/9/2020 - 19:47:21.12Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:21.12Write1480C:\malware.exeC:\Users\Behemot\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:21.12Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:21.79Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Documents
7/9/2020 - 19:47:21.541Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Documents
7/9/2020 - 19:47:21.607Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Documents
7/9/2020 - 19:47:22.204Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Documents
7/9/2020 - 19:47:22.271Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\documents\43cd2k60-readme.txt
7/9/2020 - 19:47:23.16Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:23.16Write1480C:\malware.exeC:\Users\Behemot\Documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:23.16Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:23.84Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads
7/9/2020 - 19:47:23.548Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads
7/9/2020 - 19:47:23.625Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads
7/9/2020 - 19:47:24.161Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads
7/9/2020 - 19:47:24.227Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\downloads\43cd2k60-readme.txt
7/9/2020 - 19:47:24.907Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:24.907Write1480C:\malware.exeC:\Users\Behemot\Downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:24.907Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:24.980Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites
7/9/2020 - 19:47:25.525Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites
7/9/2020 - 19:47:25.591Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites
7/9/2020 - 19:47:26.48Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites
7/9/2020 - 19:47:26.115Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\favorites\43cd2k60-readme.txt
7/9/2020 - 19:47:26.840Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:26.840Write1480C:\malware.exeC:\Users\Behemot\Favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:26.840Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:26.909Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Links
7/9/2020 - 19:47:27.366Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Links
7/9/2020 - 19:47:27.432Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Links
7/9/2020 - 19:47:27.924Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Links
7/9/2020 - 19:47:27.993Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Links\43cd2k60-readme.txt
7/9/2020 - 19:47:28.836Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:28.836Write1480C:\malware.exeC:\Users\Behemot\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:28.836Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:28.906Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Music
7/9/2020 - 19:47:29.475Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Music
7/9/2020 - 19:47:29.554Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Music
7/9/2020 - 19:47:30.172Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Music
7/9/2020 - 19:47:30.242Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Music\43cd2k60-readme.txt
7/9/2020 - 19:47:31.60Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:31.60Write1480C:\malware.exeC:\Users\Behemot\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:31.60Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:47:31.127Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:31.456Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:31.886Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:31.886Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:31.974Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:31.975Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:31.975Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:32.52Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:32.52Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:32.391Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:32.730Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:33.629Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
7/9/2020 - 19:47:33.696Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:33.696Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:33.696Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:33.771Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:33.771Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:33.771Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:33.844Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:34.937Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:35.337Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:35.338Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:35.460Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:35.460Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:35.460Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:35.569Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:35.569Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:35.909Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:36.239Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:36.735Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
7/9/2020 - 19:47:36.823Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:36.823Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:36.823Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:36.898Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:36.898Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:36.898Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:36.971Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:38.5Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:38.340Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:38.341Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:38.416Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:38.416Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:38.417Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:38.496Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:38.497Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:38.828Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:39.230Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:39.690Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
7/9/2020 - 19:47:39.761Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:39.761Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:39.761Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:39.836Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:39.836Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:39.837Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:39.923Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:40.956Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:41.290Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:41.623Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:42.133Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:42.133Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:42.217Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:42.217Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:42.217Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:42.294Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:42.294Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:42.629Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:42.962Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:43.484Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
7/9/2020 - 19:47:43.553Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:43.553Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:43.553Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:43.627Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:43.627Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:43.628Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:43.702Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:43.702Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:44.31Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:45.113Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:46.192Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:46.531Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:46.532Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:46.610Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:46.610Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:46.610Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:46.683Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:46.683Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:47.103Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:47.433Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:47.881Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
7/9/2020 - 19:47:47.949Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:47.949Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:47.949Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:48.66Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:48.67Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:48.67Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:48.76Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:48.77Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:48.437Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:49.38Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:50.117Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:50.527Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:50.527Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:50.630Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:50.630Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:50.630Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:50.747Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:50.747Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:51.82Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:51.410Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:51.993Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
7/9/2020 - 19:47:52.59Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:52.59Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:52.59Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:52.135Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:52.135Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:52.135Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:52.209Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:52.209Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:52.541Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:53.209Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:54.298Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:54.630Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:54.967Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:55.353Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:55.353Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:55.451Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:55.451Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:55.451Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:55.528Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:47:55.529Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:55.858Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:56.185Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:56.691Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
7/9/2020 - 19:47:56.757Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:57.702Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:58.669Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:58.737Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:58.737Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:58.737Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:58.881Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:47:58.881Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:58.881Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:58.891Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:47:58.892Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:59.255Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:47:59.891Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:0.975Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:1.382Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:1.382Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:1.462Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:1.462Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:1.462Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:1.537Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:1.537Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:1.869Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:2.197Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:2.708Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
7/9/2020 - 19:48:2.775Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:3.184Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:3.868Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:3.935Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:3.935Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:3.935Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:4.13Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:4.14Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:4.14Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:4.89Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:4.89Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:4.420Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:5.96Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:6.201Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:6.563Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:6.563Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:6.638Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:6.638Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:6.639Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:6.713Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:6.713Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:7.44Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:7.416Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:7.892Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
7/9/2020 - 19:48:7.959Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:8.293Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:9.56Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:9.124Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:9.124Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:9.124Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:9.203Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:9.203Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:9.203Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:9.282Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:9.282Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:9.620Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:10.340Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:11.423Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:11.756Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:12.100Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:12.500Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:12.500Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:12.578Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:12.578Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:12.578Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:12.652Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:12.653Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:12.981Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:13.310Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:13.818Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
7/9/2020 - 19:48:13.886Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:14.285Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:14.966Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:15.33Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:15.33Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:15.33Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:15.108Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:15.109Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:15.109Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:15.183Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:15.184Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:15.513Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:16.218Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:16.292Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:16.631Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:17.702Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:18.791Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:19.137Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:19.137Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:19.214Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:19.214Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:19.215Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:19.291Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:19.291Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:19.700Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:20.45Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:20.491Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
7/9/2020 - 19:48:20.557Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:20.970Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:21.576Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:21.642Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:21.642Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:21.642Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:21.717Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:21.717Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:21.717Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:21.792Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:21.792Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:22.194Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:22.862Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:22.928Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:23.328Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:24.64Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:25.154Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:25.488Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:25.489Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:25.700Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:25.700Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:25.700Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:25.813Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:25.813Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:26.195Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:26.530Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:27.38Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
7/9/2020 - 19:48:27.146Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:27.506Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:28.183Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:28.250Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:28.250Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:28.250Open1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:28.439Unknown1480C:\malware.exeC:\Users\Behemot\ntuser.dat.LOG1
7/9/2020 - 19:48:28.439Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:28.440Open1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:28.606Unknown1480C:\malware.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
7/9/2020 - 19:48:28.606Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:28.949Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:29.674Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
7/9/2020 - 19:48:29.763Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:30.99Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:30.772Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:31.887Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
7/9/2020 - 19:48:32.284Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Pictures
7/9/2020 - 19:48:32.755Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Pictures
7/9/2020 - 19:48:32.828Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Pictures
7/9/2020 - 19:48:33.349Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Pictures
7/9/2020 - 19:48:33.416Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Pictures\43cd2k60-readme.txt
7/9/2020 - 19:48:34.292Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:34.292Write1480C:\malware.exeC:\Users\Behemot\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:34.292Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:34.360Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Saved Games
7/9/2020 - 19:48:34.880Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Saved Games
7/9/2020 - 19:48:34.948Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Saved Games
7/9/2020 - 19:48:35.441Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Saved Games
7/9/2020 - 19:48:35.509Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\saved games\43cd2k60-readme.txt
7/9/2020 - 19:48:36.255Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\saved games\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:36.255Write1480C:\malware.exeC:\Users\Behemot\Saved Games\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:36.256Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\saved games\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:36.325Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Searches
7/9/2020 - 19:48:36.793Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Searches
7/9/2020 - 19:48:36.861Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Searches
7/9/2020 - 19:48:37.360Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Searches
7/9/2020 - 19:48:37.456Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Searches\43cd2k60-readme.txt
7/9/2020 - 19:48:38.229Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Searches\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:38.229Write1480C:\malware.exeC:\Users\Behemot\Searches\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:38.229Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Searches\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:38.297Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Videos
7/9/2020 - 19:48:38.823Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Videos
7/9/2020 - 19:48:38.912Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Videos
7/9/2020 - 19:48:39.404Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Videos
7/9/2020 - 19:48:39.472Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Videos\43cd2k60-readme.txt
7/9/2020 - 19:48:40.331Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:40.331Write1480C:\malware.exeC:\Users\Behemot\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:40.331Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:40.496Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot
7/9/2020 - 19:48:40.562Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default
7/9/2020 - 19:48:41.121Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Desktop
7/9/2020 - 19:48:41.660Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Desktop
7/9/2020 - 19:48:41.726Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Desktop
7/9/2020 - 19:48:42.187Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Desktop
7/9/2020 - 19:48:42.253Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Desktop\43cd2k60-readme.txt
7/9/2020 - 19:48:43.77Write1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:43.77Write1480C:\malware.exeC:\Users\Default\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:43.77Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:43.143Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Documents
7/9/2020 - 19:48:43.602Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Documents
7/9/2020 - 19:48:43.668Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Documents
7/9/2020 - 19:48:44.283Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Documents
7/9/2020 - 19:48:44.349Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\documents\43cd2k60-readme.txt
7/9/2020 - 19:48:45.103Write1480C:\malware.exe\Device\Mup\w7vm1\users\Default\documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:45.103Write1480C:\malware.exeC:\Users\Default\Documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:45.103Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:45.169Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Downloads
7/9/2020 - 19:48:45.631Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Downloads
7/9/2020 - 19:48:45.698Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Downloads
7/9/2020 - 19:48:46.201Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Downloads
7/9/2020 - 19:48:46.295Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\downloads\43cd2k60-readme.txt
7/9/2020 - 19:48:46.952Write1480C:\malware.exe\Device\Mup\w7vm1\users\Default\downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:46.952Write1480C:\malware.exeC:\Users\Default\Downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:46.952Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:47.20Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Favorites
7/9/2020 - 19:48:47.550Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Favorites
7/9/2020 - 19:48:47.617Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Favorites
7/9/2020 - 19:48:48.75Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Favorites
7/9/2020 - 19:48:48.141Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\favorites\43cd2k60-readme.txt
7/9/2020 - 19:48:48.883Write1480C:\malware.exe\Device\Mup\w7vm1\users\Default\favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:48.883Write1480C:\malware.exeC:\Users\Default\Favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:48.883Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:48.950Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Links
7/9/2020 - 19:48:49.425Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Links
7/9/2020 - 19:48:49.497Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Links
7/9/2020 - 19:48:50.28Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Links
7/9/2020 - 19:48:50.96Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Links\43cd2k60-readme.txt
7/9/2020 - 19:48:50.889Write1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:50.889Write1480C:\malware.exeC:\Users\Default\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:50.889Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:50.958Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Music
7/9/2020 - 19:48:51.489Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Music
7/9/2020 - 19:48:51.555Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Music
7/9/2020 - 19:48:52.17Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Music
7/9/2020 - 19:48:52.85Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Music\43cd2k60-readme.txt
7/9/2020 - 19:48:52.914Write1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:52.914Write1480C:\malware.exeC:\Users\Default\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:52.914Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:52.981Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Pictures
7/9/2020 - 19:48:53.442Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Pictures
7/9/2020 - 19:48:53.509Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Pictures
7/9/2020 - 19:48:54.95Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Pictures
7/9/2020 - 19:48:54.162Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Pictures\43cd2k60-readme.txt
7/9/2020 - 19:48:54.944Write1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:54.944Write1480C:\malware.exeC:\Users\Default\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:54.944Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:55.150Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Saved Games
7/9/2020 - 19:48:55.639Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Saved Games
7/9/2020 - 19:48:55.706Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Saved Games
7/9/2020 - 19:48:56.165Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Saved Games
7/9/2020 - 19:48:56.231Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\saved games\43cd2k60-readme.txt
7/9/2020 - 19:48:56.963Write1480C:\malware.exe\Device\Mup\w7vm1\users\Default\saved games\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:56.963Write1480C:\malware.exeC:\Users\Default\Saved Games\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:56.963Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\saved games\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:57.31Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Videos
7/9/2020 - 19:48:57.490Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Videos
7/9/2020 - 19:48:57.557Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Videos
7/9/2020 - 19:48:58.96Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Videos
7/9/2020 - 19:48:58.164Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Videos\43cd2k60-readme.txt
7/9/2020 - 19:48:59.35Write1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:59.35Write1480C:\malware.exeC:\Users\Default\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:59.35Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:48:59.218Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default
7/9/2020 - 19:48:59.309Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public
7/9/2020 - 19:48:59.872Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Desktop
7/9/2020 - 19:49:0.332Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Desktop
7/9/2020 - 19:49:0.444Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Desktop
7/9/2020 - 19:49:0.928Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Desktop
7/9/2020 - 19:49:0.996Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Desktop\43cd2k60-readme.txt
7/9/2020 - 19:49:1.797Write1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:1.797Write1480C:\malware.exeC:\Users\Public\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:1.797Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Desktop\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:1.870Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Documents
7/9/2020 - 19:49:2.372Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Documents
7/9/2020 - 19:49:2.438Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Documents
7/9/2020 - 19:49:2.947Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Documents
7/9/2020 - 19:49:3.13Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\documents\43cd2k60-readme.txt
7/9/2020 - 19:49:3.744Write1480C:\malware.exe\Device\Mup\w7vm1\users\Public\documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:3.744Write1480C:\malware.exeC:\Users\Public\Documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:3.745Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\documents\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:3.813Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Downloads
7/9/2020 - 19:49:4.343Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Downloads
7/9/2020 - 19:49:4.411Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Downloads
7/9/2020 - 19:49:4.926Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Downloads
7/9/2020 - 19:49:4.995Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\downloads\43cd2k60-readme.txt
7/9/2020 - 19:49:5.664Write1480C:\malware.exe\Device\Mup\w7vm1\users\Public\downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:5.664Write1480C:\malware.exeC:\Users\Public\Downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:5.664Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\downloads\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:5.730Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Favorites
7/9/2020 - 19:49:6.259Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Favorites
7/9/2020 - 19:49:6.326Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Favorites
7/9/2020 - 19:49:6.792Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Favorites
7/9/2020 - 19:49:6.865Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\favorites\43cd2k60-readme.txt
7/9/2020 - 19:49:7.617Write1480C:\malware.exe\Device\Mup\w7vm1\users\Public\favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:7.617Write1480C:\malware.exeC:\Users\Public\Favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:7.617Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\favorites\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:7.689Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Libraries
7/9/2020 - 19:49:8.153Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Libraries
7/9/2020 - 19:49:8.261Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Libraries
7/9/2020 - 19:49:8.756Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Libraries
7/9/2020 - 19:49:8.823Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\libraries\43cd2k60-readme.txt
7/9/2020 - 19:49:9.604Write1480C:\malware.exe\Device\Mup\w7vm1\users\Public\libraries\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:9.604Write1480C:\malware.exeC:\Users\Public\Libraries\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:9.604Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\libraries\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:9.672Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Music
7/9/2020 - 19:49:10.221Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Music
7/9/2020 - 19:49:10.288Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Music
7/9/2020 - 19:49:10.745Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Music
7/9/2020 - 19:49:10.811Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Music\43cd2k60-readme.txt
7/9/2020 - 19:49:11.643Write1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:11.643Write1480C:\malware.exeC:\Users\Public\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:11.643Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Music\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:11.709Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Pictures
7/9/2020 - 19:49:12.168Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Pictures
7/9/2020 - 19:49:12.235Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Pictures
7/9/2020 - 19:49:12.768Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Pictures
7/9/2020 - 19:49:12.834Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Pictures\43cd2k60-readme.txt
7/9/2020 - 19:49:13.589Write1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:13.589Write1480C:\malware.exeC:\Users\Public\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:13.589Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Pictures\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:13.699Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Recorded TV
7/9/2020 - 19:49:14.296Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Recorded TV
7/9/2020 - 19:49:14.363Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Recorded TV
7/9/2020 - 19:49:14.822Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Recorded TV
7/9/2020 - 19:49:14.937Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\recorded tv\43cd2k60-readme.txt
7/9/2020 - 19:49:15.630Write1480C:\malware.exe\Device\Mup\w7vm1\users\Public\recorded tv\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:15.630Write1480C:\malware.exeC:\Users\Public\Recorded TV\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:15.630Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\recorded tv\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:15.698Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Videos
7/9/2020 - 19:49:16.232Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Videos
7/9/2020 - 19:49:16.299Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Videos
7/9/2020 - 19:49:16.759Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Videos
7/9/2020 - 19:49:16.826Open1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Videos\43cd2k60-readme.txt
7/9/2020 - 19:49:17.664Write1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:17.664Write1480C:\malware.exeC:\Users\Public\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:17.664Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public\Videos\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:17.829Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Public
7/9/2020 - 19:49:17.896Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Contacts
7/9/2020 - 19:49:18.860Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Contacts
7/9/2020 - 19:49:18.928Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Desktop
7/9/2020 - 19:49:19.860Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Desktop
7/9/2020 - 19:49:19.954Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Documents
7/9/2020 - 19:49:20.853Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Documents
7/9/2020 - 19:49:20.926Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads
7/9/2020 - 19:49:21.785Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor
7/9/2020 - 19:49:22.375Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor
7/9/2020 - 19:49:22.441Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor
7/9/2020 - 19:49:22.903Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor
7/9/2020 - 19:49:22.969Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor\43cd2k60-readme.txt
7/9/2020 - 19:49:23.808Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:23.808Write1480C:\malware.exeC:\Users\Behemot\Downloads\Monitor\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:23.808Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:23.976Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Downloads
7/9/2020 - 19:49:24.43Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites
7/9/2020 - 19:49:24.915Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links
7/9/2020 - 19:49:25.421Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links
7/9/2020 - 19:49:25.491Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links
7/9/2020 - 19:49:25.979Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links
7/9/2020 - 19:49:26.45Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links\43cd2k60-readme.txt
7/9/2020 - 19:49:26.910Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:26.910Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:26.910Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:26.978Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:49:27.436Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:49:27.504Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:49:28.14Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links for Brasil
7/9/2020 - 19:49:28.113Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\links for brasil\43cd2k60-readme.txt
7/9/2020 - 19:49:28.771Write1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\links for brasil\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:28.771Write1480C:\malware.exeC:\Users\Behemot\Favorites\Links for Brasil\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:28.771Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites\links for brasil\43cd2k60-readme.txt43cd2k60-readme.txt
7/9/2020 - 19:49:28.938Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Favorites
7/9/2020 - 19:49:29.4Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Links
7/9/2020 - 19:49:30.8Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Links
7/9/2020 - 19:49:30.75Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Music
7/9/2020 - 19:49:31.65Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Music
7/9/2020 - 19:49:31.161Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Pictures
7/9/2020 - 19:49:32.92Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Pictures
7/9/2020 - 19:49:32.159Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Saved Games
7/9/2020 - 19:49:33.145Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Saved Games
7/9/2020 - 19:49:33.211Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Searches
7/9/2020 - 19:49:34.188Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Searches
7/9/2020 - 19:49:34.256Open1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Videos
7/9/2020 - 19:49:35.166Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Behemot\Videos
7/9/2020 - 19:49:35.307Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Desktop
7/9/2020 - 19:49:36.211Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Desktop
7/9/2020 - 19:49:36.278Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Documents
7/9/2020 - 19:49:37.338Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Documents
7/9/2020 - 19:49:37.406Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Downloads
7/9/2020 - 19:49:38.381Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Downloads
7/9/2020 - 19:49:38.447Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Favorites
7/9/2020 - 19:49:39.332Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Favorites
7/9/2020 - 19:49:39.438Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Links
7/9/2020 - 19:49:40.362Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Links
7/9/2020 - 19:49:40.428Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Music
7/9/2020 - 19:49:41.429Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Music
7/9/2020 - 19:49:41.506Open1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Pictures
7/9/2020 - 19:49:42.458Unknown1480C:\malware.exe\Device\Mup\w7vm1\users\Default\Pictures

Process
Trace
7/9/2020 - 19:45:45.744Create1480C:\malware.exe2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
7/9/2020 - 19:46:49.88Terminate1480C:\malware.exe2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

Analysis
Reason
Timeout

Status
Sucessfully Executed

Results
1

Registry
Trace
7/9/2020 - 19:45:45.549Write1480C:\malware.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Facebook_AssistantYbr
7/9/2020 - 19:45:45.549Write1480C:\malware.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Facebook_AssistantS6yP
7/9/2020 - 19:45:45.551Write1480C:\malware.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Facebook_AssistantdA2U3
7/9/2020 - 19:45:45.552Write1480C:\malware.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Facebook_Assistant8eN335
7/9/2020 - 19:45:45.554Write1480C:\malware.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Facebook_AssistantzEhXReE
7/9/2020 - 19:45:45.562Write1480C:\malware.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Facebook_AssistantfOvNL4TU
7/9/2020 - 19:45:45.563Write1480C:\malware.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunBV7BRrErOX
7/9/2020 - 19:45:46.173Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.174Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.174Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.188Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.245Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.245Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.245Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.251Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.252Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.252Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.252Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.253Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.253Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.253Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.254Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.254Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.254Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.254Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.255Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.255Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.255Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.256Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.256Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.256Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.256Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.257Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.257Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.257Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.258Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.259Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.259Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.259Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.260Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.260Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.260Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.260Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.261Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.261Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.261Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.261Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.262Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.262Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.262Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.262Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.263Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.263Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.263Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.263Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.264Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.264Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.264Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.265Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.265Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.265Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.265Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.266Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.266Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.266Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.266Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.267Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.267Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.267Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.276Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.357Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.443Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.444Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.444Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.445Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.445Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.446Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.446Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.447Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.448Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.448Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.449Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.455Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.456Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.461Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:45:46.462Write2476C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
7/9/2020 - 19:46:49.373Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000Owner
7/9/2020 - 19:46:49.373Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000SessionHash
7/9/2020 - 19:46:49.373Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000Sequence
7/9/2020 - 19:46:49.374Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:46:49.374Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:46:50.397Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:46:50.397Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:46:51.471Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:46:51.472Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:46:52.536Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:46:52.536Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:46:53.649Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:46:53.650Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:46:54.740Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:46:54.741Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:46:55.832Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:46:55.832Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:46:56.979Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:46:56.979Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:46:58.113Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:46:58.113Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:46:59.326Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:46:59.326Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:47:0.617Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:47:0.617Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:47:1.860Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:47:1.861Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:47:31.883Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:47:31.883Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:47:35.332Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:47:35.332Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:47:38.337Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:47:38.338Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:47:42.122Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:47:42.122Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:47:46.526Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:47:46.526Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:47:50.523Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:47:50.524Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:47:55.349Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:47:55.349Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:48:1.379Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:48:1.379Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:48:6.560Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:48:6.561Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:48:12.497Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:48:12.498Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:48:19.134Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:48:19.134Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
7/9/2020 - 19:48:25.485Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
7/9/2020 - 19:48:25.486Write1480C:\malware.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash

File Summary
Created
Identified: True check_circle

Deleted
Identified: False cancel

Process Summary
Created
Identified: True check_circle

Deleted
Identified: True check_circle

Registry Summary
Proxy
Identified: False cancel

AutoRun
Identified: False cancel

Created
Identified: True check_circle

Deleted
Identified: False cancel

Browsers
Identified: False cancel

Internet
Identified: False cancel

Loading...

DNS
Query

Response

TCP
Info

UDP
Info

HTTP
Info

Summary
DNS
False cancel

TCP
False cancel

UDP
False cancel

HTTP
False cancel

Results
BINARY
NFS 2.0 (Threshold = 0.8)
confidence: 67.50%
suspicious: True check_circle

Decision Tree (NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 73.69%
suspicious: True check_circle

Random Forest (100 estimators, NFS-BRMalware)
confidence: 54.00%
suspicious: False cancel

Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 67.53%
suspicious: True check_circle

LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 100.00%
suspicious: True check_circle

Add to Collection
Download